Thursday, July 23, 2026

Oracle AI Apps for Manufacturing - Customer Feedback during Strategy Council at Oracle MBX Event


Driving product strategy starts with listening to the customer. As the PMM for Oracle AI Apps for Manufacturing, I spearheaded the Strategy Council at Oracle MBX—an open-forum event where key customers shared direct feedback and strategic needs. Afterward, I published a deep-dive blog breaking down our key learnings, participant highlights, and immediate product priorities. The blog was post originally located on oracle.com here, but now is archived on archive.org here.











 

Wednesday, July 22, 2026

SIEM vs SOAR illustrated via the Tesla App

In IT security, the terms SIEM (Security Information and Event Management) and SOAR (Security Orchestration and Automated Response) sometimes causes confusion or are used interchangeably. A recent notification on a Tesla App will help to illustrate the differences.


On the Apple Watch, the owner received a notification from the Tesla App that they left the trunk open on their Tesla:





So let's map this to cybersecurity terms.

Tesla detects the trunk is open and notifies you → in the cybersecurity world, this is done by  SIEM

  1. It monitors the state of the system.
  2. It detects an event ("trunk left open").
  3. It alerts you.


Tesla app lets you tap a button to close the trunk → in the cybersecurity world, this is done by  SOAR (because human is needed to press the Close Rear Trunk button, this is the human in the loop version of SOAR)

  • The app is enabling a response.
  • In cybersecurity, SOAR goes a step further by automating the response or guiding it through a predefined workflow









In conclusion - using everyday experience of the Tesla App informing the owner that the trunk is open and allowing them to close the trunk remotely - this example can be mapped to cybersecurity SIEM versus SOAR:

  • SIEM: "Your trunk is open." (Detection + Alert)
  • SOAR (human in the loop): You tap Close Trunk. (Response orchestrated through the app)
  • SOAR (fully automated): If the trunk has been open for 5 minutes and no one is nearby, the car automatically closes it and logs the action. (Automated response)


Monday, July 20, 2026

Techniques in Punchy Writing

Techniques for Punchy Writing 


In response to "California Pizza Kitchen founder says California has become too difficult for entrepreneurs",  I wrote "Florida insurance rates causing a storm of protest".  What writing techniques am I using?







  1. Pun / Wordplay (primary technique)
    • The word "storm" has a double meaning:
    • A literal storm, evoking Florida's hurricanes.
    • A figurative storm, meaning a large public outcry or controversy.
    • This makes the headline more memorable and engaging.
    • Example : "I used to be a banker, but I lost interest"
  2. Metaphor
    • A "storm of protest" is a metaphor for an intense wave of criticism or complaints.
    • It doesn't mean there is an actual storm made of protests.
    • Example : "Life is a rollercoaster"
  3. Allusion
    • The headline subtly references Florida's association with hurricanes, even though it is discussing insurance rates.
    • This creates an immediate connection between the state's weather risks and its insurance market.
    • Example : "He is no Romeo"
  4. Emotive
    • "Storm of protest" suggests widespread dissatisfaction, making the issue sound significant without explicitly quantifying it.
    • Example : " Terrified employees face a heartbreaking holiday..." as the ruthless tech giant slashes thousands of jobs.

  5. News Style (Concise)
    • It compresses the cause ("Florida insurance rates") and effect ("storm of protest") into a short, punchy headline typical of newspapers.
    • Example : " ... as the ruthless tech giant Oracle slashes thousands of jobs."

In conclusion, writing a short punch headline requires a combination of elements that include 1) uses pun to play with word  2) uses of metaphors to find parallels in life  3) uses of allusion reference to already known people or events 4) emotive to trigger emotional response in the reader 5) conciseness because readers often exhibit TR/DL.






Wednesday, July 15, 2026

How Jira Lost Its Way (And How We’re Saving It in 2027)

Software project management is not about aesthetics, marketing buzzwords, or endless feature lists. It is about one cold, hard truth: delivering software predictably.


To do that, a team needs to track exactly three things: 1) What needs to be fixed (bugs and technical debt). 2) What needs to be enhanced (feature iterations). 3) What needs to be introduced (new, net-greenfield features).


Every single item in this trio requires a clear owner (who will do it) and a hard commitment (by when will it be done). This is the core, unvarnished function of Atlassian Jira. It is why Jira became the industry standard.


But let’s be honest about what happened.


The SaaS Renewal Trap

For years, Jira was a solid, highly configurable, easy-to-use tool. But as the industry shifted fully to a SaaS subscription model, a dangerous pressure took hold. In a world where customers renew every month or year, software companies feel a relentless itch to justify their subscription fees. Product teams are forced to prove they are "improving" the platform with every single sprint.  

Software Advice

This pressure created a toxic pattern: Breaking what already worked: Flawless, muscle-memory navigation pathways were suddenly hidden behind redesigned, clunky UI overlays. Fast-loading, utilitarian screens were replaced by heavy, slow-loading pages bloated with white space. Adding features nobody asked for: Or at the whim of the product manager.  Instead of mastering core ticket routing, speed, and clean sprint planning, Jira began introducing adjacent features and widgets that turned the product into a bloated solution looking for a problem.


Jira stopped focusing on helping developers ship code, and instead focused on justifying its own release notes. The tool we used to coordinate engineering became the very source of engineering drag.


Fast Forward to 2027: The Era of Judicious Releases

We heard you. The feedback from developers, product managers, and release engineers has been loud and clear: Stop changing things just to change them.


We are fundamentally shifting how we build and deliver Jira. Moving forward, Atlassian will be highly judicious with what we release. We are putting an end to the "forced experiment" era of SaaS.


