Techlist.io - Korean Tech Blog Curator

datadog2 min readCurated summary

How Datadog's IT team automated account inactivity and SaaS spend management | Datadog

Datadog’s IT team built an automated system to identify inactive user accounts and reduce unnecessary SaaS spending. The approach replaces manual audits with data-driven workflows that detect inactivity, notify users or owners, and reclaim unused licenses while preserving access controls and accountability. ## Automating Account Inactivity Detection - The system monitors account activity across SaaS applications. - It identifies users who have not logged in or used assigned tools for a defined period. - Automated notifications give users or managers an opportunity to confirm continued business need. - Accounts can then be suspended, deprovisioned, or escalated for review. ## Managing SaaS Spend - Inactivity data is used to find unused or underused licenses. - IT can reclaim seats instead of continuing to pay for unused subscriptions. - Usage information supports more accurate renewal and purchasing decisions. - Centralized automation reduces the manual effort required to audit many applications. ## Governance and Operational Benefits - Standardized workflows make account reviews more consistent across tools. - Automated approvals and escalation paths provide visibility into decisions. - The process helps balance cost reduction with security and user access requirements. - IT teams gain a repeatable way to manage the growing complexity of SaaS environments. Organizations with substantial SaaS usage can apply the same model: centralize activity data, define inactivity policies, automate notifications and approvals, and connect the results to license reclamation and access-management workflows.

Read original(opens in new tab)
datadog3 min readCurated summary

How Datadog's IT team automated account inactivity and SaaS spend management

Datadog expanded its Clarity auditing tool into Clarity License Manager (CLM), a system that tracks SaaS usage, reduces licensing costs, and improves security. CLM identifies inactive accounts, notifies employees, automatically deactivates unused access, and restores it quickly when needed. Its microservice architecture and application-specific adapters allow the system to scale across many SaaS products. ## The SaaS License Management Problem - Datadog used many commercial SaaS tools with substantial per-user costs. - License usage data was outdated and collected through quarterly manual audits. - IT Support had to contact employees individually, creating administrative overhead and a poor user experience. - Unused accounts also created security risks, including stale credentials that could be compromised. ## Goals of Clarity License Manager - Monitor and automatically deactivate inactive accounts, especially in sensitive services such as cloud providers. - Reduce the risk of leaked or abused stale credentials. - Limit the potential impact of security incidents. - Lower SaaS spending and support data-driven licensing decisions. - Preserve employee productivity through an easy account restoration process. ## Usage Monitoring and Automated Workflows - CLM gathers activity data through: - Direct integrations with individual SaaS APIs. - Google Workspace SAML audit logs for indirect integrations. - Employee activity is stored per application in an Amazon RDS-backed PostgreSQL database. - Employees receive email and Slack notifications after a configurable period of inactivity, with 90 days as the default. - Notifications explain the specific login or application action required to remain active. - If the employee does not respond after multiple reminders, CLM deactivates the account automatically. - Employees can reopen access by submitting a Freshservice ticket. - Accounts are restored within seconds, including their previous roles and permissions. ## Microservice Architecture - CLM consists of Python microservices running on AWS Lambda. - The services share a central PostgreSQL database. - Microservices provide: - Easier scaling as Datadog adds more SaaS applications. - Greater resilience and flexibility. - A modular foundation for future development. - The architecture introduced complexity because services required different APIs and libraries with overlapping functionality. ## Application-Specific Adapters - Each SaaS product is represented by an adapter shared across CLM microservices. - Adapters isolate application-specific API logic from the core workflows. - A typical adapter supports operations such as: - Retrieving users. - Fetching login activity. - Activating and deactivating accounts. - Onboarding and offboarding users. - This design provides: - Clear separation of responsibilities. - Reusable and flexible integration code. - Simpler microservices that do not need to handle each application’s unique behavior. CLM demonstrates how automated usage monitoring can simultaneously improve SaaS security, reduce unnecessary spending, and minimize disruption for employees. A modular adapter-based architecture is particularly useful when managing a growing portfolio of third-party applications.

