Techlist.io - Korean Tech Blog Curator

figma2 min readCurated summary

All Your Questions About Variables Answered (and a Few You Didn’t Even Know You Had) | Figma Blog

Figma’s latest variable updates expand design customization while bringing design systems closer to code. Variables can now control more visual properties and respond to different modes, making responsive, platform-specific designs easier to manage. The post presents variables as more flexible than traditional tokens and highlights their potential for both practical systems work and highly creative prototypes. ## Variables Enable Broader Customization - Designers are using variables for applications ranging from production design systems to interactive, game-like creations. - Unlike regular tokens, variables are open-ended and support more flexible customization. - Figma points to Headspace as an example of using variables to improve design-system efficiency and collaboration with developers. - Beginners can start with Figma’s dedicated variables guide and community file. ## New Properties That Support Responsive Design - **Reactive effects:** Variables can control blur sizes, drop-shadow colors, and offset distances, allowing effects to change by mode. - **Dynamic stroke weights:** Designs can use different stroke weights for platforms such as desktop and mobile. - **Layer opacity:** Opacity fields can be bound to variables for more nuanced visual control. - **Adaptable layout grids:** Grid settings can switch between modes, supporting pixel-perfect desktop and mobile layouts. - **Individual corner radii:** Each corner radius can be controlled independently through variables. - **Nested instance variant binding:** Variables can be applied to component instances nested within other components, enabling more complex component structures. ## Connecting Design and Code - The updates are intended to align design variables more closely with how values are managed in code. - Mode-based values make it easier to represent platform, theme, or responsive differences within a single design system. - Figma indicates that typography is an area planned for further variable support. Overall, the post recommends adopting variables as a flexible foundation for scalable design systems, responsive interfaces, and richer prototypes—especially when designers and developers need a shared source of truth.

Read original(opens in new tab)
figma3 min readCurated summary

Dev Mode: Building a Design Tool that Works Harder for Developers | Figma Blog

Figma built Dev Mode to make developers first-class participants in product design rather than secondary users of a designer-focused tool. The team initially emphasized code generation, but real-world differences in teams, workflows, and codebases exposed its limitations. By combining developer research, the acquisition of Visly, and a broader focus on inspection and collaboration, Figma shifted toward reducing the gap between design and code. ## Designing for Developers as Core Users - Figma’s multiplayer canvas was created for entire product teams, including product managers and developers. - Developers were already using Figma to explore work in progress, despite the tool not being optimized for their workflows. - By 2023, developers represented roughly one-third of Figma’s users. - The goal became a tailored developer experience that did not require developers to learn or navigate design-centric interactions. - Proposed directions included: - Component playgrounds - Code snippets - GitHub and Storybook integrations - Developer-specific resources - Design inspection and change comparison ## The Visly Acquisition - Figma acquired Visly in 2021, bringing in eight designers and engineers who had built a React UI development tool. - The Visly team contributed: - Extensive research into developer tooling - Practical experience with development workflows - A developer-oriented perspective and intuition - Their involvement accelerated Figma’s efforts and helped the company understand how developers work across different environments. ## Moving Beyond a Codegen-First Strategy - Early versions of Dev Mode focused on code generation: automatically translating designs into code according to predefined rules. - Codegen could save hours or even days when designs mapped cleanly to implementation. - Testing showed that successful code generation in controlled scenarios did not necessarily work in production. - Companies differ in their: - Team structures - Engineering practices - Toolchains - Codebases - Workflow conventions - These variations made it difficult to generate universally useful code, prompting the team to reconsider codegen as the central solution. ## Redefining Design-to-Code Handoff - Figma’s broader objective was to break down the traditional “handoff wall” between designers and developers. - Dev Mode was positioned as a dedicated space where developers could inspect designs, compare changes, work with VS Code, and access implementation-oriented information. - The team continued refining the product through beta feedback, including daily customer requests collected through an internal Slackbot. - Rather than assuming developers would live inside a design tool, Figma focused on making the parts of the design process they needed more accessible and useful. Dev Mode’s central lesson is that developer tooling must reflect real engineering practices, not just generate code from idealized designs. A practical developer experience combines accurate design context, collaboration, integrations, and workflow flexibility with code generation where it genuinely helps.

