Thursday, October 1, 2026

What Is Trust & Safety?

 

What Is Trust & Safety?

Trust & Safety seems like a boring topic. So to make it hit home, I will start with a real life example of how it protects us - and how Google stays compliant to government regulations. To illustrate how it works, look at a two-sided marketplace like the Google Play Store, which connects developers who build and sell apps with Android users who install them. Trust & Safety (T&S) is the discipline within digital platforms responsible for minimizing real-world harm, preventing abuse and fraud, and ensuring the platform complies with laws while remaining a fair, predictable environment for everyone who uses it.








How Is Trust & Safety implemented in Google Play and Android?

In Google Play and Android, Trust & Safety (T&S) is not just a policy enforcement layer—it is an end-to-end discipline 1)  built directly into the operating system and 2) app distribution pipeline. It safeguards billions of users and developers through continuous, defense-in-depth protections:

  • Pre-Launch App Integrity: Developer verification, automated security scans, and human review enforce policies against malware, deceptive behaviors, and unauthorized data access before apps reach the Play Store.

  • On-Device Runtime Protection: Through Google Play Protect, the system continuously monitors apps on the device, analyzing daily app behaviors and instantly neutralizing malicious software in real time, even if installed from third-party sources.

  • OS-Level Architecture: Android embeds safety fundamentals into the platform itself via application sandboxing, scoped storage, strict runtime permission prompts, and hardware-backed credential storage.

  • Ecosystem Fairness & Compliance: Dedicated teams detect fraud, mitigate financial abuse, enforce child and family safety standards, and ensure regional regulatory compliance—preserving a transparent, predictable marketplace for legitimate creators.



User Expectations (Trusting the Platform)

Users trust the platform to act as a protective barrier between their device and unknown software. Specifically, users expect:

  • Malware & Abuse Prevention: Apps must be free of viruses, spyware, trojans, ransomware, and deceptive monetization tricks (e.g., hidden recurring charges or unauthorized background activity).

  • Payment & Transaction Security: Sensitive financial details (credit cards, banking credentials) are encrypted, handled safely, and safeguarded against payment fraud.

  • Developer Authentication & Accountability: The platform verifies the real identity of developers (via corporate registration, D-U-N-S numbers, or government IDs) so malicious actors cannot repeatedly deploy scams behind anonymous accounts.

  • Data Privacy, Isolation & Transparency:

    • No Secret Spying: The platform prevents apps from harvesting behavioral or usage data outside their designated boundaries. For instance, private usage of a sensitive app (like a dating or financial app) should not leak to third-party ad brokers or other apps on the phone.

    • In-App Data Isolation: Operating systems enforce sandboxing and scoped storage—private photos, messages, or biometric data stored within one app cannot be accessed or scraped by another app without explicit user permission.

    • Transparency: Clear disclosures (such as standard Data Safety labels) explaining what data is gathered, why it is needed, and whether it is shared.

Developer Expectations (Trusting the Platform)

Developers invest significant capital and time into building software. They expect the platform to provide an equitable, secure commercial foundation:

  • Reliable Monetization: Prompt, accurate payouts whenever users purchase an app, subscribe, or buy in-app items.

  • Digital Rights Management (DRM) & Piracy Prevention: Safeguards that prevent code theft, reverse engineering, unauthorized sideloading, or bypassing in-app billing.

  • Fraud & Abuse Shielding: Protection from fraudulent chargebacks, organized review-bombing campaigns, and copycat apps that infringe on their brand or intellectual property.

  • Predictable Policy Enforcement: Clear guidelines, transparent review turnarounds, and accessible human appeals rather than arbitrary automated bans that jeopardize their business.

Google’s Needs (Platform Needs To Meet Regulatory & Legal Compliance)

Trust & Safety extends beyond platform-specific terms of service; it must align with regional and international law:

  • COPPA (Children’s Online Privacy Protection Act): Restricts the collection of personal data from children under 13, requiring verifiable parental consent.

  • GDPR (General Data Protection Regulation) & CCPA/CPRA: Governs user privacy, data portability, consent requirements, and the explicit "right to be forgotten" across Europe and California.

  • PCI-DSS (Payment Card Industry Data Security Standard): Strict operational and technical requirements for processing card transactions securely.

  • HIPAA (Health Insurance Portability and Accountability Act): Regulates how protected health information (PHI) is handled by covered healthcare tools and services.

  • EU Digital Services Act (DSA) & Digital Markets Act (DMA): Enforces algorithmic transparency, risk assessments, illegal content removal obligations, and fair platform access rules.

The Bottom Line

Trust & Safety is the structural framework that balances these three forces: protecting users from harm and privacy violations, protecting creators from exploitation and fraud, and enforcing legal guardrails so the entire ecosystem can operate sustainably at scale.


Verification vs Validation

Verification vs Validation


Validation : are we building the RIGHT product? 




Verification : are we building the product RIGHT? 






