Cybersecurity

13 posts

cloudflare3 min readCurated summary

Cloudflare proudly joins the UK government's Cyber Resilience Pledge

Cloudflare has joined the UK government’s voluntary Cyber Resilience Pledge, supporting its focus on security governance, board accountability, and supply-chain protection. The company argues that these principles align with its existing approach: make security broadly accessible, use network-scale intelligence, apply protections internally, and be transparent about failures. It presents collective action and stronger baseline controls as essential to addressing rising cyberattacks and AI-enabled threats. ## The Cyber Resilience Pledge - The pledge encourages organizations to adopt foundational cybersecurity governance and make resilience a leadership responsibility. - It promotes comprehensive security coverage across supply chains. - Its central principles include: - Democratizing access to security - Leadership accountability - Radical transparency - Cloudflare sees the pledge as validation of principles it has followed for more than a decade. - The company highlights the need to address common weaknesses such as: - Unpatched systems - Weak access controls - Poor vendor oversight ## Rising Cybersecurity Risk - Cloudflare blocked an average of 234 billion cyber threats per day during the first quarter of 2026. - It recently mitigated a DDoS attack peaking at 31.4 Tbps. - By the end of 2025, the UK was the sixth-most targeted location globally for DDoS attacks. - Threat actors increasingly targeted application-layer services in financial services, aviation, and regional government. - UK survey data found that 43% of businesses and 28% of charities experienced a cyber incident in the previous year. - Frontier AI models are making attacks easier to automate, including vulnerability scanning and convincing phishing campaigns. ## Why Cyber Resilience Matters - Resilience is a business requirement because customers expect services to remain available, responsive, and trustworthy. - It extends beyond recovering from incidents to proactively: - Monitoring threat signals - Absorbing disruptions - Adapting systems after failures - Cloudflare views security controls as the foundation that makes resilience possible. ## Cloudflare’s Resilience Architecture ### Security by Default - Cloudflare aims to make baseline protections available to organizations of all sizes. - Examples include: - SSL certificates for encrypted traffic - Unmetered DDoS protection on its free plan - CDN and DNSSEC access - Post-quantum cryptography deployment - Impact programs such as Project Galileo and the Athenian Project - This model is intended to help small businesses, startups, local authorities, and public services participate in the UK’s resilience efforts. ### The Network as a Sensor - Cloudflare peers directly with more than 13,000 networks worldwide. - Attack intelligence gathered in one location can become a protection rule for customers elsewhere within seconds. - This global visibility improves threat detection, scoring, and response across its services. ### Cloudflare as “Customer Zero” - Cloudflare uses its own security products and infrastructure to protect internal systems. - Employees access internal applications through Cloudflare Access and Gateway. - Internal requests require hardware-based MFA, device posture checks, and cryptographically verified identity tokens. - Testing security controls internally helps Cloudflare identify improvements before delivering them to customers. ### Transparency and Incident Response - Cloudflare publishes technical postmortems for security incidents and zero-day vulnerabilities. - It shares indicators of compromise, telemetry, and architectural lessons with the wider security community. - After a major outage, its “Code Orange” initiative focused on building systems that “fail small,” safer configuration tooling, and automated best practices. ## Cloudflare’s Pledge Commitments - The post begins describing the pledge’s requirements around: - Board responsibility and governance - Supply-chain security - Technical standards related to UK Cyber Essentials - The provided text ends before detailing Cloudflare’s specific implementation of these commitments. Organizations should treat cyber resilience as an ongoing governance and engineering responsibility, not an optional product feature. Raising baseline protections, sharing lessons from incidents, and securing supply chains can make the wider Internet safer and more dependable.