Read original(opens in new tab)
figma3 min readCurated summary

The Figma + Adobe Deal, Explained | Figma Blog

Figma’s post explains why it believed its proposed acquisition by Adobe would benefit users and withstand regulatory scrutiny. It presents Figma as a collaborative tool for building digital products, distinct from Adobe’s traditional creative software, and emphasizes a broad, fast-changing competitive landscape. However, the deal was ultimately abandoned on December 18, 2023, after the companies concluded that regulatory approval was unlikely. ## Figma’s Role in Digital Product Development - Figma describes itself as a web-based platform for teams building apps and websites. - Its tools support multiple stages of development: - **FigJam** for brainstorming and concepting - **Figma** for interface design and prototyping - **Dev Mode** for helping developers translate designs into code - The company says it spent thousands of hours explaining its products and market to competition regulators. ## Product Design vs. Traditional Graphic Design - Figma focuses on creating interactive digital products rather than static advertisements, illustrations, or posters. - Building an app or website requires collaboration among designers, developers, product managers, and other specialists. - This broader, team-oriented workflow has contributed to the growth of the product development software market. ## A Broad and Competitive Market - Figma portrays its market as highly dynamic, with both comprehensive platforms and specialized tools. - Competitors and adjacent products mentioned include: - Sketch, Penpot, and Figma - Miro, Flinto, Anima, ProtoPie, and Zeplin - Salesforce’s low-code development tools - The company argues that new startups and products enter the market frequently, while AI is accelerating innovation. - Figma says its competitive landscape slide became outdated only three weeks after it was created. ## Adobe’s Position - Adobe XD had previously competed with Figma but was placed into maintenance mode after Adobe stopped developing new features. - Photoshop and Illustrator serve different purposes, such as photo editing and advanced illustration. - Figma argues that those tools are not designed for collaborative website and application development. ## The Proposed Benefits of Combining Figma and Adobe - Figma contributes collaborative product design and development expertise. - Adobe contributes widely used creative tools and access to hundreds of millions of users. - Figma argued that the companies’ complementary strengths could create new consumer benefits, including closer connections between design, creativity, and product development. - The proposed acquisition was announced on September 15, 2022, as a major collaboration between the companies. ## Regulatory Outcome - Despite Figma’s efforts to demonstrate that the deal would benefit users and occur in a competitive market, regulatory concerns continued for fifteen months. - On December 18, 2023, Figma and Adobe abandoned the proposed acquisition because they no longer saw a path to regulatory approval.

Read original(opens in new tab)
figma3 min readCurated summary

Config 2024: Designing a Better Conference | Figma Blog

Config 2024 is presented as a community-centered conference shaped by lessons from Figma’s previous events. Scheduled for June 26–27 in San Francisco, it aims to improve both the learning program and attendee experience through reserved breakout seating, more developer content, expanded networking, and greater accessibility. Figma’s goal is to make Config a broader, more inclusive gathering for everyone involved in building products. ## A Community-Driven Conference - Config has grown from its first 1,000-person conference in 2020 into a larger global community. - Figma describes the event as more than a product conference: it is intended to support learning, idea-sharing, and celebration of craft. - The 2024 program is expected to include more than 75 speakers covering design systems, AI, development, and related topics. ## Reserved Seating for Breakout Talks - Attendees can reserve places in breakout sessions instead of relying on available seating. - Registered attendees are guaranteed a seat if they arrive on time. - Very early bird ticket holders receive access to session registration 24 hours before other attendees. ## More Content for Developers - Figma is expanding programming specifically for developers. - The developer track reflects the company’s aim to serve everyone who contributes to building digital products. - Additional details about this programming were still forthcoming when the announcement was published. ## Improving In-Person Connections - The schedule will include more downtime for networking, informal conversations, and community interaction. - A larger event footprint is intended to reduce lines and crowding. - Figma expects the changes to create a smoother overall attendee experience. ## Supporting a Global Audience - Virtual attendees will receive captions in English, French, German, Japanese, Korean, and Spanish. - In-person attendees will have access to simultaneous interpretation and translation. - Figma plans to continue adding languages to future events. ## Expanding the Leadership Collective - The executive-focused Leadership Collective will return after positive feedback in 2023. - The track will include more content, a new executive briefing center, and additional networking opportunities. - Participation is invite-only, with applications available during registration. ## Registration and Participation - Very early bird tickets were available through Config’s registration site. - Scholarships were offered for qualifying attendees. - Figma invited the community to submit ideas and suggestions by email or social media. - The call for speakers was open, with applications due by December 31, 2023. Overall, Figma’s approach is to combine product announcements and educational sessions with better logistics, accessibility, and community interaction. The event is designed for designers, developers, executives, and other people involved in building products.

