from/prod
← All companies

THE COMPANY INDEX TRACKED BLOG

Nicolas Fränkel

Ideas, decisions, and lessons from the team.

blog.frankel.ch (opens on the source site)
26Posts tracked
last weekLatest publication
2.2Posts / month over the last 12 months

Latest writing

20 of 26 posts

Security Baked Into the JVM: no single party controls the outcome (opens on the source site)

A URL is a name, and names get reused. Replace the bytes behind https://repo.example.org/order-processor.jar and every permission granted to that URL still applies, now to code nobody audited. So far in this series, Part 1 declared constraints on a remote call, Part 2 vetted code before a client loaded it, Part 3 established who is calling, and Part 4 carried that chain of identities across the wire.

Read at the source

AI-assisted genealogy, a follow-up (opens on the source site)

I got a lot of feedback on my post AI-assisted genealogy, some good, some not so good. In any case, I felt the subject was interesting to a lot of people. Meanwhile, I continue working on my tree, and I have deepened my understanding of the subject. In this post, I want to share again. Trust, but verify Let’s address the not-so-good feedback first. The gist of it was: AI can hallucinate. It’s true in theory: when you ask a question, it provides any answer.

Read at the source

World geography gotchas (opens on the source site)

Years ago, a colleague of mine told me about two pockets of foreign land surrounded by Switzerland: Campione d’Italia and Büsingen am Hochrhein, respectively Italy and Germany. Both are enclaves of their respective country in Swiss territory: An enclave is a part of the territory of a state that is enclosed within the territory of another state. To distinguish the parts of a state entirely enclosed in a single other state, they are called true enclaves.

Read at the source

AI-assisted genealogy (opens on the source site)

My son recently came to me to brag about using AI to find our ancestors. While the results were correct, I didn’t learn anything new, as it stopped at my grandparents. I was never very interested in my genealogy, but I decided to see if AI would be a good tool for this. TL;DR: Yes, it is, and even more than that. In a little less than one month, I managed to gather more than 600 individuals and get back 12 generations in some branches.

Read at the source

Security Baked Into the JVM: sixteen Subjects on the wire (opens on the source site)

Alice calls the order service. The order service calls the ledger on her behalf. At the second hop, the ledger has to decide whose authority the debit is being made under. Most stacks answer badly. Forward Alice’s bearer token verbatim, and the ledger cannot tell her from the service that relayed it. Drop the token and the ledger sees a machine, with no record that a human started the chain. Neither option lets the ledger authorize the combination.

Read at the source

Solving Gradle metadata and Renovate integration (opens on the source site)

My current company has settled on using Gradle. It doesn’t make me very happy, but you need to learn to work with constraints. Plus, I must admit that the developers who actually implemented the build files did a pretty good job overall: they used Kotlin instead of Groovy, they moved code to regular plugins, etc. This week, I worked on improvements to a new project and set up Renovate.

Read at the source

Security Baked Into the JVM: two Subjects, one call (opens on the source site)

The constraint system stops a bad call before it leaves the JVM. The Safe Codebase Audit Pipeline stops bad code before a client ever loads it. What remains is identity: who is calling, and can you verify it? Most frameworks answer with a token check at the door. A filter validates a bearer token, sets a thread-local variable, and hopes that nothing downstream forgets to look at it. DirtyChai answers differently.

Read at the source

GitHub agentic workflows and Renovate (opens on the source site)

I’ve been a big fan of Renovate for a couple of years already. Renovate scans your repositories, detects outdated package versions, and opens pull requests to automatically bump them. It’s similar to Dependabot in that it keeps your dependencies up to date. If I had to compare them in one sentence, I’d say Renovate is less integrated in the GitHub ecosystem, but handles more ecosystems and, more importantly, is extensible.

Read at the source

RFC 9880 and the IoT Validation Problem (opens on the source site)

The IoT/IIoT world has a data model problem and the concept of Digital Twin has made this issue more important. Plenty of people have tried to fix it. RFC 9880 and its Semantic Definition Format (SDF) are a serious attempt: a JSON-based, ecosystem-neutral way to describe what a device is and what it does. I have had some experiences with this specification, and I’ve understood that the format shows its full value once you treat it as source code, something you compile.