Read original(opens in new tab)
github1 min readCurated summary

6 security settings every GitHub maintainer should enable this week

Joseph is a cybersecurity and AI expert who creates software and educational content to help developers build more securely. His open-source game, videos, and international speaking engagements have reached a broad audience, combining practical security guidance with accessible explanations. ## Cybersecurity and AI Leadership - Develops software and content focused on secure development. - Helps shape how developers approach cybersecurity and AI. ## Open-Source Security Education - Created the open-source game [gh.io/scg]. - More than 10,000 developers have used it to build future-proof security skills. ## Educational Videos - His videos have received over 2.8 million views. - Simplifies complex security topics into actionable advice for a global audience. ## International Speaking - Delivered 79 talks across 25 countries in the past four years. - Known for combining technical insight with energetic stage presence. Overall, Joseph’s work spans hands-on tools, accessible education, and public speaking, making cybersecurity knowledge more practical and widely available to developers.

Read original(opens in new tab)
cloudflare3 min readCurated summary

Celebrating 12 years of Project Galileo

Project Galileo, launched by Cloudflare 12 years ago, provides free cybersecurity services to more than 3,400 civil society websites across 120 countries. Its anniversary report shows that journalists, human rights groups, and nonprofits face more frequent and intense attacks than other Internet users, especially during politically sensitive work. Cloudflare is responding with expanded research, case studies, partnerships, and a call for accessible security protections. ## Project Galileo’s Mission and Reach - The program protects journalists, human rights defenders, and nonprofit organizations from being forced offline. - It now supports more than 3,400 websites in 120 countries. - Cloudflare’s global network spans more than 335 cities in 125 countries, with over 20% of the web behind its infrastructure. ## Cyberattacks Targeting Civil Society Cloudflare’s first comprehensive annual report compares threats against civil society with attacks against Internet users more broadly. - DDoS attacks were the most common threat, often lasting for days or weeks. - Civil society organizations faced website vulnerability exploitation attempts at more than seven times the rate of other Cloudflare customers. - Media organizations were especially affected. - Journalists working in exile received nearly four times more malicious traffic than journalism organizations overall. - Almost 10% of emails processed for civil society organizations contained potential phishing material. - Attacks often coincided with investigative reporting, public advocacy, or other critical organizational activities. Cloudflare calls for affordable cybersecurity, greater transparency around cyberattacks and Internet shutdowns, and default integration of AI-aware and post-quantum protections. The company plans to publish the report annually to track changing threat patterns. ## Case Studies of Project Galileo Participants Sixteen case studies illustrate the varied security needs of participating organizations, including: - Digital rights groups such as SHARE Foundation. - Investigative and independent media organizations, including OCCRP, elTOQUE, and China Digital Times. - Organizations documenting conflict and human rights abuses, such as Ukraine War Archive. - Research and public-interest institutions including Our World in Data and the Bulletin of Atomic Scientists. - Environmental, legal, scientific, and humanitarian groups such as Sea Shepherd Brazil, Activist Rights, and the Royal Meteorological Society. ## Expanding the Partner Network Project Galileo depends on 59 civil society partners that review and approve applications. - Partners contribute local expertise and help identify organizations that need protection. - Previous collaborations produced initiatives such as email security with Protect.ngo and Internet measurement work through UNICEF’s Giga project. - Cloudflare has focused on expanding access beyond North America and Europe through regional events and partnerships. - Recent Asia-Pacific partners include EngageMedia and the OpenCulture Foundation. - The anniversary announcement introduces three additional partners serving journalists, including the International Center for Journalists and Media Cluster Norway. Project Galileo’s next phase combines threat intelligence, direct protection, regional partnerships, and specialized services for journalism organizations. Its broader recommendation is that reliable cybersecurity should be treated as essential infrastructure for civil society and public discourse.

Read original(opens in new tab)
github1 min readCurated summary

Making secret scanning more trustworthy: Reducing false positives at scale

Mariko is a Principal Applied Scientist at Microsoft who leads the development of agentic AI workflows for cybersecurity operations. Her work centers on using large language models and agentic systems to bring frontier AI research into practical products and operational environments. ## Professional Role - Principal Applied Scientist at Microsoft. - Leads agentic AI workflow development for cybersecurity operations. ## Research and Technical Focus - LLM-powered systems. - Agentic workflows. - Applying frontier AI research to real-world products and operations. Overall, Mariko’s work connects advanced AI research with practical cybersecurity and enterprise applications.