Read original(opens in new tab)
figma2 min readCurated summary

Figma’s State of the Designer Report 2023 | Figma Blog

Designers appear more satisfied and optimistic despite the disruption of the past three years. Figma’s survey of 470 designers in Europe and Asia–Pacific examines how remote and hybrid work have affected collaboration, productivity, career prospects, and fulfillment. Its central conclusion is that designers are adapting successfully, while the growing strategic importance of design is improving both morale and opportunity. ## Remote Work and Job Satisfaction - 69% of designers report greater job satisfaction than before the pandemic. - Individual contributors are especially positive: 82% say their satisfaction has improved. - Designers generally feel more in control of where and how they work. - Many believe their workflows and ability to create high-quality digital products have improved, even as remote work has become more common. - Group meetings and collaborative design practices are helping teams work together remotely. ## Design’s Growing Influence - Nearly five times as many designers feel more positive about the design profession as feel more negative. - Design is increasingly viewed as a business-wide way of thinking rather than a function limited to one department. - Visible support from CEOs and other executives reinforces designers’ sense that their work is strategically important. - Leaders who participate in design files, give direct feedback, and experience product development firsthand create stronger connections with design teams. ## Improved Career Prospects - 69% of respondents say their employment options have improved or greatly improved. - Designers are encouraged by organizations placing design at the center of product and business decisions. - The profession’s growing influence is changing how designers view their roles and future opportunities. The report suggests that remote collaboration and increased executive engagement have helped designers feel more satisfied, empowered, and optimistic. Organizations can build on this momentum by supporting flexible work, investing in collaborative practices, and treating design as a core part of business strategy.

Read original(opens in new tab)
figma2 min readCurated summary

Little Big Updates: When going big means thinking small | Figma Blog

Figma argues that meaningful product progress often comes from small, frequent improvements rather than headline features. Because designers may spend 40 or more hours a week in Figma, reducing friction in everyday workflows can have a greater cumulative impact than adding rarely used capabilities. Its annual “Little Big Updates” initiative formalizes this focus on quality, usability, and user joy. ## Why Small Improvements Matter - Subtle changes can save users clicks, eliminate recurring frustrations, and fix long-standing bugs. - Figma users invest heavily in learning the tool, creating a responsibility for Figma to continually improve it. - Quality-of-life updates are difficult to market, but often affect the actions users perform most frequently. - A small improvement repeated hundreds of times a day can matter more than a flashy feature used occasionally. ## The Origin of Little Big Updates - Figma originally released product updates weekly. - After accumulating four updates, the team released one per day from Monday through Thursday. - Users compared the experience to opening a new present each day. - This response inspired the “Little Big Updates” format, which gives individual improvements their own attention. ## Examples of High-Impact Details - Figma fixed paste behavior that previously placed content in seemingly random locations. - Although the change was not headline-worthy, it removed a frustration users encountered hundreds of times daily. - Text selection when switching between frames was also improved, eliminating unnecessary double-clicking. - These examples show how workflow friction can be more important than feature novelty. ## Prioritizing Big and Small Features - Major initiatives, such as AI features for FigJam, require deliberate planning and coordination. - Large features may need to be sequenced carefully so related capabilities work together. - Small improvements should be prioritized differently: teams should avoid over-planning and allow decisions to remain decentralized. - Individual teams are often best positioned to identify which usability improvements will have the greatest effect. - Every team should treat product quality as an ongoing responsibility, not as a secondary concern. Figma’s recommendation is to balance ambitious new capabilities with sustained attention to everyday details. Product teams can create substantial user value by identifying frequent sources of friction and steadily removing them.

