VolatileThunk

Talks

I'm Louis Jackman, a technology architect in London. See my CV, my LinkedIn, my articles and my projects and open-source contributions. Find out how to contact me, and more about me in general.


Java Meetup, 2018: Concurrency Techniques for Services - Actors, Fibers, and Reactive Streams

An evaluation of the many concurrency techniques available on the JVM, i.e. the Java Virtual Machine.

This video is of its time. In particular, the mentioned "fibers" prototype in the JVM was later renamed to "virtual threads". In addition, neither Akka actors nor the idea of ubiquitous reactive-based APIs for all services going forward took off as much as Kotlin coroutines or virtual threads. Although reactive programming still enjoys strong support in domains with lots of long-lived streaming and extensive back-pressure concerns.

As of today, I broadly maintain my criticisms - in both this talk and my related article - of asynchronous APIs, believing that Go's goroutines and JVM virtual threads are a better approach to handle non-blocking I/O. But some of the more mechanical nuisances of asynchronous APIs have been ameliorated in an era of AI-authored code.


Java Meetup, 2019: How not to be Equifax - Securing Java Codebases in the Cloud Era

In essence, this is a talk discussing common security issues in web-based backend services - just given a Java flavour to accommodate a JVM-focused meetup.

Most of these categories are still problems today, but prioritisations have shifted - as can be seen by the ever-changing OWASP Top 10s.

In an AI world, issues around insecure code generation (e.g. injections) can be offset by the use of high-quality code-generation models, plus strong SAST tools and AI-based reviewers using different models from the implementer for adversarial diversity. I find that configuration bugs, imprecise access controls, and especially supply-chain attacks are the more prominent problems nowadays.

The organisational framing around communicating security issues via a tangible price tag and being honest about practical supply chain auditing limitations hold up.