Read original(opens in new tab)
github1 min readCurated summary

Investigating unauthorized access to GitHub-owned repositories

Alexis Wales is GitHub’s Chief Information Security Officer, responsible for protecting the platform, its products, and the open source community. With two decades of experience defending critical networks, she combines public- and private-sector expertise to address major cybersecurity challenges affecting modern technology. ## Leadership at GitHub - Leads a team of security professionals at GitHub. - Focuses on safeguarding GitHub’s platform and products. - Supports more than 150 million developers building and deploying software securely. - Helps protect the broader open source community. ## National Cybersecurity Experience - Has 20 years of experience defending critical national and private-sector networks. - Previously worked with the Department of Defense. - Served at the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). ## Public-Private Collaboration - Her government experience shaped a strong interest in cooperation between public and private organizations. - Advocates collaboration to solve complex security threats affecting widely used technology. Overall, Wales’s work combines large-scale platform security with cross-sector cooperation to strengthen cybersecurity for developers and the broader technology ecosystem.

Read original(opens in new tab)
cloudflare3 min readCurated summary

How Cloudflare responded to the “Copy Fail” Linux vulnerability

Cloudflare assessed the “Copy Fail” Linux privilege-escalation vulnerability (CVE-2026-31431) immediately after its disclosure on April 29, 2026. Its existing kernel update process meant the relevant fixes were already deployed across most infrastructure, while behavioral detections could identify exploitation attempts within minutes. Cloudflare reported no environmental impact, customer data exposure, or service disruption. ## Cloudflare’s Linux Kernel Update Process - Cloudflare runs custom Linux kernels based on community Long-Term Support releases across datacenters in 330 cities. - Automated jobs build updated kernels approximately weekly from upstream security and stability fixes. - New builds are tested in staging before global deployment. - The Edge Reboot Release pipeline rolls updates through edge infrastructure on a four-week cycle. - Control-plane systems generally use the newest kernel, with reboots scheduled based on workload requirements. - By the time vulnerabilities are publicly disclosed, fixes are typically already present in stable LTS releases and deployed by Cloudflare. - At disclosure, most systems used Linux 6.12 LTS, while some were transitioning to 6.18 LTS. ## How Copy Fail Worked - The vulnerability affected the Linux kernel’s `AF_ALG` interface, which lets unprivileged processes access cryptographic operations through the `algif_aead` module. - Attackers could combine: - `sendmsg()` or `splice()` to submit data - `recvmsg()` to execute the cryptographic operation - Page-cache references to redirect writes into files - An older in-place optimization allowed the AEAD implementation to write beyond the intended output boundary. - The `authencesn` wrapper performed a controllable four-byte out-of-bounds write. - By using `splice()`, an attacker could target pages belonging to any readable file and control: - The file being modified - The write offset - The four bytes written ## Privilege Escalation Through `/usr/bin/su` - The public exploit targeted `/usr/bin/su`, a setuid-root binary commonly present on Linux systems. - The attacker populated the binary’s contents in the page cache and connected those cached pages to a crypto scatterlist. - Shellcode was supplied through AAD bytes in `sendmsg()`. - `splice()` parameters controlled the target offset in the binary. - Although `recvmsg()` returned `-EBADMSG`, the out-of-bounds write had already modified the shared page cache. - Executing `/usr/bin/su` then loaded the modified cached pages, causing the injected code to run with root privileges. ## Upstream Fix and Cloudflare’s Response - The upstream fix, commit `a664bf3d603d`, reverted the 2017 in-place optimization responsible for the flaw. - After disclosure, Cloudflare’s security and kernel engineering teams worked in parallel to: - Identify vulnerable kernel versions - Assess infrastructure exposure - Review the exploit technique - Validate behavioral detections - Existing monitoring could detect the exploit pattern within minutes. - Cloudflare concluded that its infrastructure was not impacted and that no customer data or services were affected. Cloudflare’s experience demonstrates the value of maintaining patched LTS kernels, automating frequent kernel builds and staged rollouts, and combining preventative patching with behavioral exploit detection.