Read original(opens in new tab)
figma2 min readCurated summary

Config 2022: Thinking big and acting with urgency | Figma Blog

Figma’s Config 2022 centered on the idea that designers and builders can influence major global and local challenges by thinking bigger and acting urgently. The 24-hour event brought together 100 speakers for 68 talks, while Figma introduced a broad set of product updates aimed at improving responsive design, collaboration, prototyping, and workflow integration. ## Config’s Broader Mission - Config connected a global design community spanning nearly every country. - Dylan Field argued that creatives are not powerless in the face of issues such as economic inequality and climate change. - The event encouraged attendees to use design and technology to create meaningful change, locally and globally. ## Expanded Design and Prototyping Capabilities - **Dark mode** became available on Figma’s desktop and web applications. - **Redesigned auto layout** added more intuitive responsive-design controls, including absolute positioning and negative spacing. - **Variable font support** enabled more expressive and optimized typography. - **Spring animations** allowed designers to create more natural transitions in prototypes. - **Individual strokes** made it possible to customize borders on specific sides of four-sided shapes. - **Updated outlines** exposed hidden objects and bounding boxes across the canvas. ## More Flexible Design Systems - **Component properties** reduced the need for excessive variants. - The feature also improved alignment between design systems and implementation code, supporting smoother developer handoff. - **Review states** enabled teams to approve changes, request revisions, and provide contextual feedback through branching. ## Collaboration and Workflow Integrations - **Spotlight** allowed participants in multiplayer sessions to direct everyone’s attention to a specific collaborator. - New **FigJam widgets** connected collaborative ideas with execution tools: - Jira - Asana - GitHub - Additional FigJam widgets included greeting cards and voice memos for team celebrations. - **International keyboard shortcuts**, initially in beta, improved shortcut support for German, Japanese, and French keyboards. ## Sharing and File Management - **Password protection** gave file owners more control over who could access shared files. - **Favoriting files** made frequently used documents easier to find and access. Figma positioned these updates as tools for making design work more responsive, collaborative, inclusive, and connected to broader product-development workflows. Teams can benefit most by adopting the features that strengthen their design systems, review processes, and collaboration practices.

Read original(opens in new tab)
figma2 min readCurated summary

Figma Community Awards 2022 | Figma Blog

Figma introduced its first-ever Community Awards to recognize the plugins, widgets, templates, UI kits, and other resources that help designers collaborate and work more efficiently. With more than 1,600 resources published daily, the awards highlight how the community builds practical and creative tools for Figma and FigJam. Winners were selected through community nominations and voting, then announced at Config. ## Purpose of the Awards - The awards celebrate community members who “imagine, design, and build” together. - Recognized resources support workflows ranging from accessibility and UI design to workshops, ideation, and team bonding. - The program included ten award categories. ## 2022 Award Winners - **Plugin for extending Figma’s utility:** *Similayer* by Dave Williames, for selecting similar layers using multiple properties. - **Plugin for adding content:** *Content Reel* by Eugene Gavriloff and Microsoft, offering reusable text, images, and icons. - **Widget for teams:** *FigJenda* by PG Gonni, an interactive workshop and meeting agenda compatible with the FigJam timer. - **Widget for utility or fun:** *Rock Paper Scissors* by Alex Einarsson. - **Team bonding template:** *Remote Design Sprint* by Miranda Mazzara, Danila Gallardo, and Aerolab. - **Ideation template:** *Customer Journey Map* by Fuad Aslan. - **UI kit:** *Ant Design Open Source* by Mr Biscuit and Vinh Bui, an open-source design system. - **Icon set:** *css.gg* by Lona and Astrit, containing more than 700 CSS, SVG, and Figma icons. - **Educational resource:** *Micro interactions - Prototyping* by Rusmir Arnautovic. - **Graphic resource:** *Sketch Elements Brushes Set* by Streamline. ## How the Awards Worked - Community members could nominate resources through Figma Community profiles. - Nominations were open from April 14–22, followed by finalist announcements on May 2. - Voting took place from May 2–10. - Each resource could be nominated only once, but users could nominate as many different files, plugins, or widgets as they wished. - Nomination totals were kept private to preserve fairness. ## Recognition for Creators - Winners were honored during the awards ceremony at Config on May 11. - They received a physical Figma Community Award and Figma merchandise. - Creators were encouraged to promote their resources and use **#FigmaCommunityAwards**. The awards demonstrate how central community-created resources are to the Figma ecosystem. Designers were encouraged both to recognize tools that improve their work and to publish their own resources for others to discover and use.