Thursday, July 23, 2026

Oracle AI Apps for Manufacturing - Customer Feedback during Strategy Council at Oracle MBX Event


Driving product strategy starts with listening to the customer. As the PMM for Oracle AI Apps for Manufacturing, I spearheaded the Strategy Council at Oracle MBX—an open-forum event where key customers shared direct feedback and strategic needs. Afterward, I published a deep-dive blog breaking down our key learnings, participant highlights, and immediate product priorities. The blog was post originally located on oracle.com here, but now is archived on archive.org here.











 

Wednesday, July 22, 2026

SIEM vs SOAR illustrated via the Tesla App

In IT security, the terms SIEM (Security Information and Event Management) and SOAR (Security Orchestration and Automated Response) sometimes causes confusion or are used interchangeably. A recent notification on a Tesla App will help to illustrate the differences.


On the Apple Watch, the owner received a notification from the Tesla App that they left the trunk open on their Tesla:





So let's map this to cybersecurity terms.

Tesla detects the trunk is open and notifies you → in the cybersecurity world, this is done by  SIEM

  1. It monitors the state of the system.
  2. It detects an event ("trunk left open").
  3. It alerts you.


Tesla app lets you tap a button to close the trunk → in the cybersecurity world, this is done by  SOAR (because human is needed to press the Close Rear Trunk button, this is the human in the loop version of SOAR)

  • The app is enabling a response.
  • In cybersecurity, SOAR goes a step further by automating the response or guiding it through a predefined workflow









In conclusion - using everyday experience of the Tesla App informing the owner that the trunk is open and allowing them to close the trunk remotely - this example can be mapped to cybersecurity SIEM versus SOAR:

  • SIEM: "Your trunk is open." (Detection + Alert)
  • SOAR (human in the loop): You tap Close Trunk. (Response orchestrated through the app)
  • SOAR (fully automated): If the trunk has been open for 5 minutes and no one is nearby, the car automatically closes it and logs the action. (Automated response)


Monday, July 20, 2026

Techniques in Punchy Writing

Techniques for Punchy Writing 


In response to "California Pizza Kitchen founder says California has become too difficult for entrepreneurs",  I wrote "Florida insurance rates causing a storm of protest".  What writing techniques am I using?







  1. Pun / Wordplay (primary technique)
    • The word "storm" has a double meaning:
    • A literal storm, evoking Florida's hurricanes.
    • A figurative storm, meaning a large public outcry or controversy.
    • This makes the headline more memorable and engaging.
    • Example : "I used to be a banker, but I lost interest"
  2. Metaphor
    • A "storm of protest" is a metaphor for an intense wave of criticism or complaints.
    • It doesn't mean there is an actual storm made of protests.
    • Example : "Life is a rollercoaster"
  3. Allusion
    • The headline subtly references Florida's association with hurricanes, even though it is discussing insurance rates.
    • This creates an immediate connection between the state's weather risks and its insurance market.
    • Example : "He is no Romeo"
  4. Emotive
    • "Storm of protest" suggests widespread dissatisfaction, making the issue sound significant without explicitly quantifying it.
    • Example : " Terrified employees face a heartbreaking holiday..." as the ruthless tech giant slashes thousands of jobs.

  5. News Style (Concise)
    • It compresses the cause ("Florida insurance rates") and effect ("storm of protest") into a short, punchy headline typical of newspapers.
    • Example : " ... as the ruthless tech giant Oracle slashes thousands of jobs."

In conclusion, writing a short punch headline requires a combination of elements that include 1) uses pun to play with word  2) uses of metaphors to find parallels in life  3) uses of allusion reference to already known people or events 4) emotive to trigger emotional response in the reader 5) conciseness because readers often exhibit TR/DL.






Wednesday, July 15, 2026

How Jira Lost Its Way (And How We’re Saving It in 2027)

Software project management is not about aesthetics, marketing buzzwords, or endless feature lists. It is about one cold, hard truth: delivering software predictably.


To do that, a team needs to track exactly three things: 1) What needs to be fixed (bugs and technical debt). 2) What needs to be enhanced (feature iterations). 3) What needs to be introduced (new, net-greenfield features).


Every single item in this trio requires a clear owner (who will do it) and a hard commitment (by when will it be done). This is the core, unvarnished function of Atlassian Jira. It is why Jira became the industry standard.


But let’s be honest about what happened.


The SaaS Renewal Trap

For years, Jira was a solid, highly configurable, easy-to-use tool. But as the industry shifted fully to a SaaS subscription model, a dangerous pressure took hold. In a world where customers renew every month or year, software companies feel a relentless itch to justify their subscription fees. Product teams are forced to prove they are "improving" the platform with every single sprint.  

Software Advice

This pressure created a toxic pattern: Breaking what already worked: Flawless, muscle-memory navigation pathways were suddenly hidden behind redesigned, clunky UI overlays. Fast-loading, utilitarian screens were replaced by heavy, slow-loading pages bloated with white space. Adding features nobody asked for: Or at the whim of the product manager.  Instead of mastering core ticket routing, speed, and clean sprint planning, Jira began introducing adjacent features and widgets that turned the product into a bloated solution looking for a problem.


Jira stopped focusing on helping developers ship code, and instead focused on justifying its own release notes. The tool we used to coordinate engineering became the very source of engineering drag.