Every new update, UI change, or feature rollout will now be strictly categorized into two clear, transparent buckets:






1. Must Adopts

These are non-negotiable updates. However, we will only slap the "Must Adopt" label on changes that directly improve speed, security, infrastructure stability, or core issue-tracking reliability. No more unexpected UI overhauls masked as mandatory updates. If we force an update on you, it's because it makes your daily standup faster, your queries snappier, or your deployment integrations more stable.


2. Try It and Tell Us

Want to try a new AI-assisted spec writer, a colorful roadmap visualization, or a new collaboration layout? They will live here. "Try It and Tell Us" features are strictly opt-in. They will remain hidden behind an admin toggle until they are thoroughly battle-tested by actual development teams. If the community tells us a feature is bloat, we throw it away. We will not pollute your workspace with solutions looking for problems.


Returning to the Core

Jira’s job is to get out of your way so you can answer three questions: What are we shipping, who is shipping it, and when is it landing?


By simplifying our release philosophy, we are stripping away the noise of the SaaS feature mill and returning Jira to what it was always meant to be: the reliable engine of predictable software delivery.

Tuesday, June 2, 2026

Introduction to Palo Alto Networks Cloud Wall

 

Introduction to Palo Alto Networks Cloud NGFW


As business compute infrastructure shifts from on-premise to the cloud, network security must evolve alongside it. Traditional defenses—like firewalls, IDS/IPS, deep packet inspection, and application-aware firewalls—all need a cloud-native counterpart. But how do you secure an infrastructure that no longer lives in your data center? The answer isn't just migrating your legacy hardware virtually. To truly protect your cloud environment without sacrificing performance, you need a solution built for the cloud—offering seamless scalability, unified management, and cost-effective protection without the burden of traditional hardware maintenance.

This is where Palo Alto Networks Cloud Next-Generation Firewall (Cloud NGFW) can help. It serves as an enterprise-grade, fully managed network security fabric for you modern cloud ecosystem. Delivered as a cloud-native Firewall-as-a-Service (FWaaS), it integrates Layer 7 visibility, deep learning threat detection, and automated scaling directly into hyperscaler environments like AWS and Microsoft Azure.

Rather than managing complex physical or manually provisioned virtual appliances, NetSec and DevOps teams can leverage Cloud NGFW to enforce unified Zero Trust policies with zero infrastructure overhead.


Strategic Traffic Protection Modes

Modern cloud architectures demand distinct traffic management rules depending on data directionality. Cloud NGFW automatically safeguards three critical vectors:

  • Inbound (North-South): Inspects incoming traffic to shield front-facing cloud applications, container clusters, and databases from external web-based threats and unauthorized access.

  • Outbound (North-South): Monitors and controls data leaving the cloud environment. This restricts connections to verified external repositories, prevents data exfiltration, and curbs command-and-control (C2) communication.

  • Lateral (East-West): Protects traffic moving between Virtual Private Clouds (VPCs), Virtual Networks (VNets), or individual workloads. If a single microservice is compromised, East-West inspection ensures the threat cannot traverse deeper into the network fabric.


Centralized Policy Enforcement: Cloud NGFW eliminates tool sprawl by integrating natively with cloud management portals (like AWS Firewall Manager and Azure Virtual WAN) while channeling unified global visibility and configuration control through Strata Cloud Manager.

Conclusion : Future-Proofing Cloud Network Security 

Migrating to the cloud shouldn't mean compromising on enterprise-grade security or drowning in operational complexity. By shifting from legacy hardware mindsets to a cloud-native fabric, organizations can eliminate the traditional trade-off between agile deployment and robust protection.

Palo Alto Networks Cloud NGFW bridges this gap. By embedding Layer 7 visibility, deep learning threat prevention, and automated scalability directly into the fabric of AWS and Azure, it ensures that inbound, outbound, and lateral traffic remain secure under a single pane of glass. Ultimately, Cloud NGFW allows NetSec and DevOps teams to stop managing security infrastructure and start focusing on what matters most: accelerating secure business growth in the cloud.


Core Architectural Pillars

ComponentOperational BenefitTechnical Execution
Fully Managed Cloud-Native Service0% Infrastructure OverheadPalo Alto Networks manages the underlying deployment, patching, and maintenance, backed by a 99.99% availability SLA.
Advanced Layer 7 Visibility (App-ID™)Context-Aware EnforcementBypasses basic port/protocol filtering to identify, monitor, and restrict traffic based on the specific application, user, and workload context.
AI-Powered Threat PreventionZero-Day MitigationUtilizes inline deep learning to analyze full data packets and stop evasive exploits, malware, and data exfiltration attempts in real time.
Elastic AutoscalingSeamless Resource AlignmentIntegrates natively with cloud infrastructure (e.g., AWS Gateway Load Balancer) to dynamically scale with burst traffic without causing latency or downtime.

Thursday, May 28, 2026

Tactics Used In Selling Snake Oil - Explained by AI

Sally is selling snake oil but no one is buying. To boost sales, she starts to talk at gatherings to drum up business. She starts by dispelling the fact the she is selling snake oil. "Some people out there don't know how great snake oil is. They haven't seen the real data and the testimonies on its efficacy.  They are brainwashed by the controlled media and the crooked government. These are the same people who voted to the party that allowed criminals enter the US and committing crimes." What tactic is Sally using?





Sally is using a mix of rhetorical and propaganda tactics. The main ones are:


  • Poisoning the well: She discredits critics before they can respond (“brainwashed by the controlled media and crooked government”), making people less likely to trust opposing views.

  • Ad hominem / attacking the audience: Instead of addressing evidence about the snake oil, she attacks the character or intelligence of skeptics and ties them to a disliked political group.

  • Appeal to conspiracy: Claiming “controlled media” and “crooked government” suggests hidden forces suppress “the truth,” which encourages distrust of mainstream criticism without needing proof.