Read original(opens in new tab)
figma2 min readCurated summary

The power of emoji | Figma Blog

Emoji have become an essential layer of digital communication, helping convey emotion, tone, body language, and intent that are otherwise difficult to express through text. Jennifer Daniel, chair of Unicode’s Emoji Subcommittee, argues that emoji do not create new ideas; they translate long-standing human concepts into a flexible visual form. Because Unicode characters are permanent and globally interoperable, new emoji must be selected carefully, with an emphasis on broad usefulness and future relevance. ## Emoji supplement face-to-face communication - Digital communication lacks cues such as: - Rhythm and cadence - Volume - Eye contact - Body language - Emoji help restore some of these signals by clarifying a message’s emotional intent and tone. - As people become more familiar with emoji, choosing and placing them becomes almost instinctive. ## Emoji are contextual rather than a universal language - Emoji represent concepts that have existed throughout written and visual communication, rather than inventing new ones. - Their meanings can shift depending on context and cultural use. - For example, ❤️‍🔥 might suggest religious devotion, heartburn, or desire. - The way people actually use emoji often differs from how they believe they use them. ## Unicode makes emoji permanent - The Emoji Subcommittee operates within the Unicode Consortium, which standardizes digital writing systems worldwide. - Adding an emoji creates a permanent Unicode code point: - It cannot be removed or deprecated. - There are no “do-overs” if an idea becomes outdated. - This permanence contrasts with the fast, experimental cycle common in technology. - Unicode therefore tends to formalize concepts that already exist instead of rapidly creating new ones. ## Selecting useful, future-proof emoji - With more than 3,500 emoji, storage and implementation complexity are becoming constraints. - The committee is shifting away from overly specific objects—such as buckets, saws, and shorts—and toward symbols that support human expression and connection. - Strong candidates are: - Broadly relevant across cultures - Open to multiple meanings - Useful metaphorically or symbolically - Combinable with existing emoji to express new ideas - Adding one narrowly defined character can create pressure for related additions, such as needing both golden retriever and poodle emoji. - As a result, many valid proposals are rejected when their meaning is too specific or already expressible through existing characters. Emoji work best as flexible building blocks for communication, not as an attempt to represent every object or concept. Designers and standards bodies should prioritize symbols that are widely understandable, culturally adaptable, and capable of expressing multiple layers of human emotion and intent.

Read original(opens in new tab)
figma2 min readCurated summary

What’s new in Figma: April 2022 | Figma Blog

Figma’s April 2022 update focuses on making FigJam more structured, customizable, and playful for collaborative workshops, brainstorms, and retrospectives. The release adds organizational and formatting tools alongside expressive features such as Washi tape and artist-designed stickers. Together, these updates aim to help teams create clearer boards while preserving the informal energy of digital collaboration. ## Structure and Customize FigJam Files - Users can organize boards with dedicated sections. - Stickies and shapes now support more colors, including custom colors. - Sticky notes can be made proportional and visually consistent with other content. - Adjustable font sizes make it easier to establish hierarchy for titles and labels. - Improved snapping helps users arrange and align objects precisely. - Multiple objects can be locked or unlocked simultaneously. ## Add More Personality to Collaborative Work - Figma made cursor chat more expressive. - New sticker packs were added, created by Figma Community artists Jiro Bevis, Diana Marmol, Rooney, and Fanny Luor. - The stickers provide playful ways to react, encourage teammates, and personalize FigJam sessions. ## Washi Tape Returns Permanently - Washi tape, previously introduced as an April Fun Day feature, became a permanent FigJam tool. - The update includes dozens of newly designed tape patterns. - Users can upload their own patterns. - The feature is intended to recreate the creative, tactile feel of decorating physical workshop materials. These changes make FigJam more adaptable for organized facilitation without sacrificing creativity. Teams can use sections, consistent formatting, and alignment tools to improve clarity, then add custom colors, stickers, and Washi tape to make collaborative sessions more engaging.