Fast Forward to 2027: The Era of Judicious Releases

We heard you. The feedback from developers, product managers, and release engineers has been loud and clear: Stop changing things just to change them.


We are fundamentally shifting how we build and deliver Jira. Moving forward, Atlassian will be highly judicious with what we release. We are putting an end to the "forced experiment" era of SaaS.


Every new update, UI change, or feature rollout will now be strictly categorized into two clear, transparent buckets:






1. Must Adopts

These are non-negotiable updates. However, we will only slap the "Must Adopt" label on changes that directly improve speed, security, infrastructure stability, or core issue-tracking reliability. No more unexpected UI overhauls masked as mandatory updates. If we force an update on you, it's because it makes your daily standup faster, your queries snappier, or your deployment integrations more stable.


2. Try It and Tell Us

Want to try a new AI-assisted spec writer, a colorful roadmap visualization, or a new collaboration layout? They will live here. "Try It and Tell Us" features are strictly opt-in. They will remain hidden behind an admin toggle until they are thoroughly battle-tested by actual development teams. If the community tells us a feature is bloat, we throw it away. We will not pollute your workspace with solutions looking for problems.


Returning to the Core

Jira’s job is to get out of your way so you can answer three questions: What are we shipping, who is shipping it, and when is it landing?


By simplifying our release philosophy, we are stripping away the noise of the SaaS feature mill and returning Jira to what it was always meant to be: the reliable engine of predictable software delivery.

Tuesday, June 2, 2026

Introduction to Palo Alto Networks Cloud Wall

 

Introduction to Palo Alto Networks Cloud NGFW


As business compute infrastructure shifts from on-premise to the cloud, network security must evolve alongside it. Traditional defenses—like firewalls, IDS/IPS, deep packet inspection, and application-aware firewalls—all need a cloud-native counterpart. But how do you secure an infrastructure that no longer lives in your data center? The answer isn't just migrating your legacy hardware virtually. To truly protect your cloud environment without sacrificing performance, you need a solution built for the cloud—offering seamless scalability, unified management, and cost-effective protection without the burden of traditional hardware maintenance.

This is where Palo Alto Networks Cloud Next-Generation Firewall (Cloud NGFW) can help. It serves as an enterprise-grade, fully managed network security fabric for you modern cloud ecosystem. Delivered as a cloud-native Firewall-as-a-Service (FWaaS), it integrates Layer 7 visibility, deep learning threat detection, and automated scaling directly into hyperscaler environments like AWS and Microsoft Azure.

Rather than managing complex physical or manually provisioned virtual appliances, NetSec and DevOps teams can leverage Cloud NGFW to enforce unified Zero Trust policies with zero infrastructure overhead.


Strategic Traffic Protection Modes

Modern cloud architectures demand distinct traffic management rules depending on data directionality. Cloud NGFW automatically safeguards three critical vectors:

  • Inbound (North-South): Inspects incoming traffic to shield front-facing cloud applications, container clusters, and databases from external web-based threats and unauthorized access.

  • Outbound (North-South): Monitors and controls data leaving the cloud environment. This restricts connections to verified external repositories, prevents data exfiltration, and curbs command-and-control (C2) communication.

  • Lateral (East-West): Protects traffic moving between Virtual Private Clouds (VPCs), Virtual Networks (VNets), or individual workloads. If a single microservice is compromised, East-West inspection ensures the threat cannot traverse deeper into the network fabric.


Centralized Policy Enforcement: Cloud NGFW eliminates tool sprawl by integrating natively with cloud management portals (like AWS Firewall Manager and Azure Virtual WAN) while channeling unified global visibility and configuration control through Strata Cloud Manager.

Conclusion : Future-Proofing Cloud Network Security 

Migrating to the cloud shouldn't mean compromising on enterprise-grade security or drowning in operational complexity. By shifting from legacy hardware mindsets to a cloud-native fabric, organizations can eliminate the traditional trade-off between agile deployment and robust protection.

Palo Alto Networks Cloud NGFW bridges this gap. By embedding Layer 7 visibility, deep learning threat prevention, and automated scalability directly into the fabric of AWS and Azure, it ensures that inbound, outbound, and lateral traffic remain secure under a single pane of glass. Ultimately, Cloud NGFW allows NetSec and DevOps teams to stop managing security infrastructure and start focusing on what matters most: accelerating secure business growth in the cloud.


Core Architectural Pillars

ComponentOperational BenefitTechnical Execution
Fully Managed Cloud-Native Service0% Infrastructure OverheadPalo Alto Networks manages the underlying deployment, patching, and maintenance, backed by a 99.99% availability SLA.
Advanced Layer 7 Visibility (App-ID™)Context-Aware EnforcementBypasses basic port/protocol filtering to identify, monitor, and restrict traffic based on the specific application, user, and workload context.
AI-Powered Threat PreventionZero-Day MitigationUtilizes inline deep learning to analyze full data packets and stop evasive exploits, malware, and data exfiltration attempts in real time.
Elastic AutoscalingSeamless Resource AlignmentIntegrates natively with cloud infrastructure (e.g., AWS Gateway Load Balancer) to dynamically scale with burst traffic without causing latency or downtime.