  • Association / guilt by association: She links skepticism about snake oil to controversial political issues (“the same people who voted for…”), trying to transfer emotional reactions from immigration/crime debates onto her critics.

  • Appeal to in-group identity: She frames believers as enlightened truth-seekers and skeptics as manipulated outsiders, which can strengthen group loyalty.

  • Deflection from evidence: Rather than proving the snake oil works, she shifts the discussion toward culture-war and political grievances.

In informal terms, this is often described as a form of demagoguery or grievance-based persuasion: redirecting attention from the product’s merits to identity, distrust, and emotionally charged political themes.

Friday, May 8, 2026

Enterprise Resource Planning (ERP) = Business Software

Enterprises (aka large businesses) use software to run their business. This software is called "Enterprise Resource Planning", or ERP. Sounds fancier than "business software", no? So what is ERP, and how does it work? Let's create an imaginary company "ACME" that designs, manufactures, and sells its AeroGadget.



ACME, an Apple Wannabe 

ACME wants to be the next Apple. So like Apple, it wants to control the entire life cycle of its products. From design to manufacturing to marketing to sales. Meaning ACME owns the entire lifecycle of AeroGadget. ACME will 1) Design 2) Procure 3) Supply Chain Management 4) Manufacture 5) Market 6) Sell 7) Service to keep customers happy. 






ERP used in ACME 

The creation of the mechanical AeroWidget—a complex assembly of brass gears, engraved plates, and precision-tuned springs—requires more than just skilled craftsmanship. For ACME to successfully bring this gadget to market, it must employ a comprehensive Enterprise Resource Planning (ERP) system that unifies every department, from the workshop floor to the executive back office.



Engineering, Manufacturing, and Quality Control

The "soul" of the AeroWidget lies in its mechanical intricacy. The ERP system serves as the central nervous system for these physical processes:


Design & PLM: Product Lifecycle Management (PLM) modules manage the technical blueprints and gear-ratio schematics, ensuring that every design iteration is tracked.


BOM & Procurement: The system automates the Bill of Materials (BOM), coordinating the sourcing of raw brass, wood, and specialized gears from global suppliers.


Manufacturing & Quality: As units move through production, the ERP tracks real-time assembly progress and triggers "Engraving Tests" to ensure the high-fidelity aesthetic of the gadget meets ACME's standards.


Marketing, Sales, and Logistics

Turning a masterpiece into a product requires seamless market integration:


CRM & Sales: Customer Relationship Management (CRM) tools allow ACME to target collectors of luxury mechanical goods while managing incoming orders to prevent over-promising on stock.


Warehouse & Shipping: The ERP manages the delicate inventory and optimizes "Track & Trace" logistics, ensuring that the fragile glass-and-brass units are delivered safely via specialized transport.


The Back-Office Foundation: HR, Finance, and Accounting

While the gears turn in the widget, the ERP ensures the business gears turn behind the scenes:


Human Resource Management: The "Talent Pipeline" and "Workforce Management" modules ensure that ACME recruits and retains the specialized master horologists and engineers required for such a unique product.


Finance & Accounting: These modules provide "Capital Management" and "Ledger Control," balancing the high cost of raw materials against revenue. This ensures that every brass screw is accounted for in the company’s financial plans.


Service & Analytics: Finally, the system manages "Calibration Schedules" for field service and uses cross-functional data analytics to refine future production runs based on customer feedback.


Conclusion:

ERP is business software used by enterprises to run their business. ERP encompasses all business software - such as design, planning, supply chain, marketing, sales, human resource, finance, accounting.  By integrating these disparate functions into a single "ERP Flow," ACME can transform a complex mechanical challenge into a sustainable, scalable, and highly efficient luxury brand.

Tuesday, May 5, 2026

Why Do We Need SASE In Modern IT?

 Secure Access Service Edge (SASE)


  • Before I begin, let’s start with the basic definitions. Zero Trust is a concept of never trusting anyone, always verify, even if they are in the house. SASE is architecture. So all devices that need to access the corporate network will go to the cloud first to have the user verified. SD-WAN is an implementation of SD-WAN.

  • Ok on to SASE Secure Access Service Edge!




  • SASE in a nutshell : SASE is short for Secure Access Service Edge. In the olden days, to secure access to a company network, you had to go into the office to connect to the company network. But modern digital life means you can be anywhere, using any device, at any time. So a new, safe environment that is beyond the office walls is needed. Introducing SASE. With SASE, the office network reach is now global. The security guard now follows the worker - instead of the workers going to the office guarded by a security guard.







Sunday, May 3, 2026

Amazon One Palm Reader Discontinued In Amazon Grocery Stores (Whole Foods) Starting June 2026


Amazon One is a contactless, palm-based biometric identity service. It announced in September 29, 2020 in this news release as being  available in Amazon Go mini-market stores. Later on March 28th, 2024 with this news release. Amazon One palm reader payment is used at Whole Foods grocery markets (owned by Amazon). During check out, a shopper just puts their palm on a palm reader to pay. No app. No card. No cash.

Roughly over just 2 years later, Amazon announced earlier in 2026 that Amazon One biometric authentication will be fully discontinued for retail customers on June 3, 2026. It’s officially the end of an era for the "palm wave" at checkout.   The decision to pull the plug on the technology—which uses a combination of surface-area imaging and subcutaneous vein patterns—comes down to a few key factors:




1. The "Adoption Gap"

Despite the initial hype, Amazon reported that customer adoption simply never reached the critical mass needed to justify the overhead. Most shoppers remained more comfortable with the muscle memory of tapping a credit card or using a digital wallet (Apple/Google Pay), which offered similar speed without the perceived "creep factor" of biometric scanning.  