Read original(opens in new tab)
figma2 min readCurated summary

Three Creator Fund projects to know and love | Figma Blog

The Figma Creator Fund supports creators building free plugins, widgets, templates, and educational resources for Figma Community. Since launching in March, it has awarded nearly $300,000 to 13 creators in nine countries, reaching almost a million users. The post highlights how these grants help creators solve difficult, practical problems while keeping their tools freely available. ## The Creator Fund’s Purpose - The program funds resources that expand what creators can do in Figma. - Supported projects include: - Mandarin-language design systems tutorials - Developer-platform education tools - Design-to-code plugins - Free templates and widgets - Figma prioritizes projects that: - Address challenging problems - Save users time - Offer practical value - Can remain free for the wider community - Applicants are encouraged to present a clear vision, invest effort in their application, prepare visuals, and pursue ideas they genuinely care about. ## Figma to Code by Bernardo Ferrari - Based in Curitiba, Brazil, Bernardo Ferrari created Figma to Code, a plugin that converts Figma designs into: - HTML - Tailwind CSS - Flutter - SwiftUI - The project began during the COVID-19 pandemic, when Bernardo helped rebuild a state-level virus-tracking website. - Although he had not worked extensively with web development since 2015, he used Figma as a bridge between design and implementation. ## Problems with Existing Design-to-Code Tools Bernardo found that existing plugins were limited because they were: - Too slow - Dependent on too many steps - Paywalled for full functionality - Incomplete in their support for Figma’s API - Missing important capabilities such as auto layout - Restricted to a single programming language or framework - Weak at handling responsive design and accessibility He spent two months building his own plugin, which launched in July 2020. ## Using the Grant to Modernize the Plugin - Figma and web frameworks evolved significantly after the plugin’s release, but the plugin had fallen behind. - Earlier limitations included: - Only horizontal and vertical padding - Auto layout support limited to “min” and “fixed” - The Creator Fund gave Bernardo the resources to update the plugin without introducing a paid tier. - The grant also enabled him to add support for Figma’s Dev Mode. - He completed the major update in roughly a month and launched it during Config 2023. - Bernardo describes the fund committee as supportive and encouraging toward creators with ambitious ideas. The post’s supplied excerpt ends during Bernardo’s account of launching the update at Config 2023, before the other Creator Fund projects are presented.

Read original(opens in new tab)
figma2 min readCurated summary

Introducing AI to FigJam | Figma Blog

FigJam’s new AI features are designed to solve practical collaboration problems rather than serve as a novelty. Users can generate meeting templates and diagrams from plain-language prompts, summarize brainstorms, and automatically organize sticky notes. Figma argues that this lowers the barrier to visual collaboration while helping experienced users move more quickly from ideas to action. ## AI-Powered FigJam Features - Generate templates for weekly syncs, brainstorms, reviews, and other meetings. - Create visual timelines and organizational charts from a simple prompt. - Summarize the contents of a brainstorm or meeting. - Sort and group sticky notes by theme automatically. - Customize generated outputs based on common workflows and best practices. ## Lowering the Barrier to Visual Collaboration - FigJam AI lets users describe their goals in everyday language instead of learning specialized design software. - A prompt such as “I need a meeting with four people” can produce an initial meeting template. - This approach makes visual collaboration more accessible to people without design backgrounds. - It supports Figma’s goal of “lowering the floor and raising the ceiling”: making the product easier to use while expanding what users can accomplish. ## Solving the Blank Canvas Problem - Starting with an empty FigJam file can make users unsure how to begin. - AI acts as an initial brainstorming partner, helping users move toward actionable next steps. - Tasks such as summarizing complex discussions or synthesizing ideas into categories can take significant manual effort. - Automating this work allows teams to focus on discussion, decision-making, and higher-level collaboration. ## Building AI Around Real User Problems - Figma says its product team drew on its own experience using FigJam to identify useful applications. - The features focus on everyday collaboration needs rather than adding AI for its own sake. - Templates and prompts are based on established practices and common use cases. - The article presents generative AI as a way to make visual tools more useful and approachable across disciplines. FigJam AI is positioned as a practical assistant for getting started, organizing information, and reducing repetitive work. Its main value is helping more people participate in visual collaboration without requiring them to master design tools first.

