SShortSingh.
0
ProgrammingDEV Community ·

VMs, Containers, Serverless: How to Choose the Right Compute Model

Virtual machines, containers, and serverless are three distinct ways to run code, each defined by how much of the underlying environment an application carries with it. VMs bundle a full operating system, offering strong isolation and control but at the cost of size and slow startup times. Containers share the host OS kernel, making them lightweight, fast, and portable — the default choice for most modern services. Serverless platforms like AWS Lambda run code entirely on demand, requiring zero infrastructure management but offering less control and struggling with long-running workloads. In practice, most real-world systems combine all three, selecting each based on the specific needs of individual workloads rather than applying one model across the board.

0
ProgrammingDEV Community ·

AI Gateways Are Becoming Essential Infrastructure for Managing Multi-Model Apps

As development teams increasingly rely on multiple AI providers simultaneously, managing API keys, costs, and safety checks across services has grown chaotic. An AI gateway is a centralised control layer that sits between applications and model providers, handling routing, cost attribution, rate limiting, caching, and security in one place. By routing simpler requests to cheaper models and reserving powerful ones for complex tasks, teams can significantly reduce token spend without rewriting logic across every service. The gateway also solves a persistent FinOps problem by attributing AI spend to specific features or teams, making costs visible and governable rather than buried in scattered invoices. While adding a gateway introduces a small latency overhead and an extra component to maintain, its consolidation benefits are increasingly seen as standard practice in production AI deployments.

0
IndiaNDTV ·

Harish Salve Urges Authorities to Consider Displaced Residents in Illegal Building Action

Senior advocate Harish Salve has weighed in on the issue of illegal buildings in Delhi, cautioning authorities against simply evicting residents. Speaking to NDTV, Salve argued that officials must address where displaced people will go if removed from such structures. He also raised the question of why residents were compelled to seek out illegal or unsafe housing in the first place. Salve's remarks highlight the need for a more humane and considered approach when dealing with unauthorised constructions in the city.

0
ProgrammingDEV Community ·

WebMCP Lets AI Agents Interact With Websites via Structured Browser Tools

WebMCP is a draft W3C standard, backed by Google and Microsoft, that allows AI agents to interact with websites through declared, structured tools rather than guessing at page elements. It shipped as an early preview in Chrome 146, with the entry point accessible via document.modelContext in the browser. Developers can implement it either declaratively by adding attributes to existing HTML forms, or programmatically by registering tools with JavaScript using a feature-detection shim. Each tool requires a name, a description for the agent, and an input schema, and executes within the user's own browser session using their existing permissions. Security guidance emphasizes least-privilege exposure, treating tool inputs as untrusted, and adding confirmation steps before any destructive actions such as deletions or payments.

0
ProgrammingDEV Community ·

WebMCP and Google Cloud Run Offer a New Architecture for Secure AI Agent Backends

Engineers are combining WebMCP, an emerging browser-level standard, with Google Cloud Run to build more reliable and secure AI agent backends. WebMCP allows web pages to expose structured, machine-readable tools directly to in-browser AI agents, replacing fragile methods like CSS scraping and screenshot analysis. Unlike traditional web automation, this approach gives AI agents a typed, deterministic contract to interact with websites, reducing token waste and unpredictable behavior. Google Cloud Run provides the serverless backend infrastructure, automatically scaling containerized applications in response to traffic without manual orchestration. Together, the two technologies aim to close the 'interface gap' in AI web infrastructure while keeping users informed and in control of agent actions.

0
Crypto & Web3CoinDesk ·

Hunter Biden Memecoin Crashes 98% at Launch, Early Buyers Face Six-Figure Losses

A memecoin themed around Hunter Biden suffered a dramatic 98% price crash shortly after its launch. The project's team attributed the collapse to thin liquidity and the activity of automated trading bots, which they say distorted the market at debut. On-chain data from analytics platform Nansen revealed that some early buyers are now sitting on six-figure losses. The incident highlights the risks associated with politically themed memecoins, which often experience extreme volatility at launch.

0
ProgrammingHacker News ·

Opinion: Growing Disillusionment With the Modern Internet

A blogger writing on the Bear Blog platform has shared a personal essay expressing deep frustration with the current state of the internet. The piece resonated enough to be shared on Hacker News, where it attracted reader attention. The post reflects a broader sentiment of disillusionment that many users feel toward today's online experience. While the article garnered modest engagement with 7 points and 1 comment, it touches on themes that are widely discussed in tech circles.

0
ProgrammingHacker News ·

DeepSeek Announces V4.1 Flash Model

DeepSeek AI announced what appears to be a new model called DeepSeek V4.1 Flash via a post on Twitter/X. The announcement garnered attention on Hacker News, accumulating 34 points and 6 comments. No further technical details or specifications are available from the provided source. The full context of the announcement requires direct access to the original Twitter post.