2. Privacy and Trust Hurdles

Biometrics are a tough sell in the current privacy climate. While Amazon emphasized that the data was encrypted and stored in a specialized "One" cloud rather than on-device, privacy advocates and even some members of Congress voiced concerns about surveillance and data security. For many users, the convenience wasn't worth the perceived risk of handing over a "palm signature" to a retail giant.  


3. A Massive Retail Pivot

The discontinuation of Amazon One is part of a much larger strategic retreat. Amazon is simultaneously shuttering its Amazon Fresh and Amazon Go physical locations to refocus its grocery efforts on Whole Foods Market and same-day delivery. Since those experimental stores were the primary "homes" for palm readers, the infrastructure no longer fit the new business model.  


4. High Operational Costs

Maintaining the hardware and the complex backend (which required real-time cloud authentication and seamless integration with various payment processors) is expensive. Without the volume of users to offset these costs, the ROI wasn't there—especially compared to standard NFC payments.  


What Happens Now?

Data Deletion: Amazon has stated that all user data, including palm signatures and associated payment info, will be automatically deleted once the service is fully decommissioned in June.  


The Healthcare Exception: Interestingly, the technology isn't dying everywhere. It will reportedly remain active for patient check-ins at specific healthcare facilities (like NYU Langone) for the time being, where the "identity verification" use case still holds some value.  


Alternative Tech: Amazon is shifting its focus to Dash Carts (the smart shopping carts that track items as you go) and its broader Just Walk Out licensing for third-party venues like stadiums.


It seems the world wasn't quite ready to pay with a high-five. Given the current trend toward Zero Trust and enhanced data sovereignty, a centralized biometric database for snacks was always going to be a steep hill to climb.


Are you looking for a more secure alternative for your own workflows, or were you mostly concerned about the data privacy aspect of the shutdown?

Thursday, April 23, 2026

Introduction to Microsoft Defender XDR

Windows Defender was originally a basic built-in antivirus that protected endpoints (namely PCs) running the Windows operating system. As endpoint attack vectors became more sophisticated, antivirus passively protecting an endpoint no longer sufficed. A holistic protection - including identities, emails, and infrastructure - was needed. This was when Windows Defender was rebranded to  Microsoft Defender.

 




Fast forward to today, Microsoft Defender is now the overarching brand that covers a series of related products that provide integrated threat protection across the entire digital estate, including endpoints, identities, email, applications, and multi-cloud infrastructure. Here are the products under the Microsoft Defender brand:


  • Microsoft Defender XDR: This is the unified dashboard/suite that includes:
    • Microsoft Defender for Endpoint 
    • Microsoft Defender for Office 365
    • Microsoft Defender for Identity
    • Microsoft Defender for Cloud Apps
  • Microsoft Defender for Cloud
  • Microsoft Defender Vulnerability Management
  • Microsoft Defender for IoT




What Is Microsoft Defender XDR

Microsoft Defender XDR (Extended Detection and Response) is an integrated suite of four security products, each providing a unique and needed defense against sophisticated attacks. Powered by AI, Microsoft Defender XDR  provides an always learning, adapting, and automated unified defense across your digital estate. The four included products in XDR are:


  • Microsoft Defender for Endpoint: Protects physical devices (Windows, macOS, Linux, Android, iOS). It provides both preventative antivirus and EDR (Endpoint Detection and Response) for hunting advanced persistent threats. 
  • Microsoft Defender for Identity: Uses your on-premises Active Directory or Entra ID (formerly Azure AD) signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
  • Microsoft Defender for Office 365: Safeguards your "collaboration" layer—protecting against malicious links (Safe Links) and attachments (Safe Attachments) in Outlook, Teams, SharePoint, and OneDrive.
  • Microsoft Defender for Cloud Apps: A Cloud Access Security Broker (CASB) that gives you visibility into your SaaS apps, helping to identify "Shadow IT" and protect sensitive data moving in and out of the cloud.



What Makes Microsoft Defender XDR Unique?

Microsoft Defender differentiates itself by moving beyond simple signature-based detection to behavioral AI and automation.

  • AI : Uses machine learning and cloud-delivered intelligence to block malware in real-time, even if the threat has never been seen before (Zero-day).
  • Attack Surface Reduction (ASR): A set of controls that prevent actions typically used by malware, such as launching executable files from email or blocking Office apps from creating child processes.
  • Self-Healing (AIR): Short for Automated Investigation and Response. When an alert is triggered, Defender can automatically launch an investigation, determine if a file is malicious, and remediate it (e.g., quarantine a file or stop a process) without human intervention.
  • Advanced Hunting: For security pros, this provides a powerful query language (Kusto Query Language or KQL) to search through 30 days of raw telemetry data to find hidden indicators of compromise.
  • The "Agentless" Advantage: Because the sensors for Defender are built directly into the Windows operating system, there is no third-party agent to install or update. This reduces "agent sprawl," lowers CPU overhead, and prevents the common "security vs. performance" conflict.


Conclusion

Microsoft Defender XDR represents a paradigm shift from traditional, siloed security to a unified, AI-native ecosystem.  Unlike third-party solutions, it requires no additional software installation, which eliminates compatibility issues and ensures peak system performance by minimizing CPU overhead  By integrating defense across endpoints, identities, email, and cloud apps, Microsoft Defender XDR seamlessly correlates telemetry across endpoints, identities, and cloud applications to eliminate the silos that attackers exploit. 

Tuesday, April 29, 2025

Connecting Supply Chain Networks : When One Plus One Made Three



 

 

Once upon a time, in a bustling digital world, there lived two companies: Fulcra and Velos.

Fulcra specialized in logistics and inventory. It could track every package in real time, optimize delivery routes with satellite precision, and move goods faster than anyone else. But Fulcra didn’t know what to move — only how to move it.