Read at the source

Security Baked Into the JVM: the Safe Codebase Audit Pipeline (opens on the source site)

In Part 1, the minimal deployment showed constraints traveling with the proxy: authentication, encryption, hardened deserialization, all declared in configuration and enforced at the call boundary. The proxy is a JAR. That JAR was downloaded and unmarshalled before any constraint ran. That step is the earlier problem. Distributed Java systems that load remote code are vulnerable to supply chain compromise: an attacker can replace a legitimate JAR with one containing malicious bytecode.

Read at the source

Making ServiceLoader usable: a provider factory (opens on the source site)

I keep coming back to java.util.ServiceLoader. I have used it to put a JSON layer behind a contract, so the core code carries no direct dependency on any particular JSON library, and I can swap the implementation without touching callers. The same shape works for JWT handling, where the concrete library might be jose4j or another JOSE implementation, and you can easily find other decoupling use-cases.

Read at the source

Two nasty surprises in Home Assistant's config (opens on the source site)

Last year, I motorized the rolling shutters on the southern façade of my apartment. My idea was to manage them via Home Assistant. I had a couple of automations in mind: In the evening, roll down the shutters of my bedroomIn the morning:If it’s too hot outside, roll down all shuttersIf it’s too cold outside, roll down all shuttersIn other cases, roll up all shutters but my bedroom’s Living in France, I added the official Météo France integration.

Read at the source

Security Baked Into the JVM: why fork Apache River and OpenJDK? (opens on the source site)

The more distributed a system, the harder it is to secure. Code crosses JVM boundaries. Objects are serialized across trust boundaries. Third-party proxies run inside your process. The usual answer is a network firewall. It helps, but it operates at the wrong level. Java 17 deprecated the SecurityManager, Java 24 put the final nail in its coffin. Most developers didn’t notice.

Read at the source

On programming languages, targets, and platforms (opens on the source site)

I started as a Java developer, but for some time now, I have broadened my horizons. Recently, I thought about how early languages were dedicated to a single target and platform, and now they are broadening their focus. In this post, I want to write down my thoughts in the hope that it may be useful to others, probably to my future self. Definitions You may have been wondering about the title terms.

Read at the source

double, BigDecimal, or Fixed-Point? (opens on the source site)

There is an evergreen debate in the Java world: should you always use BigDecimal for money? The short answer is no. The real answer is: it depends on your computational context: the precision you need, the rounding rules you must follow, and the performance budget you have. The problem is that this conversation is often driven by dogma rather than engineering.

Read at the source

Seasons time-lapse - the video (opens on the source site)

In the first post of this series, I focused on the project foundations: what should I do to create a video from photos taken from the same position year after year? I dedicated the second part to aligning images. It wasn’t as easy as I expected. I stumbled upon new concepts, such as ORB and RANSAC. In this third and final post, I want to tackle the video creation itself, explain some 'artistic' decisions, and leave the door open to future work.

Read at the source

AI gateways: why and how (opens on the source site)

Before working for 2 years on the Apache APISIX API gateway, I was mainly oblivious to API gateways. It’s only by working with them that I understood their value. Decoupling the client and the server unlocks a lot of options: moving authentication to the API Gateway, securing APIs, deduplicating API requests, etc. In this post, I want to describe how the same pattern applies to AI. AI gateways AI gateways work in a similar way.

Read at the source

Seasons time-lapse - alignment (opens on the source site)

In the previous post, I described the Seasons project: a time-lapse of hundreds of pictures taken from nearly the same viewpoint over the years. The hardest challenge wasn’t taking the pictures or assembling them, but aligning them. You might have noticed the nearly part about viewpoint in the above paragraph. Indeed, it’s an approximation. I’m a human being, not a tripod. The position changes ever so slightly, and so does the exact angle.

Read at the source

Privacy choices

Reading never requires analytics. These choices last 90 days on this browser.

Essential sign-in and security storage always stays on. Read the privacy notice.