Read original(opens in new tab)
github1 min readCurated summary

Securing the git push pipeline: Responding to a critical remote code execution vulnerability

Alexis Wales is GitHub’s Chief Information Security Officer, responsible for protecting the platform, its products, and the open source community. She leads security experts supporting more than 150 million developers and draws on two decades of experience defending critical networks. Her work has reinforced the importance of public-private collaboration in addressing major technology security threats. ## Leadership at GitHub - Oversees GitHub’s security strategy and teams. - Focuses on safeguarding developers, products, the platform, and the broader open source ecosystem. - Supports secure software development and deployment for more than 150 million developers. ## Cybersecurity Experience - Has 20 years of experience protecting national and private-sector networks. - Previously held roles with the Department of Defense and CISA. - Developed a strong interest in cooperation between government and industry. ## Focus on Collaboration - Advocates public-private partnerships to address complex cybersecurity challenges. - Applies her experience to threats affecting the technology people rely on every day.

Read original(opens in new tab)
aws2 min readCurated summary

Our First 2026 Heroes Cohort Is Here! | Amazon Web Services

AWS has announced its first 2026 Heroes cohort, recognizing Maurizio, Ray Goh, and Sheyla Leacock for combining technical expertise with community leadership. Their work spans cloud architecture, generative AI, machine learning, and cybersecurity, while emphasizing mentorship, education, and meaningful human connections. Together, they demonstrate how technology leaders can expand access to skills and strengthen communities globally. ## Maurizio – Pignola, Italy - CTO and organizer of the AWS User Group Basilicata. - Has spent more than a decade developing cloud communities and technology ecosystems in areas where they previously did not exist. - Founded an international technology conference in a small mountain village, connecting global experts with local developers. - Covers topics including cloud architecture, DevOps, and web scaling, alongside creative networking opportunities. - Mentors children, university students, and professionals transitioning into cloud careers. - Combines technical leadership with inclusive, cross-generational community building. ## Ray Goh – Singapore - AI and machine learning community leader involved in AWS programs since 2018. - Founded The Gen-C in 2024, offering public library workshops on generative AI, LLM fine-tuning, and AWS AI agents. - Has spoken at major AWS events and contributed to the AWS Machine Learning Blog. - Led DBS Bank’s AWS DeepRacer initiative, which trained more than 3,100 employees. - Trained over 1,300 ASEAN students in LLM techniques in 2025. - Supports skills-based programs teaching AI and machine learning to women, children, and young people. ## Sheyla Leacock – Panama City, Panama - IT security professional, mentor, technical writer, and international speaker. - Leads the AWS User Group in Panama and participates in AWS Community Days and regional meetups. - Has spoken at AWS Summits, AWS re:Invent PeerTalk sessions, and more than 20 international conferences. - Publishes educational content focused on AWS cloud computing and cybersecurity. - Works with universities as a guest lecturer to help develop future technology and security professionals. - Strengthens the cloud and cybersecurity ecosystem through education, knowledge sharing, and community leadership. The new cohort highlights the broader impact of community-driven technology leadership. Readers can visit the AWS Heroes webpage to learn more about the program or connect with a Hero.

Read original(opens in new tab)
kakao4 min readCurated summary

From Student to Developer: Learning Rational Choices Over Right Answers—From DB and Security to AI