Read original(opens in new tab)
figma3 min readCurated summary

Good ideas stick | Figma Blog

Figma’s digital washi tape began as a playful April Fun Day experiment inspired by a community tweet. The feature translated washi tape’s blend of visual delight, flexibility, and “just-right adhesion” into Figma and FigJam, attracting 224,000 rolls in a single day. Strong user enthusiasm convinced Figma that the feature should become more than a one-day joke. ## Why Washi Tape Works - Japanese washi tape is a decorative form of masking tape used for gift wrapping, scrapbooking, drawing, and planning. - Its appeal comes from being: - Colorful and expressive - Easy to tear, move, layer, and write on - Functional without damaging the surface underneath - These qualities make it especially appealing to designers, who enjoy patterns, lines, grids, and color. ## The Origins of Modern Washi Tape - In 2007, three Tokyo artists asked Japanese industrial tape manufacturer Kamoi Kakoshi to create more colorful versions of its masking tape. - The company invited them to its factory, saw how creatively they used the tape, and developed a new product line called **mt**. - The first collection launched with 20 colors. - Kamoi refined the tape’s “just-right adhesion,” allowing it to be repositioned, torn by hand, layered, and removed without damaging walls or other surfaces. - The company continued expanding the product with new colors, patterns, and collaborations until washi tape became a common household craft material. ## Translating Washi Tape into a Digital Product - Figma’s team prototyped a digital equivalent for Figma and FigJam. - The goal was to preserve the physical product’s: - Decorative, tactile feeling - Ease of manipulation - Practical usefulness - Ability to add personality to otherwise ordinary work - The April Fun Day release let users decorate files with bold, colorful strips of digital tape. ## From April Fools’ Feature to Lasting Utility - The feature quickly spread across user files, generating 224,000 digital “rolls” in one day. - Users experimented with ways to make sticky notes feel “stickier” and incorporated the tape into their work. - Many users asked Figma to bring the feature back permanently. - Their response showed that the tape was not merely a novelty: its combination of fun and utility made it genuinely useful in collaborative spaces. Figma’s experiment demonstrates that successful digital tools can emerge by identifying the emotional and functional qualities of familiar physical objects—not just copying their appearance. Washi tape’s lasting appeal comes from making everyday work more expressive, and digital versions can offer the same sense of creativity with even greater flexibility.

Read original(opens in new tab)
datadog1 min readCurated summary

It's always DNS . . . except when it's not: A deep dive through gRPC, Kubernetes, and AWS networking | Datadog

The supplied content does not include the blog post itself; it mainly contains Datadog navigation links and a promotional banner stating that Datadog was named a Leader in Gartner’s Magic Quadrant for Observability Platforms. The URL suggests the missing article concerns a gRPC, DNS, and load-balancing incident, but no incident details are provided. ## Available Content - Datadog promotes its recognition as a Gartner Magic Quadrant Leader. - The navigation lists products across: - Infrastructure and application monitoring - Logs, databases, and data observability - Security - Digital experience monitoring - Software delivery and service management - AI and platform capabilities - The linked page path references an engineering post titled “gRPC, DNS, and Load Balancing Incident.” ## Missing Technical Details - No description of the incident or its impact - No explanation of the DNS or load-balancing failure - No timeline, root-cause analysis, or remediation steps - No lessons learned or recommendations Please provide the full article text for a substantive technical summary.