Velos, on the other hand, was an e-commerce titan. Its storefronts were beautiful, its marketing sharp, and its customer base global. But when orders poured in, chaos followed. Warehouses ran out of stock. Deliveries arrived late. Refunds stacked up.

Each company excelled at what it did. Yet both suffered in silence.

One day, a young analyst named Rina, who had worked briefly at both companies, saw the problem clearly: “These systems don’t talk to each other.”

She proposed something radical: a real-time connection between Fulcra’s logistics engine and Velos’s e-commerce platform. Orders placed in Velos would instantly inform Fulcra’s inventory and routing. Fulcra’s supply chain insights would feed back into Velos’s product availability and delivery promises.

At first, both companies resisted. “It’s too risky,” said Fulcra’s CIO. “We’ll lose control of our data,” Velos’s head of tech argued.

But Rina persisted. She ran a simulation — and it showed that with full integration, customer satisfaction would increase 30%, delivery times would drop by 40%, and operational costs would shrink.

“One plus one doesn’t just equal two,” she said. “It equals three — or more — when the systems are connected.”

With cautious optimism, the two companies launched Project Converge. APIs were built. Dashboards redesigned. Silos torn down.

The results were immediate.

Customers now saw accurate delivery times before they hit "Buy." Warehouses preemptively stocked products in areas with rising demand. Returns plummeted. Profits soared. Fulcra and Velos, once strong but isolated, became unstoppable together.

And Rina? She was promoted to lead a new initiative: connecting more systems across the ecosystem. She understood a powerful truth most businesses forget:

In isolation, systems work.
In connection, systems create.
And when 1 + 1 = 3, that’s the power of integration.

 



Tuesday, December 10, 2024

Hosting Ruby on Rails On Heroku Cloud and Coding with Cloud9 IDE


Hosting Ruby on Rails
On Heroku Cloud
Albert Chiang






1.    Ruby, Rail

Ruby is an Object-Oriented Programming scripting language and Rails (the Model View Controller web app framework developed using the Ruby language).  The purpose of this document is to show how to deploy a Ruby on Rails production website to Heroku cloud.  This will be demonstrated via a “Thanksgiving Potluck Signup” app running on Heroku (a Platform-As-A-Service).
 

2.    How I did it & source code

2.1.    Concept of the “Thanksgiving Potluck App”

Every year, my dear friend Neil invites others and I to his house for a Thanksgiving dinner potluck.   Neil usually brines and bakes a turkey, but he needs help from his guests to bring other dishes. He also wanted a way for guests to sign up for dishes, but did not want the dishes to overlap.  He used Evite to manage the email list and track who is coming, but tracking who was bringing what dishes was not easy to use. And being able to access the list via web or mobile web instantly via its own URI will make the app much easier to use.
                        
                                                  
Figure 1 Thanksgiving Potluck at Neil's

2.2.    Development environment

My development was on Cloud9 cloud IDE, which basically allowed me to use my browser to development and run my Rails web app.  It was easy enough to use, so I gave up using a Linux terminal and my trusty vi editor. Below is a screen shof of development on Cloud9 Cloud IDE
 




2.3.    Initial data model

For Neil’s Thanksgiving potluck, Neil wanted a simple guest registration system for the guests to use to register themselves. He wanted it to be accessible on both web and mobile. For each guest, Neil wanted to know these about his guests:
1.    Name of guest
2.    What food is being brought by the guest
3.    Total number of people coming
4.    Email of the guest

Further more, Neil said that it would be nice if the registration system can check for overlap in food brought.
 

2.4.     Initial scaffold creation using Rails

Rails is a framework that eases web app development and testing. The framework was designed to bring order to a potentially messy process of developing and testing web apps. But the framework also potentially adds extra baggage, especially for simple web apps. One way Rails eases the creation of the framework is via automated scaffold generation.  A Rails scaffold creates the necessary directory structure and pre-populated files.


2.5.    Seeding the database 

Now that we have a web app running, the framework of what to show (guest information) and how to manage it (edit, destroy, show) is built in and ready to use. But now we would like to have data in this web app. What is the fastest way to pre-populate data into it? We can populate the web app with data by using seed.
                                       

2.6.    Data migration

The data model was created using Rails and resides in the db/migrate directory as a Ruby file. But the Rails framework eventually will interact with a MySQL database. Rails has one built-in called SQLite3. In order to “migrate” the Ruby version of the data into SQLite3, the “rake db:migrate” is invoked. To double check the output of the migration into an sqlite3 file, I used  SQLite Free – Datum.
 


2.7.    Customize the User Interface View 

The Rails scaffold command creates a basic look on the View. Neil wanted a bit more customization in the web app – which means changes to HTML and CSS. In Rails, HTML is produced from processing Embedded Ruby files (erb) and CSS is produced from processing Sassy CSS (SCSS) files.  
                        s.
                                  

2.8.    Validating the data model

Neil preferred that guests not bring duplicate food.  He wanted the web app to warn a guest if the food to be brought was already registered. This is easily done in Rail using the “validates” concept. Neil also want to limit the number of  total guests, so a limit of 4 per guest is imposed by Neil.

2.9.    Route configuration

Ruby on Rails uses a Models View Control (MVC) design pattern. Which means that web app requests from users are sent to the Controller. But in Rails, before the user request is sent to the Controller, it is first routed through a Rails router.
            

2.10.    App testing
Rails was design with test in mind. With Rails, tests are easy to write, easy to run, and offers powerful abilities for test automation.
    
 
3.    Deployment to The World - Using Heroku PAAS & Git
Now that we have developed and tested our web app on my Macbook Pro, it is time to let other use it – by pushing the web app to production. Which means Neil and his guests can starting using the app from any web browser. But in order to push my Ruby on Rails environment to production, I need a way to host my Ruby on Rails application. This is where Heroku can help.