The onboarding of 40 new Kakao developers shifted their perspective from making features work to designing systems that survive real-world operations. Across databases, security, and AI, they learned that there is rarely one perfect answer; the best choice depends on scale, risk, maintainability, and business needs. The central lesson was to replace theoretical correctness with responsible, adaptable engineering judgment. ## Database: From Finding the Right Answer to Preparing for Change - Database design must be evaluated by whether it can withstand traffic, schema changes, and operational demands—not only by theoretical correctness. - Foreign keys are not automatically the best choice: - They can introduce locking, performance, and flexibility concerns. - Referential integrity can instead be managed at the application layer, provided testing and correction processes are strong. - Soft deletion, using fields such as `deleted_at`, supports auditability and recovery and is often an essential operational strategy. - Indexes should be selected according to the questions the database must answer: - B-tree, GIN, GiST, SP-GiST, and vector indexes serve different data and query patterns. - Execution plans reveal whether SQL uses indexes or performs full table scans, directly affecting I/O and response times. - Duplication is not always harmful: - Intentional denormalization can avoid expensive joins. - Snapshot data can simplify reads and preserve the information needed by a business workflow. - In MongoDB, embedding selected related data can make screen queries much simpler than relying exclusively on references. - Different database systems embody different trade-offs among performance, consistency, scalability, and operational cost. - The training covered MySQL high availability, PostgreSQL primary-key structures, cloud-native systems such as Neon, and the broader storage-to-analysis pipeline of Hadoop and Spark. - The resulting mindset favors designs that are safe to change and affordable to operate over designs that are theoretically perfect. ## Security and IT: From Someone Else’s Responsibility to a Personal Default - Security became a direct consequence of developers’ code rather than merely a compliance or infrastructure concern. - Everyday safeguards such as development/production separation, VPNs, and antivirus software demonstrate that safety often requires accepting some inconvenience. - DDoS defense is not only about blocking traffic: - It can be difficult to distinguish an attack from legitimate traffic spikes caused by a popular event. - Developers should apply basic controls such as rate limiting and escalate suspicious activity through established response channels. - Hands-on API exploitation made vulnerabilities concrete and encouraged developers to view security through an attacker’s perspective. - Security must be continuous: - AI is increasingly being used both to discover vulnerabilities and to strengthen attacks. - Social-engineering methods involving QR codes, app permissions, and human behavior require more than purely technical defenses. - Security checks should be integrated from the beginning of development, not performed only at the end. - Software quality also depends on people: - Code should remain understandable enough for another developer to take over quickly. - Strong engineering means choosing and communicating the most appropriate solution for the business context, not merely finding a technically possible one. ## AI: From Chatting with Models to Designing Systems - An AI agent is not simply a model; it is an architecture composed of tools, routing logic, error handling, and model calls. - Agent development applies familiar software-engineering practices to probabilistic models. - Because LLM outputs can vary, reliable systems need deliberate controls: - Prompt chaining breaks large tasks into smaller steps and limits context contamination. - Few-shot examples clarify required output formats. - Routing selects different prompts or workflows based on conditions. - Multi-agent systems divide responsibilities among specialized agents, echoing the modularity and scalability principles of microservices. - RAG reduces hallucinations structurally by: - Chunking documents. - Searching for semantically similar vectors. - Supplying retrieved information to the model as additional context. - MCP exposes internal systems and data as callable tools, effectively enabling remote function calling and connecting AI to enterprise capabilities. - Effective AI use shifted from criticizing poor answers to specifying clear objectives, formats, examples, context, and supporting data. - The goal is not merely to receive an intelligent response, but to design a system that consistently produces intelligent behavior. The training ultimately marked a transition from student-style problem solving to professional engineering. Developers should consider operational resilience, security, maintainability, and business value, then make and clearly explain the most reasonable choice for the circumstances.

Read original(opens in new tab)
lineOriginal article

Practical security knowledge growing with (opens in new tab)