Read original(opens in new tab)
datadog3 min readCurated summary

It's always DNS . . . except when it's not: A deep dive through gRPC, Kubernetes, and AWS networking

A routine update to a critical metrics query service caused intermittent errors and increased latency. Although logs initially pointed to DNS failures, the investigation revealed a deeper networking problem involving dropped packets and saturated AWS VPC connection tracking. The incident highlighted how Kubernetes, Cilium, AWS networking, and DNS behavior can interact in ways that obscure the true cause. ## Initial Symptoms and Apparent DNS Failures - Errors increased whenever the metrics query service was rolled out. - The service retrieves data from metric stores for dashboards and monitor evaluations. - Automatic retries reduced user-facing failures but increased latency. - Service logs showed DNS errors when connecting to dependencies inside Kubernetes. - The investigation therefore began with the cluster’s DNS infrastructure. ## NodeLocal DNSCache Reaches Its Limits - NodeLocal DNSCache runs as a `node-local-dns` DaemonSet on every Kubernetes node. - DNS pods had: - A 64 MB memory limit - A `max_concurrent` limit of 1,000 requests - The pods experienced out-of-memory errors and rejected requests during rollouts. - Increasing memory to 256 MB stopped the OOM errors, but DNS failures continued. - Request volume was far below the expected capacity: - Normally about 400 queries per second - Nearly 2,000 queries per second during rollouts - Expected capacity of at least 200,000 queries per second - Upstream resolvers were marked unhealthy, suggesting that NodeLocal DNSCache could not establish or maintain connections. - Because upstream requests could wait up to five seconds, connection failures consumed concurrency slots and made the cache appear overloaded. ## Evidence of a Network Problem - The instances were below their 5-Gbps sustained throughput limits. - TCP retransmits increased in correlation with service rollouts. - Engineers suspected brief traffic spikes, or microbursts, that were not visible in aggregate throughput metrics. - This shifted the investigation from DNS configuration toward lower-level AWS networking behavior. ## AWS VPC Connection Tracking - ENA metrics revealed a significant increase in `conntrack_allowance_exceeded`. - This metric counts packets dropped when VPC connection tracking becomes saturated. - Connection tracking maintains state for network flows and supports features such as stateful EC2 security groups. - The infrastructure used two tracking layers: - VPC conntrack maintained at the hypervisor level - Linux conntrack inside each instance - VPC conntrack appeared saturated even though Linux conntrack contained fewer than 60,000 entries—well within the observed capacity of similar instances. - AWS Support confirmed that conntrack capacity varies by instance type and that VPC conntrack limits could differ substantially from Linux conntrack limits. - Scaling to larger instances resolved the symptoms, but the engineers wanted to understand the traffic pattern and find a more efficient long-term solution. ## VPC Flow Logs as the Next Investigation Tool - The team turned to Amazon VPC Flow Logs to examine the service’s low-level network behavior. - These logs were expected to clarify why connection tracking filled up and how rollout traffic contributed to the saturation. - The investigation was still ongoing at the point where the provided article excerpt ends.

Read original(opens in new tab)
figma2 min readCurated summary

What’s new in Figma: March 2022 | Figma Blog

Figma’s March 2022 updates focus on making Figma and FigJam more accessible, flexible, and useful across devices and global teams. Major additions include FigJam for iPad, right-to-left text support, font-independent superscript and subscript characters, and improved Slack notifications. Together, these features help users ideate anywhere, design for more languages, and keep distributed teams informed. ## FigJam for iPad - FigJam is now available on the iPad through the App Store. - Users can sketch, brainstorm, and annotate away from desktop distractions. - Work can be resumed across iPad and desktop, supporting more fluid workflows. ## Right-to-left text support - Figma and FigJam now support right-to-left writing systems. - Arabic, Hebrew, Urdu, and other languages can be designed and edited more naturally. - The update improves Figma’s suitability for global audiences and international products. ## Superscript and subscript in any font - Superscript and subscript characters can now be used even when the selected font lacks those glyphs. - Figma automatically creates a synthetic, or “faux,” glyph. - The glyph is resized and repositioned to match the surrounding font style. ## Slack notifications for teams - Figma’s updated Slack app helps teams track activity in shared files, teams, and projects. - Notifications can arrive in real time or as hourly and daily digests. - Teams can subscribe project files to dedicated Slack channels. - Comment and collaboration updates can be shared where teammates already coordinate work. Overall, the release recommends using Figma’s new cross-device, localization, typography, and collaboration features to make design work more accessible and connected.