Read original(opens in new tab)
datadog2 min readCurated summary

Engineering spotlight: Jeromy Carriere | Datadog

Datadog announces that Gartner has named it a Leader in the 2026 Magic Quadrant for Observability Platforms. The provided content does not include the report’s evaluation criteria or detailed rationale, but it presents Datadog as a broad observability platform spanning infrastructure, applications, data, logs, security, digital experience, software delivery, and AI. ## Gartner Recognition - Datadog highlights its position as a Leader in Gartner’s 2026 Magic Quadrant for Observability Platforms. - The linked resource appears to provide the full Gartner-related announcement and assessment. ## Broad Observability Coverage - **Infrastructure:** infrastructure, container, network, serverless, GPU, storage, and cloud-cost monitoring. - **Applications:** APM, service monitoring, continuous profiling, dynamic instrumentation, and agent observability. - **Data and logs:** database monitoring, data-stream and job monitoring, log management, sensitive-data scanning, and observability pipelines. - **Security:** code, cloud, workload, vulnerability, compliance, SIEM, and application/API protection. - **Digital experience:** real-user monitoring, session replay, synthetic monitoring, product analytics, mobile testing, and error tracking. - **Software delivery and service management:** CI visibility, test optimization, feature flags, incident response, SLOs, workflow automation, and developer portals. - **AI capabilities:** AI agents, investigation tools, GPU monitoring, integrations, MCP support, and AI-assisted chat and coding. Datadog’s positioning rests on consolidating telemetry and operational workflows across the technology stack. To understand the Gartner recognition in depth, readers would need the linked report, since the supplied excerpt contains the announcement and product navigation but not the supporting analysis.

Read original(opens in new tab)
datadog3 min readCurated summary

Engineering spotlight: Jeromy Carriere

Jeromy Carriere, Datadog’s SVP of Product Engineering, describes engineering leadership as balancing strategy, execution, people development, and organizational processes. His career across Google, Facebook, and Datadog shaped his passion for observability and taught him to lead through mistakes, autonomy, and accountability. He argues that sustained innovation requires both intentional direction and space for teams and individuals to grow. ## The Responsibilities of Engineering Leadership - Carriere’s work shifts with organizational cycles: - Quarterly planning focused on connecting initiatives and increasing collaboration. - Execution periods focused on removing resource and decision-making blockers. - Ongoing performance management across the broader engineering organization. - He works on how Engineering operates, including: - Process definition and improvement. - Hiring and performance management. - Reviewing design documents and code. - Observing incidents and postmortems. - His central challenge is balancing attention across strategy, execution, people, and technical quality. ## From Cloud Monitoring to Datadog - At Google in 2014, Carriere helped create a cloud monitoring offering because Google Cloud lacked capabilities comparable to Datadog. - He later worked on observability at Facebook and developed a strong interest in improving developer and engineer productivity. - He returned to Datadog after seeing its ability to innovate and deliver products with sustained velocity. - He emphasizes that velocity means more than moving quickly: it requires direction, strategy, and consistency over time. ## Learning Through Mistakes - Carriere believes the most valuable lessons come from making and owning mistakes. - Earlier in his career, he was sometimes too directive, limiting team creativity and ownership. - At other times, he was too distant and failed to provide enough support. - His current leadership approach aims to: - Give teams substantial autonomy. - Provide support when needed. - Hold teams accountable for agreed-upon outcomes. - He also learned that people may not have a clear five-year career plan. Leaders should help them identify the work that provides satisfaction and enables them to perform at their best. ## Creating Space for Career Decisions - People often become focused on the immediate task and overlook other possibilities. - Carriere recommends deliberately stepping back to observe: - What activities feel satisfying. - What opportunities exist nearby. - What kinds of work could better match an individual’s strengths and interests. - This reflection requires intentional time and freedom rather than waiting for clarity to emerge automatically. ## The Value of Co-op and Internship Programs - Carriere credits the University of Waterloo’s co-op program with giving him early experience as a professional software developer. - The combination of strong academic training and repeated, high-quality industry placements helped connect theory with real work. - He sees a similar benefit in Datadog’s internship program, where interns are trusted with meaningful projects and often produce some of the company’s strongest work. Datadog’s engineering approach, as described by Carriere, combines strategic product velocity with thoughtful organizational support. For both leaders and individual contributors, the practical recommendation is to learn from mistakes, create room for reflection, and build environments where people have autonomy, meaningful work, and accountability.