3.1.    What is Git
Git is a source code revision control system. Which allows you to store your source code into a safe place – called a repository.  Git in itself is a great software development tool to keep backups of your project , as well as keep revision control so that you can revert to previous version of your project.  But must we use Git?
The answer is yes – because we are using Heroku to push our project to production.
 


3.2.    Pushing to Heroku

Heroku offers Platform As A Service (PAAS) to deploy applications. In order to productize my web app, I first applied for a free Heroku account. Once established, the Linux command line can be used to control interaction with the Heroku Command Line Interface (CLI).  
 

3.3.    Differences Between Development and Production - PostgreSQL instead of SQLite
During the development of our Rails web app on my Macbook Pro, SQLite3 was the default Relational Database System (RDB) used with Ruby on Rails. SQLite3 is an embedded RDB, in contrast to MySQL – a full RDB environment. MySQL is part of Oracle, which leaves the Open Source community a bit nervous because Oracle makes money from selling  its own Oracle Database.
For those looking for pure open source RDB, PostgreSQL is the popular choice. Moreover, PostgreSQL is a Object Relational Database. Hence it is not surprising that Heroku supports PostgreSQL over SQLite.
 
 

3.4.    Production Web View
 





4.    Conclusion


Ruby is an object oriented scripting language targeted for web applications. Rails add a framework around Ruby so that code with specification functionality has a nature home in the framework. Rails adopt the MVC design pattern.  Ruby on Rails provides a proven and robust framework for web app development, testing, and production. Within a few short Rails command, a full web app is created.  Heroku cloud was picked as the public cloud hosting platform.

Wednesday, October 23, 2024

Simple Cybersecurity Intro

Introduction to Cybersecurity
 
Businesses of today have migrated to all in on digital - relying on smart phones, laptops, networks, programs, and data to operate. Gone are the analog days where businesses use papers, faxes, and even telephones to operate.  Using just a laptop or smart phone, customers from the other side of the planet can be ordering products and services from you 24/7 without a human slowing down the  experience and transaction. But that same ease of use for the customer far away is the same mechanism that hackers can use to 1) shutdown your business by disrupting your IT 2) steal your company's intellectual property information 3) steal your customer information 4) lock your business out of its data and ask for a ransom to unlock it 5) plant bots that run secretly and quiet to launch more attacks to steal and disrupt.   Cybersecurity is the practice of protecting all of the above systems : smart phones, laptops, networks, programs, and data - from digital attacks. Here is a diagram of a business IT system.
 

 

In order for a business to protect its IT from cyberattacks, here are some basic protections to take.

 

1) Identify all attempts to use and login into your IT system : people, machines, and now with AI - AI Agents. Following the IdAAA framework, your cybersecurity system must 1) Identify the user - who are you?! 2) Authenticate the user - prove who you are with what you know, what you have, what your are 3) Authorize the user - once identified and authenticated, look up the permissions. You don't want an engineer accessing HR or Financial systems 4)  Accounting - log and track all interactions

 

2) Endpoint : this is the ENTRY POINT into your critical IT systems : the programs, the network, the data. Early days of antivirus were passive and one dimensional. Today's attack sophistication means that your endpoint protection needs to keep up with new and complex attack vectors. EDR (Endpoint Detect and Response) and XDR (Extended Detect and Response) are the bare minimum of today.  

 

3) Network security : Old generation IDS (Intrusion Detection System) and IPS (Intrusion Prevention Systems)  were static and not ready for today's AI and Quantum Compute attacks on network. Start at the very least with Next Gen Firewall (NGFW)

 

4) Server : These are hardware that runs everything in IT. Server hardening, including secure boot, patch management, continuous monitoring, strict access controls (don't share root password!), redundancy

5) Application : This is the direct interface to your customers and hackers. Secure your apps with passwordless & MFA. Leverage OpenID Connect & OAuth 2.0 instead of building your own login system, modern apps use established protocols to outsource authentication to trusted identity providers. Define and implment fine-Grained Authorization: Moving beyond simple "User" or "Admin" roles to Attribute-Based Access Control (ABAC), where access is granted based on time, location, and the specific sensitivity of the data.

6) Storage: This is where your data ultimately lies, and hence a target for ransomware. Make sure your business performs backup, snapshoting, fine grain partition, encryption of data at rest, access anomaly detection.

7) Database : Programs rely on database to provide searchable, indexed, reliable curated data. Authorization by programs, users, and now AI agents is critical to keep business safe (confidential, with integrity). Like storage, need to backup, snapshoting, fine grain partition, encryption of data at rest, access anomaly detection.

Wednesday, October 16, 2024

Home Storage : Direct Attached Storage, Network Attached Storage, Over Firewire, USB-SATA, Ethernet

Storage has sort of been a interest of mine. Not only did i use it for primary storage, but also for backup, and in some cases, to boot an OS.  As I dug through my boxes of drives, I became amazed at the changes of storage through the years.  I have owned several different types of hosts (Windows, Mac, Linux), connector (Firewire, USB, SATA, IDE), and media (3.5" HDD, 2.5" HDD, 2.5" SSD). Here is a quick walk through of some of my setup:



1) Firewire to iMac HDD : on the "Intel Aluminum" iMacs, the Fireware port was supposedly a cool thing to have. So I bought a Firewire enclosure to fit a 3.5" HDD. Worked great, but later on found that USB drives were ok too.

2) 3.5" SATA HDD : this might have been one of my first SATA drives that pivoted away from messy IDE.

3) USB DAS : I used this Direct Attached Storage as a desktop unit to backup my Windows laptop. Its slick shape made it look appealing on my desk.

4) NAS : this was my first Network Attached Storage, configured to RAID 0 because I really needed space (so there is no redundancy of data - bad!). This particular model also can host an Apache Web Server with a MySQL database.