LINE CTF 2025 serves as a collaborative platform for global security experts to exchange technical knowledge and tackle real-world cybersecurity challenges through a competitive framework. Under the newly integrated LY Corporation, the event evolved to prioritize anti-AI problem design and enhanced privacy protections, reinforcing its position as a top-tier competition in the Asian security community. The event successfully demonstrated that high-quality problem engineering and community-focused operations can drive both individual growth and organizational security excellence. ## Strategic Shift and AI-Resilient Design * **Multisite Collaboration:** While previous years were led primarily by the Japanese team, 2025 saw a shift where the Korean security team led preparations and the Vietnamese team contributed the highest volume of technical challenges. * **Counter-AI Engineering:** To maintain fairness in an era of LLMs, problems were specifically designed to mislead automated AI analysis, requiring human logic and deep conceptual understanding to arrive at the correct "flag." * **Systemic Integration:** This was the first year applying the unified LY Corporation administrative and approval processes, resulting in a more refined timeline for problem verification and quality control. ## Competition Format and Problem Engineering * **Jeopardy-Style Challenges:** The event featured 13 independent challenges—6 Web, 4 Pwnable, and 3 Reverse Engineering—where teams earned points based on difficulty. * **Three-Stage Validation:** Every problem underwent a rigorous cycle of idea conception, technical environment isolation/testing, and internal peer review to eliminate unintended "cheese" solutions or bugs. * **Technical Philosophy:** Problems were modeled after real-world service vulnerabilities and latest security trends, targeting a difficulty level that requires several hours of dedicated analysis by a skilled researcher. ## Platform Evolution and Performance * **Privacy-First Infrastructure:** The team customized the open-source CTFd framework to remove email-based registration, instead using a recovery-code system to ensure participant anonymity and data security. * **Growing Technical Prestige:** The competition’s rating on CTFtime (a global community platform) has climbed steadily over three years, reaching a weight of 66.5 in 2025, reflecting its high quality and difficulty. * **Competitive Results:** The Korean team "The Duck" maintained dominance with a third consecutive win, while the battle for second place was decided by a dramatic last-minute solve by the Japanese team "GMO Ierae." Participating in CTFs like LINE CTF offers an invaluable practical learning environment for security engineers to master vulnerability analysis and exploit development. Aspiring and professional researchers are encouraged to engage with these challenges to sharpen their analytical skills and contribute to a more robust, collaborative global security culture.

slack3 min readCurated summary

Building Slack’s Anomaly Event Response

Slack’s Anomaly Event Response (AER) is designed to close the gap between detecting suspicious activity and stopping it. By combining real-time monitoring, adaptive analytics, and automated session termination, AER can disrupt high-confidence attacks within minutes rather than hours or days. Slack presents it as a built-in security capability for Enterprise Grid customers that works without additional tools or security staff. ## Shared Responsibility for Securing Slack - Slack processes billions of daily interactions from tens of millions of weekly users. - Enterprise customers receive audit logs covering hundreds of platform actions. - Specialized anomaly logs flag activity such as: - Irregular logins - Malware uploads - Unexpected data transfers - Audit logs provide early warning but traditionally require security personnel or third-party systems to interpret and act on them. - AER provides automated response for customers that lack the resources or infrastructure to build those integrations. - Advanced customers can still combine AER with customized security controls. ## Configurable Threat Detection AER focuses on common indicators of account compromise, data exfiltration, and automated abuse: - Access from Tor exit nodes - Excessive downloading - Data scraping through non-native automation tools - Session fingerprint mismatches - Unexpected API-call volumes or patterns - Unusual user agents, including virtual or non-standard clients Organizations can choose which anomaly types should terminate sessions and which should only be logged. Notification settings are also configurable, with alerts available for organization owners and security administrators through email or Slack. ## Detection Engine - The detection engine analyzes billions of Slack events each day. - It combines rule-based heuristics with dynamic thresholds. - Thresholds are calibrated to each enterprise’s historical usage patterns. - This prevents normal high-volume activity in one organization from being treated as anomalous in another. - Adaptive thresholds help reduce false positives while allowing Slack to refine detection sensitivity over time. ## AER Architecture AER consists of three main components: - **Detection engine:** Identifies suspicious activity and creates anomaly audit payloads. - **Decision framework:** Validates detected behavior and determines whether it qualifies for automated response. - **Response orchestrator:** Carries out the configured response, including terminating user sessions. The overall flow is: 1. Suspicious user activity is analyzed. 2. An anomaly is detected. 3. The AER controller determines whether it is a supported anomaly and whether the organization’s settings require action. 4. Associated user sessions may be terminated. 5. The event is always recorded in audit logs. 6. Customer notifications are sent according to configured preferences. AER’s practical value is that it turns anomaly detection into immediate containment, helping organizations interrupt attack chains before attackers can complete data theft or compromise.