Read original(opens in new tab)
figma3 min readCurated summary

Localization, languages, and listening | Figma Blog

Figma is expanding internationally by adapting its product and organization to local users. The company’s strategy combines listening to designers worldwide, localizing languages, opening regional offices, and hiring local teams. It highlights Japan, EMEA expansion, and the difficult engineering work behind RTL language support as steps toward making design accessible to everyone. ## Learning from Designers Worldwide - Around 80% of Figma’s weekly active users were outside the United States from the company’s early days. - Customer visits around the world helped Figma understand that different regions have distinct needs and expectations. - These experiences shaped Figma’s vision: “Make design accessible to all.” - The company sees international growth as requiring humility, direct feedback, and a willingness to learn from local communities. ## Launching in Japan - Figma incorporated in Japan, opened its first Asian office in Tokyo, and appointed Hiro Kawanobe as its local leader. - Customer conversations revealed that Figma’s English-only product limited adoption. - Figma began localizing its product into Japanese, targeting a localized experience by the end of 2022. - It also planned to hire local staff across sales, marketing, community, and customer support. ## Expanding Across EMEA - Figma is increasing its European presence with offices in London, Paris, and Berlin. - Regional employees will help the company better understand and support customers across EMEA. - Figma intends to expand language support in ways that are useful and meaningful to local communities. ## Building RTL Language Support - Figma introduced support for right-to-left languages, a feature users had requested since the company’s early days. - Implementing RTL required substantial custom engineering because Figma uses: - A custom rendering stack optimized for performance - Its own text-rendering engine - Custom handling for bidirectional text and cursor behavior - Arabic and other RTL scripts create additional complexity through: - Characters whose forms change based on their position in a word - Ambiguous boundaries between writing directions - Complex diacritics and font behavior - Difficulties with text wrapping and navigation - Community plugin developers helped test the implementation, ensure compatibility with existing RTL content, and identify critical bugs during the beta. ## Growing Through Feedback - Figma acknowledges that international expansion may involve cultural mistakes or imperfect translations. - The company asks users to provide feedback so it can improve its products and approach. - Hiring continues in Tokyo, Paris, Berlin, and other locations to support its global growth. Figma’s international strategy is not limited to translating the interface. Its broader recommendation is to combine localization, local teams, technical investment, and continuous listening to build products that genuinely serve users in different regions.

Read original(opens in new tab)
datadogOriginal article

Using the Dirty Pipe vulnerability to break out from containers | Datadog (opens in new tab)

The Dirty Pipe vulnerability (CVE-2022-0847) is a critical Linux kernel flaw that allows unprivileged processes to write data to any file they can read, effectively bypassing standard write permissions. This primitive is particularly dangerous in containerized environments like Kubernetes, where it can be leveraged to overwrite the host’s container runtime binary. By exploiting how the kernel manages page caches, an attacker can achieve a full container breakout and gain administrative privileges on the underlying host. ## Container Runtimes and the OCI Specification * Kubernetes utilizes the Container Runtime Interface (CRI) to manage containers via high-level runtimes like containerd or CRI-O. * These high-level runtimes rely on low-level Open Container Interface (OCI) runtimes, most commonly runC, to handle the heavy lifting of namespaces and control groups. * Isolation is achieved by runC setting up a restricted environment before executing the user-supplied entrypoint via the `execve` system call. ## Evolution of runC Vulnerabilities * A historical vulnerability, CVE-2019-5736, previously allowed escapes by overwriting the host’s runC binary through the `/proc/self/exe` file descriptor. * To mitigate this, runC was updated to either clone the binary before execution or mount the host's runC binary as read-only inside the container. * While the read-only mount improved performance through kernel cache page sharing, it created a target for the Dirty Pipe vulnerability, which specifically targets the kernel page cache. ## The Dirty Pipe Exploitation Primitive * Dirty Pipe allows an attacker to overwrite any file they can read, including read-only files, by manipulating the kernel's internal pipe-buffer structures. * The exploit targets the page cache, meaning the overwrite is non-persistent and resides only in memory; the original file on disk remains unchanged. * In a container escape scenario, the attacker waits for a runC process to start (triggered by actions like `kubectl exec`) and targets the file descriptor at `/proc/<runC-pid>/exe`. ## Proof-of-Concept Escape Walkthrough * The attack begins with a standard, unprivileged pod running a malicious script that monitors the system for new runC processes. * Once a `kubectl exec` command is issued by an administrator, the script identifies the runC PID and applies the Dirty Pipe exploit to the associated executable. * The exploit overwrites the runC binary in the kernel page cache with a malicious ELF binary. * Because the host kernel is executing this hijacked binary with root privileges to manage the container, the attacker’s malicious code (e.g., a reverse shell or administrative command) runs with full host-level authority. To protect against this attack vector, it is essential to patch the Linux kernel to a version that includes the fix for CVE-2022-0847 and ensure that container nodes are running updated distributions.