5) 2.5" SATA SSD : this small for factor was idea for laptops and NUCs. I found this cheaper than to buy a "proper" flash USB drive. Had to buy a SATA to USB connector to use the SSD as plug in storage.

6) Boot macOS from 2.5" SATA SSD : I wanted to have a sandbox macOS environment, and so I installed macOS on to the external 2.5" SATA SSD and boot my Macbook from it.

Friday, January 12, 2024

Introducing Dr Data 2024

A data professional is an individual with expertise in managing and analyzing data to derive meaningful insights. They work with various data sources, databases, and tools to collect, organize, and interpret information. Data professionals may have skills in data cleaning, transformation, and visualization, as well as statistical analysis and machine learning. They play a crucial role in helping organizations make informed decisions based on data-driven evidence. (1)

Because the data profession is such a deep field, the major includes :

  • enterprise storage engineer
  • data engineer
  • database administrator
  • data analyst
  • data scientist
  • machine learning engineer

 


 


Each title in its own right is a full profession. In future blogs, I will cover in detail the responsibilites of each profession - as told by Dr Data 2024!


(1) ChatGPT "User give a summary of a data professional"

(2) DALL-E "mad scientist, name tag is "Dr Data", surrounded by data, cartoon style"

Wednesday, December 13, 2023

VR, AR and MR Path to Adoption (2023)

Introduction

Virtual Reality (VR)  has found moderate success in consumer applications, such as gaming. Major gaming manufacturers including Sony, Nintendo, and Microsoft, all have dabbled in VR to a limited success. For example, Nintendo hastily released its Virtual Boy back in 1995. Due to a combination of poor design and  headaches from use, it was unceremoniously pulled off the market in 1996. Note : I was one of the few who benefited from this and was able to snag one from Target's clearance shelf.  Augmented Reality (AR) early usage was in Heads Up Display (HUD) in aircraft to overlay important information in front of the pilot, in car information system, and now consumer and industrial use. Mixed Reality (MR) is now helping to drive the future of VR and AR with  product releases such as Meta Oculus Quest family of MR googles, Microsoft Hololens Mixed Reality googles adoption by the U.S. Army Integrated Visual Augmentation System (IVAS), and awaiting Apple to finally launch its Vision Pro to validate the MR market.

   

Quick Definitions

Virtual Reality (VR) : You buy special goggles (usually called VR goggles - which does not have a camera to pass outside world in), put it on, and everything you see in the goggles is not real (virtual). Augmented Reality (AR): You use an every day device (say mobile phone), aim its camera at a thing (say a building), and additional information about the building is overlaid on to screen of the mobile phone. Mixed Reality (MR):  You buy special goggles (usually called MR goggles - which have cameras to pass outside world in), put it on, and and you see both real world and virtual world visuals.  This is where all the action is, with : Meta Quest (version 3 launched October 2023), Microsoft HoloLens (version 2),  Apple Vision Pro (not yet released, but website is up).

 

Enterprise Adoption

Fast forward to 2018. I am at Mobile World Congress (MWC) in Barcelona to explore how emerging technologies, including VR and AR, is making inroads into industrial applications. Here at the show, AR seem to have gained a stronger traction over VR. VR is a bit "intrusive" in its use model - usually requires donning special glasses or goggles - and if the Nintendo Virtual Boy is of any predictor, adoption might be resisted. AR, on the other hand, is less intrusive - usually only requires holding up a tablet (such as an iPad) or mobile phone (such as iPhone) towards a "re-conditioned" environment.






Gaming Adoption

In spite of early failures, gaming manufacture continue to power through early design challenges to try to  bring VR back to dizzy gamers. SonyVR, Microsoft Hololens 2, and new challengers such as Meta Quest VR Headsets are not giving up the fight to make VR right. In fact, Meta's vision for VR is not squarely targeted at gamers. Rather, it is targeted at those who want to be transported to an alternative reality called The Metaverse.  Meta has already sunk over $20 billion in 2021-2022 and will continue to invest in it - in hardware, software, and content. As an Oculus Quest owner, I have already enjoyed transporting myself to space, looking out at a serene and calm environment - away from the polluted and contentious planet that I want to escape from. 






Daily Life Adoption

AR has now been quietly gaining traction as a utility to improve daily life. In a recent trip to The Hague, I exited the metro and had no idea where to go.  On my moderately new iPhone (Android has this feature too), I have already installed the Google Map app. Google Map gave me the option of using my iPhone to augment information on top of what my camera sees. So from the metro station, I pointed my phone at a nearby building, and Google Maps was able to identify the building, and it proceeded to guide me on where to walk to. Digging into the technology a bit - Apple has made combining maps and camera data easier via its ARKit software libraries.





E-Commerce Adoption

With the mobile phone as the primary way for consumer to discover, learn, and buy products, AR is now enabling the consumer to explore, visualize, and imagine the product more immersive. This picture was taken at MWC. But if you are a Amazon Prime subscriber, you probably have seen AR features to overlay products (such as a lamp) onto your living room.


Keys To Adoption : Content

As a semi-avid gamer for decades, I have owned almost every major gaming console from Atari, Sega, Nintendo, Sony,  Microsoft, and Meta. And from a casual observation, I can say that games sells consoles. That is why every gaming console has a must have launch title  - such as Microsoft's Halo and Nintendo's Legend of Zelda.  Looking at VR, AR, and MR, it will be games and content and a killer app that drives adoption.  In Oct 2023, wedged between the launch for Meta's Quest 3 and the 2023 holiday season, NPR writes Meta Quest 3 review: powerful augmented reality lacks the games to back it up.  And Microsoft's long and contentious $70B acquisition of Activision highlights this phenomenon - Bill Gates was right 20+ years ago when he wrote the "Content is King" essay.