Read original(opens in new tab)
figma2 min readCurated summary

Storyboarding the Future of Design and Creativity | Figma Blog

The post imagines how a Figma–Adobe partnership could transform design workflows by connecting products, assets, collaboration, AI, and storytelling. It envisions a future where ideas move instantly from user research to interactive storyboards, 3D models, prototypes, and marketing videos. The proposed merger was ultimately abandoned in December 2023 after the companies concluded regulatory approval was unlikely. ## From User Journeys to Storyboards - User journeys could be converted from basic sticky-note diagrams into visual storyboards. - More engaging formats would make it easier for teams to understand, discuss, and improve product experiences. ## Connected Assets Across Tools - Assets created in Adobe Substance 3D could be placed into Figma mockups. - Linked assets would remain synchronized, reducing manual updates across products. - Shared design systems could connect colors, fonts, and other design tokens between Adobe and Figma. - Adobe Fonts could become available directly within Figma. ## Multiplayer Collaboration in 3D - Adobe’s 3D tools could gain Figma-style multiplayer collaboration. - Multiple designers could work simultaneously on different aspects of a model, such as geometry, lighting, and textures. - Real-time collaboration could make learning complex 3D workflows easier. ## Generative AI in Product Design - Adobe Firefly could integrate directly into Figma workflows. - Designers could generate backgrounds that match an interface’s visual style. - Generative Fill could extend images to fit responsive layouts without leaving the design process. ## Prototypes Connected to Marketing - Working app prototypes could be inserted directly into launch videos. - Updates made to the product could automatically appear in the video, helping marketing teams keep pace with last-minute design changes. The post presents these integrations as a vision for a more connected and collaborative creative ecosystem, though the planned Figma–Adobe merger did not proceed.

Read original(opens in new tab)
figma2 min readCurated summary

Figma Participates in TISAX Assessment for the European Automotive Industry | Figma Blog

Figma announced its participation in the Trusted Information Security Assessment Exchange (TISAX), a security and compliance benchmark for Europe’s automotive industry. The assessment is intended to reassure automotive customers that their design files are securely managed according to industry standards. Figma positions TISAX alongside its broader European data-protection efforts, including EU Cloud Code of Conduct certification and EU-based file hosting. ## TISAX and Automotive Data Security - TISAX is governed by the ENX Association on behalf of the German Automotive Industry Association (VDA). - It is widely recognized as a data-security and protection benchmark in Europe’s automotive sector, particularly in Germany. - Participation gives automotive product designers greater confidence that their Figma work is handled securely and compliantly. ## Figma’s Assessment Details Figma’s participation can be verified through the ENX portal using: - **Company:** Figma, Inc. - **Scope ID:** S3XH77 - **Assessment ID:** AV01AK-2 ## Broader European Compliance Efforts Figma describes TISAX as part of its wider investment in serving European customers: - It has received a compliance mark under the **EU Cloud Code of Conduct**. - Customers can choose to host Figma and FigJam files within the **European Union**. - These measures complement Figma’s broader security and compliance program. Figma’s participation in TISAX signals that organizations in the European automotive industry can use its collaborative design tools with greater assurance about security, compliance, and regional data-handling requirements.

Read original(opens in new tab)
figma2 min readCurated summary

How Figma’s data science and user research teams weave together insights that count | Figma Blog

Figma’s data science and user research teams combined quantitative and qualitative methods to understand why notifications were not driving enough collaboration. Data revealed where users dropped out of the notification funnel, while user research explored the reasons behind those behaviors. Their synthesis showed that the biggest issue was not interaction with notifications, but that many users were never receiving them, leading to new alert types and changes to notification recipients and timing. ## Building a Cross-Functional Process - Data Scientist Caitlin Hudon and Researcher Jennifer Sanders began with a teamwide FigJam brainstorm. - They reviewed notification funnel metrics, including the percentages of users who: - Were eligible for notifications - Received them - Viewed them - Interacted with them - The team identified strategic questions, potential notification types, and data gaps. - Questions were divided according to whether data science or user research was best suited to answer them. - Caitlin and Jennifer maintained close communication while conducting their separate investigations, treating quantitative and qualitative work as complementary rather than independent. ## Understanding the Notification Funnel - Figma notifications can arrive through email, Slack, mobile devices, the file browser, the system tray, or the desktop app. - Notification events include comments, replies, reactions, invitations, editing access, and @mentions. - Users must move through several stages before engaging: - All Figma users - Users eligible for notifications - Users who receive notifications - Users who view them - Users who interact with them - Quantitative analysis showed what users were doing at scale. - User research was needed to understand why users behaved that way, since people may not always accurately explain their own motivations. ## Finding the Biggest Opportunity - The activity team initially needed to determine which stage of the funnel deserved attention. - Cross-functional analysis revealed that most users were not receiving notifications at all. - This shifted the focus away from simply improving notification engagement. - The main opportunities were to create new alert types and reconsider who should receive notifications and when. ## From Insights to Impact - Figma’s activity team began running notification experiments based on the combined findings. - A new notification type was released to address major user pain points. - The broader goal is to help teams stay connected and collaborate effectively across Figma and FigJam. The case demonstrates that product teams get stronger, more actionable conclusions when behavioral data is paired with direct user research.