0
ProgrammingDEV Community ·

When Access Control Fails, Stale Data Is Often the Real Culprit

A developer series on real-world security infrastructure highlights how attribute-based access control (ABAC) systems can produce wrong access decisions even when policy rules are correctly written. In one documented case, an employee was mistakenly given contractor-level access because the identity service held an outdated employment type, while the device posture service had timed out entirely. The policy engine behaved correctly — it simply evaluated whatever data it received at that moment, exposing a gap between clean architectural design and messy production realities. The author argues that each resolved attribute should carry provenance metadata, including its source, timestamp, and freshness status, so engineers can distinguish stale or unavailable values from genuinely false ones. The piece recommends placing data freshness requirements directly alongside the policies that depend on them, ensuring that audits cover the age of evidence and not just the logic of the rules.

0
IndiaTimes of India ·

MP man who revived polluted Ajnar River hits back at Dhruv Rathee's PR claim

Surendra Singh Choudhary, popularly known as Bittu Tabahi, gained widespread recognition for single-handedly cleaning the heavily polluted Ajnar River in Madhya Pradesh. His efforts caught the attention of Chief Minister Mohan Yadav, drawing significant public and political notice. YouTuber Dhruv Rathee subsequently criticised the government's response to Bittu's work, dismissing it as a public relations exercise. Bittu responded by shifting focus away from the controversy, instead urging citizens to take collective responsibility for keeping the environment clean and preventing future pollution.

0
ProgrammingDEV Community ·

Why Safely Retiring an Experiment Repo Is Harder Than Starting One

A developer closing down a throwaway agent-workflow experiment found that deleting the repository required more care than creating it. The core challenge was distinguishing experimentally validated conclusions from provisional demo choices, such as card formats and cap rules, that were never proven and should not be inherited as defaults. Before any deletion, architecture notes had to be updated to past tense, live URLs removed, and all validated findings documented in a durable record. Skipping the unlinking step risks leaving dead references that future agents or developers may misread as lost context. The experience highlighted that safe retirement demands an explicit discard list, not just archival absorption of every visible artifact.

0
IndiaNDTV ·

Naidu Rejects CBI Probe Demand Into Andhra Teacher Recruitment Irregularities

Andhra Pradesh Chief Minister N Chandrababu Naidu has turned down the Opposition's demand for a Central Bureau of Investigation probe into the Mega DSC 2025 teacher recruitment drive. The Opposition had alleged irregularities in the recruitment process and sought a CBI inquiry to ensure accountability. Naidu defended the process, stating that government officials had already addressed and clarified every allegation raised. The Chief Minister's rejection signals his administration's confidence in the transparency of the recruitment exercise.

0
ProgrammingDEV Community ·

How Firebase Misconfigurations Expose Production Apps to Attackers

Firebase configurations embedded in mobile apps do not serve as a true security boundary, making misconfigured production services vulnerable to exploitation. Attackers can replicate legitimate app requests outside Android or iOS environments, bypassing client-side controls like hidden buttons or navigation restrictions if Security Rules are too permissive. Simply verifying that a user is authenticated is insufficient — authorization must tie the user's identity to specific resources and permitted actions. Sensitive operations such as refunds, KYC approvals, and role assignments should be handled exclusively by trusted backends that validate the actor, state, and input. A robust security model layers authentication, Security Rules, App Check, and backend enforcement while assuming the client can be inspected or automated.

0
ProgrammingDEV Community ·

XZ Utils Backdoor: How a Microsoft Dev Accidentally Stopped a Global Linux Threat

In late March 2024, Microsoft engineer Andres Freund discovered a sophisticated backdoor in xz Utils, a widely used compression library present on most Linux and macOS systems, while investigating unusual SSH login slowdowns on a test machine. The vulnerability, tracked as CVE-2024-3094, was not a coding accident but the result of a multi-year social engineering campaign by a threat actor using the alias 'Jia Tan', who gradually earned commit access to the xz Utils project. The malicious code was concealed inside obfuscated binary test files and activated only under specific build conditions, ultimately targeting the SSH daemon to allow unauthorized root access without leaving log traces. Had the backdoor gone undetected, it could have compromised millions of servers worldwide once it reached stable releases of major Linux distributions such as Debian and Red Hat. The incident has been widely described as a wake-up call for open-source security, raising urgent questions about supply chain integrity, maintainer burnout, and trust in critical software infrastructure.

0
ProgrammingDEV Community ·

Enterprise Software Licensing Models: What Founders Must Know in 2026

Choosing the right software licensing model is a critical strategic decision for founders building enterprise applications, as the wrong choice can limit distribution, restrict scaling, or expose proprietary code. The three primary categories are proprietary licensing, permissive open-source licences, and copyleft licences, each carrying distinct legal and commercial implications. Proprietary models let customers run software without accessing source code, while permissive licences such as MIT and Apache 2.0 allow free use and modification with minimal obligations. Copyleft licences like GPL and AGPL require derivative works to be released under the same open-source terms, posing a significant risk if integrated into commercial products. Pricing structures range from one-time perpetual fees to SaaS subscriptions and negotiated enterprise agreements, and founders are advised to align their chosen model with revenue goals, IP protection needs, and client scalability requirements.

← NewerPage 985 of 4924Older →