 



How to Scale Contention for VR, AR, MR

Make creation of  virtual worlds easier by further leveraging tools that have already been used to do this such as Unity3D or Unreal Engine. Enable easier 3-D modeling of real world assets, perhaps open source versions of builder tools such as Blender,  Maya (Autodesk), or 3ds Max. Lower  Write code to implement the functionality of your VR experience. This includes user input handling, interaction mechanics, and any custom features.  Use the chosen game engine's scripting language (e.g., C# in Unity, C++ in Unreal

 

Conclusion

MR, AR, and VR is continuing to refine the future of human to machine engagement. It has had a rough start - early failures of Nintendo's Virtual Boy,  soldiers complaining of headaches with Microsoft Hololens,  the snail pace transition to the Metaverse.  But if the gaming industry (and its tools) has anything to teach us - it is that Content is King.

Friday, November 3, 2023

Path from VM to Containers

Business require software to run their operations. These software were written using a software pattern called Model-View-Controller (MVC), bundled into a single software package called monolith (because everything that the software needed to do was bundled into that one software package). That software run on-premise hardware as Virtual Machines. Because those virtual machines ran on on-premise hardware, the business needed to pay for an IT team, plus give them a budget to procure/install/configure/maintain/patch/upgrade/backup. If the software required more compute or storage (say during the holidays when orders are streaming in), IT was summoned to scale up and follow the aforementioned long process - which was as bottleneck. Cloud solved the IT bottleneck issue, where the need to own your own on-premise hardware and the IT team was eliminated. If that need that software to be able to scale up during the holidays, and be accessible from around the planet, while remaining resilient. Also if one of the MVC components of the software failed (which is 8/9 of the combinations), the software dies. Virtual Machines could not keep up with the requirements to scale and be resilient. Problems with monolithic software that ran on virtual machines gave rise to micro-services that ran on Kubernetes containers. Micro-services broke the single monolithic software package into micro pieces, so that when one piece fails, the others run to keep the software running just enough. And microservices did not need the overhead of virtual machines that were designed to run huge monoliths, so containers were invented. Kubernetes is just management software that track containers.

Monday, July 24, 2023

Seeing New Insights From Data - Thanks to Datalakes running on G-DB



Geo-Data + Social = New Business Intelligence & Insights


Whereas much of the enterprise business analysis has been focused on RDBMS and Big Data sales transactions to test hypothesis and create reports, the adoption of geo-data on business transactions is an area of huge opportunity. Several companies and industries have already adopted geo-data and are reaping financial benefits. For example, UPS is using geo-data to optimize truck delivery routes, aiming for as many right turns at traffic intersections as possible. This will result in an anticipated $50M saving per year. 




Enterprise Insights Exploration of Geo-Data + Social







If you looked at your favorite social media apps, you will find that they want to track your location. These apps take your location—combined with what you are doing, how you feel, who you are with, and why you are there—provide invaluable and difficult to obtain insights about you. For example, if on January 21, 2017, between 2PM-8PM, you were at location 37.79° N, 122.39° W, and you tweeted that you were feeling happy and civic, you were probably part of the Women’s March in San Francisco. Hence, a certain marketing profile can be built up on you for target marketing.




Enterprise Insights   Exploration Hampered by a Lack of Data Diversity




A business analyst, seeing the value of geo-data, wants to perform an ad-hoc query. She has data from Women’s March with an estimated 4 million marchers nationwide. She can query who was at the start location of the Washington D.C. March (38.88° N, 77.01° W), at the starting time (1:15 PM EST), and Tweeted or Liked positively. This is the profile of a enthusiastic, conscientious person. The analyst can also query who was at the end location of the March (38.89° N, -77.03° W), but at the starting time of the March— perhaps a supporter or reporter.  Acting on the speed of thought, the analyst wants access to billions of rows of data, to draw a perimeter of the map to localize around the start of the March, focus on the start time, and filter by contextual data. And after that, try again with another set of criteria so that she can constantly refine her hypothesis to reach a conclusion.  But currently, each click will cause minutes or even hours of calculations before results are seen. This is due to the nature of CPUs – limited number of cores, memory speed, and the types of instructions it excels at.





Augmenting IT Data with  OT Data

Querying a database requires processing cores and fast memory. CPU based servers is limited up to only 22 processing cores and fairly fast memory. CPUs need to be clustered together to be able to serve the queries of billions of rows of data. Another type of processor, called GPU, has thousands of cores and very fast memory. The cores in the GPU process data in parallel and pass data extremely fast to memory. GPUs are so powerful that a single GPU server can sometimes replace multiple clusters of CPU servers. GPU can save money, reduce labor, lower energy consumption, and reduce space over CPU.








Whilst GPU is a great match for looking through billions of records in milliseconds, a database optimized for GPU is needed. That’s where G-DB comes in. G-DB offers two synergistic products – G-DB Server and G-DB Visual. G-DB Query is a GPU optimized database. It is an in-memory, columnar data highly optimized to harness the power of thousands of cores in the GPU.  Every SQL query that you submitted is broken down and re-targeted to run in parallel on thousands of GPU cores. That’s how we are able to return queries on billions of rows in milliseconds.  But the magic doesn’t stop there. Synergistically, GPU is also ultrafast at drawing the output of the query results. This is where G-DB Visual comes in. It renders the results of your queries immediately – so that you can use your eyes to help you brains to discover insights immediately.



Conclusion

Transaction, geo-data, and social media combined will enable insights into people not possible before.  Processing billions of rows of this type of data will be slow and/or expensive on a CPU based system, making this valuable data inaccessible. But GPU based systems, like G-DB, can handle this type and size of data with ease. With G-DB, not only can you gain insights at the speed of thought, you have ultrafast high fidelity visuals to match.