Read original(opens in new tab)
figma2 min readCurated summary

Server-side sandboxing: Virtual machines | Figma Blog

Virtual machines provide strong workload isolation by separating guest systems from the host and from one another through a hypervisor. However, VMs are not a complete security solution: hypervisor vulnerabilities can enable escapes, while compromised workloads may still abuse network access or credentials. Figma therefore treats VMs as one layer in a broader defense-in-depth sandboxing strategy. ## The VM Security Model - A VM acts like an independent computer with its own CPU, memory, disk, and operating system. - The hypervisor manages multiple VMs on a physical host and enforces separation between: - The host and guest VMs - Individual guest VMs - The primary escape risk is a **VM escape**, in which malicious code breaks through the guest boundary and accesses the host or other guests. - Hypervisors provide a useful security boundary, but they have a large and complex attack surface because they mediate operating-system and hardware operations. - Cloud providers such as AWS and Microsoft Azure rely heavily on hypervisor-based VM isolation, meaning most cloud workloads inherently depend on this boundary unless they use bare-metal instances. ## VM Permissions and Blast Radius - Preventing VM escapes is only one part of the security model. - A compromised workload may still: - Make network calls to exfiltrate data - Invoke other services - Abuse credentials assigned to the VM - VM capabilities must therefore be restricted to limit the damage caused by a compromised job. - Security depends not only on the hypervisor, but also on carefully controlling the guest’s permissions, network access, and available resources. ## Engineering Trade-offs - VMs generally offer stronger isolation than lighter-weight mechanisms such as containers and seccomp. - Their disadvantages include greater operational complexity, resource overhead, and dependence on the security of the hypervisor. - Building or deeply analyzing a specialized hypervisor requires substantial expertise because of its broad attack surface. - In many cloud environments, relying on VMs is unavoidable, so teams should focus on reducing guest privileges and layering additional controls around the VM. A VM should be treated as a strong isolation boundary, not an all-purpose security guarantee. The safest design combines hypervisor isolation with restricted permissions, controlled networking, and other defenses that minimize the impact of a compromised workload.

Read original(opens in new tab)
figma2 min readCurated summary

Server-side Sandboxing: An Introduction | Figma Blog

Server-side sandboxing helps contain the damage caused by vulnerabilities in software that processes untrusted user input. This is especially important for image processing, parsing, compression, and thumbnailing libraries often written in memory-unsafe languages, as demonstrated by ImageTragick. Figma argues that sandboxing complements—rather than replaces—secure coding by limiting a compromised workload’s access to data, services, and infrastructure. ## Why Server-Side Sandboxing Matters - Modern SaaS applications must process user-generated content using complex libraries. - Many of these libraries are written in C or C++, which are vulnerable to memory-corruption bugs. - ImageTragick showed how a vulnerability in ImageMagick could enable remote code execution when processing user-supplied images. - Preventing every vulnerability through rewrites, memory-safe languages, or program analysis is expensive and imperfect. - Sandboxing provides defense in depth by containing failures when vulnerabilities are exploited. ## Figma’s Server-Side Risk - Figma uses server-side components such as RenderServer, a C++ version of the editor, along with third-party libraries for graphical data. - Malicious input processed directly inside production infrastructure could allow an attacker to: - Access data belonging to other jobs - Make requests to internal production services - Move laterally through the environment - Compromise additional systems - Sandboxing reduces the external interfaces and resources available to potentially compromised workloads. ## Common Sandboxing Approaches - The article introduces three major sandboxing primitives: - **Virtual machines (VMs):** Isolate workloads through a hypervisor and separate guest operating systems. - **Containers:** Isolate workloads using operating-system-level mechanisms and container engines. - **Seccomp:** Restricts the system calls a program is permitted to make. - Each approach involves trade-offs in security properties, operational complexity, performance, and suitability for different workloads. - The article’s broader goal is to help teams compare these options and select an appropriate combination of isolation techniques. ## Choosing an Appropriate Strategy - Sandboxing technologies have historically been expensive, immature, or difficult to operate at scale. - Recent improvements have made virtualization, containment, and workload isolation more practical for a wider range of security teams. - Teams should evaluate sandboxing based on their workload’s risk, required interfaces, resource needs, and acceptable operational trade-offs. Teams should treat sandboxing as a practical layer of defense around risky processing workloads, rather than relying solely on preventing vulnerabilities.

Read original(opens in new tab)