datadog3 min readCurated summary

Escaping containers using the Dirty Pipe vulnerability | Datadog Security Labs

The post demonstrates how the Linux Dirty Pipe vulnerability can enable an unprivileged process to escape a container and gain administrative privileges on the host. The exploit abuses runC’s execution model and its host binary, which is exposed read-only inside the container but can still be modified through the kernel page cache. A proof of concept shows how a compromised Kubernetes pod can overwrite runC with a malicious executable when an administrator runs `kubectl exec`. ## Container Runtimes and runC - Kubernetes commonly uses containerd or CRI-O through the Container Runtime Interface (CRI). - These runtimes rely on lower-level OCI runtimes, most notably runC, to create isolated Linux processes. - runC configures namespaces, cgroups, and the container environment before executing the supplied entrypoint with `execve`. - During execution, `/proc/self/exe` inside the container can refer to an open descriptor for the runC binary on the host. ## Earlier runC Escape Vulnerability - CVE-2019-5736 exploited this `/proc/self/exe` behavior: - A malicious container entrypoint could write to the host’s runC binary. - Overwriting runC enabled subsequent container operations to execute attacker-controlled code with host-level privileges. - runC initially mitigated the issue by cloning its binary before execution. - It later changed the design to mount the runC binary read-only inside the container, improving performance through kernel page-cache sharing. - That optimization created conditions in which Dirty Pipe could bypass the apparent read-only protection. ## Dirty Pipe as a Container Escape Primitive - Dirty Pipe allows an unprivileged process to overwrite files it can read, even without write permission. - The modification occurs in the kernel page cache rather than persistent storage: - The original file remains intact on disk. - Dropping caches or rebooting can restore the original contents. - Despite being temporary, the overwrite is sufficient to execute malicious code when the modified binary is run. - In this case, the attacker targets the host’s runC binary through `/proc/<runC-pid>/exe`. ## Kubernetes Proof of Concept - The demonstration starts an ordinary, unprivileged pod using an attacker-controlled container image. - Its entrypoint script: - Replaces `/bin/sh` with a launcher referencing `/proc/self/exe`. - Waits for a runC process to appear. - Invokes the Dirty Pipe exploit against that process’s executable. - An administrator running `kubectl exec` causes runC to execute inside the container, triggering the overwrite. - The modified runC is replaced with a malicious ELF binary that runs commands such as `id` and `hostname`, recording their output in `/tmp/hacked`. - The exploit is adapted from the original Dirty Pipe proof of concept and the earlier runC escape technique. The attack illustrates that kernel vulnerabilities can undermine container isolation even when the container is unprivileged and the target binary is mounted read-only. Systems should promptly patch vulnerable Linux kernels and container runtimes, while treating compromised containers as potential paths to host compromise.