Read original(opens in new tab)
microsoft2 min readCurated summary

Common annotated security keys

GitHub’s improved security-token format demonstrated that fixed signatures and checksums can sharply reduce both false positives and missed secret detections. Microsoft applies these ideas across its services and proposes the open-source Common Annotated Security Standard (CASK), a shared format for identifiable secrets. CASK is intended to make scanning faster, more accurate, and easier to apply across an entire ecosystem without disrupting developers. ## Identifiable Secrets and Better Detection - “Identifiable” keys combine: - A fixed signature that reliably identifies the format. - A checksum that validates whether a detected string is a real key. - These features reduce scanner noise and missed findings. - Microsoft can hard-block identifiable keys from being stored in source code, work items, and similar locations with high confidence. - Scanners can detect the common format first and classify the specific service provider later, if needed. ## The Common Annotated Security Standard - CASK defines platform-agnostic requirements for minted security keys. - It reserves space for individual platforms and providers to encode service-specific metadata. - Microsoft has defined Azure-specific metadata within this reserved area. - A shared standard lowers the effort required for security tools to protect multiple service providers. - Other providers can adopt the same core format. ## CASK Key Requirements ### Alphanumeric Encoding - Keys use only the BASE62 alphabet. - Avoiding special characters allows keys to be transmitted without escaping or additional encoding. ### Strong Entropy - Each key contains 52 randomized encoded characters. - This provides approximately 310 bits of entropy. - The design is intended to prevent brute-force attacks, including in a post-quantum environment. ### Fixed Signatures - Every CASK key includes: - The standard signature `JQQJ`. - A provider-specific signature. - Microsoft observed `JQQJ` to be rare in both open-source and internal code, enabling fast and accurate detection. - Azure DevOps uses `AZDO` as its provider signature. - These signatures allow tools to detect CASK keys generically while still supporting provider-specific classification. ### Metadata and Testing Support - Keys include their creation month and year. - Timestamps support incident response and key-rotation enforcement. - CASK reserves dedicated test keys so developers can test scanners and security controls without exposing real credentials. - Microsoft plans to provide more details about Azure-specific metadata. Microsoft recommends that service providers adopt CASK and contribute feedback as the standard evolves.

Read original(opens in new tab)
figma2 min readCurated summary

The 6 design trends John Maeda predicted in his State of the Union | Figma Blog

John Maeda’s 2017 *Design in Tech Report* predicted rapid growth and transformation in product design. The article argues that companies increasingly need designers because technology has become easy to build, making user experience and emotional relevance key differentiators. However, fragmented tools and outdated education remain major challenges. ## Designer Hiring Surges - Major corporations are expanding their product design teams. - Companies such as Facebook, Google, and Amazon reportedly hired 65% more designers in the previous year. - More than 35 design agencies were acquired by large companies over two years. - As app development becomes commoditized, design determines how useful and meaningful products feel to people. ## More Inclusive Design - Technology’s broader reach requires products designed for people from varied backgrounds and experiences. - Companies including Airbnb, Slack, Google, and Microsoft were highlighted as leaders in inclusive design. - Inclusion is becoming both a social responsibility and a product-quality requirement. ## Design Education Falls Behind - Many design programs remain focused on print-era disciplines such as traditional typography. - Schools often fail to teach digital product design for web and mobile platforms. - More than two-thirds of surveyed students said they learned digital skills independently through resources such as Lynda.com. - Maeda expects educational institutions to change slowly because their structures and processes evolve deliberately. ## Design-Focused Investment - Venture capital is showing greater interest in companies built around design. - Two VC firms were reportedly launching with design-focused investment strategies. - Designers themselves show entrepreneurial interest: 80% of those surveyed said they would start a company if they had sufficient funding. ## Growing Number of Design Tools - Product design tools remain fragmented, supporting different workflows rather than one unified process. - Many companies are attempting to streamline collaboration and production. - Maeda warned that increasingly sophisticated tools could create more opportunities for machine intelligence and eventually reduce demand for some design work. ## Emerging Specializations - Voice-interface design is growing alongside products such as Amazon Alexa. - Cybersecurity is creating demand for specialized designers. - China is expected to become increasingly influential in the global design landscape. The outlook for technology and product design is strong, but the industry must address outdated education and disconnected workflows. Designers, companies hiring them, and toolmakers all have opportunities—especially to create more unified, collaborative design processes.

Read original(opens in new tab)