Read original(opens in new tab)
figma3 min readCurated summary

The art and influence of motion | Figma Blog

Motion helps digital interfaces communicate in ways that resemble the physical world. UX designer Katie Swindler argues that animation can clarify state, build mental models, improve perceived responsiveness, and add personality—but only when it serves a clear purpose. Effective motion balances practicality with restraint and must remain accessible to people who cannot or should not experience animation. ## Motion as a Human-Centered Language - People naturally interpret facial expressions, gestures, and movement alongside spoken information; interfaces can use motion similarly. - Animations communicate: - Progress, such as loading bars - Errors, such as a field shaking after an incorrect password - Change, such as charts recalibrating after a page refresh - Motion helps translate a digital environment into terms understood by a brain shaped by interaction with a physical, three-dimensional world. - It gives users information for building mental models without requiring explicit explanation. ## Designing Familiar Physical Metaphors - Digital animations can borrow from familiar physical behavior. - A sliding menu or “drawer” suggests that: - It can be opened and closed repeatedly - Its contents remain available when reopened - These familiar cues make interfaces feel intuitive. - Figma examples include animated cursor-chat bubbles and the celebratory shake of the FigJam Timer. ## Purpose-Driven Microanimations - Microanimations should solve a specific user or system problem rather than exist merely for decoration. - A short one- to two-second transition can disguise unavoidable backend processing delays and make a product feel more responsive. - Motion should be evaluated with the same discipline as icons: adding more visual elements is not automatically beneficial. - Designers should consider whether text, a static visual, or no additional communication would work better. ## Balancing Practicality and Personality - The strongest motion combines functional guidance with a distinct sense of character. - Animations should be fast, subtle, and respectful of the user’s time. - Swindler highlights Apple’s “sprout” or “Genie in the Bottle” animation: - Minimizing a window visually pulls it into its dock icon. - Restoring it reverses the motion, showing where the window came from and where it will return. - This type of animation provides orientation and delight without distracting from the task. ## Accessibility and Common Mistakes - Motion must never be essential to understanding or operating an interface. - Certain animations can trigger people with epilepsy or create barriers for users with motion-related sensitivities. - Excessive or frenetic movement can: - Interrupt users - Create confusion and visual busyness - Add unnecessary steps - Frustrate users and weaken brand affinity - Every animation should be selected carefully and used with restraint to solve a user problem elegantly. Motion is most effective when it communicates meaning, reinforces familiar behavior, and adds personality without demanding attention. Designers should prototype animations deliberately, test them for accessibility, and remove any movement that does not clearly improve the experience.

Read original(opens in new tab)
figma2 min readCurated summary

FigJam for iPad: space to explore and ideate | Figma Blog

FigJam for iPad was introduced to make brainstorming and collaboration more fluid across devices. The article argues that tablets’ focused, tactile nature complements FigJam’s infinite canvas, especially for sketching, exploring early ideas, and giving visual feedback. Although the standalone iPad app is being retired in 2026, FigJam remains available through the Figma app and the web. ## Why Tablets Suit FigJam - Desktop workflows often interrupt creative focus with notifications and constant context switching. - Tablets provide a more focused, single-app environment. - The iPad’s portability and touch or pen input make it feel similar to working in a notebook. - FigJam’s open canvas naturally supports freeform drawing, doodling, annotations, and low-fidelity exploration. - Users can move fluidly between desktop and tablet depending on the task. ## Embracing Early Ideas - Low-fidelity sketches make nonlinear exploration and iteration easier. - Rough ideas encourage collaboration rather than inviting narrow critique. - Users can sketch concepts on an iPad, then continue refining or sharing them from a laptop. - Team members can draw directly over one another’s ideas, making ideation more interactive. ## Making Feedback More Personal - Handwritten annotations can complement or replace traditional comments. - Users can circle, underline, and mark up text, diagrams, and sketches directly on the canvas. - Visual and handwritten feedback creates a warmer, more collaborative experience than written critique alone. ## Running Collaborative Sessions - The iPad can support group workshops as well as individual work. - Facilitators can display a FigJam file on a desktop screen while using the iPad for live annotations. - Quick actions—such as circling stickies or highlighting contributions—make meetings feel more natural and fluid. Figma positioned FigJam for iPad as an early step toward richer tablet-based design workflows. For current users, FigJam is available through the Figma mobile app or the web; the standalone iPad app is scheduled for retirement on January 8, 2026.

Read original(opens in new tab)