<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The NOKIA Blog</title>
	<atom:link href="https://thenokiablog.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://thenokiablog.com/</link>
	<description></description>
	<lastBuildDate>Wed, 29 Jul 2026 13:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.6</generator>

<image>
	<url>https://thenokiablog.com/wp-content/uploads/2024/03/cropped-Cjdowner-Cryptocurrency-Flat-ICON-ICX.512-32x32.png</url>
	<title>The NOKIA Blog</title>
	<link>https://thenokiablog.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Bull And Bear Case For Digital Design In The Age Of AI</title>
		<link>https://thenokiablog.com/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Wed, 29 Jul 2026 13:00:00 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Color]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Figma]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai/</guid>

					<description><![CDATA[<p>As AI reshapes product design, it could give designers greater autonomy or expose the gaps that...</p>
<p>The post <a href="https://thenokiablog.com/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai/">The Bull And Bear Case For Digital Design In The Age Of AI</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><section aria-label="Quick summary" class="article__summary"><span id="article__start" class="summary__heading" aria-hidden="true"></span>As AI reshapes product design, it could give designers greater autonomy or expose the gaps that autonomy makes harder to hide. Exploring both the bull and bear cases, Andy Budd examines what happens when designers need less permission to act.</section>
</p>
<p>Designers have spent years saying they would do better work if the organisation got out of the way. Not always in those exact words, obviously. It usually comes out as something more reasonable: we didn&rsquo;t get enough engineering time, product had already decided the solution, the roadmap was too packed, leadership only cared about this quarter&rsquo;s numbers, research got cut, the experiment was never run properly, the design debt was known about, but nobody wanted to spend a sprint fixing it.</p>
<p>Much of this is true. Most designers have worked inside that awkward middle space between product and engineering. Product frames the problem, or at least thinks it does. Engineering decides what is feasible, or at least what is affordable. Design is expected to make the thing clearer, simpler, more coherent, more usable, and occasionally more desirable, while also being careful not to disrupt the plan too much.</p>
<p>That position has always been uncomfortable.</p>
<blockquote><p>Designers are told to think strategically, but often lack the power to act strategically.</p></blockquote>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>They can spot the broken onboarding flow, the confusing upgrade path, the empty state that makes users feel stupid, the feature that looks reasonable in a product review but makes no sense in real use. Seeing the problem is one thing. Getting it fixed is another.</p>
<p>So design often becomes an <strong>argument</strong>. You make the case. You annotate the flow. You bring the research clip. You point to the support tickets. You show the Figma prototype. You explain why the <em>&ldquo;small edge case&rdquo;</em> is actually the first-run experience for half your new users. Then everyone nods, agrees it matters, and moves on to whatever had already made it onto the roadmap.</p>
<p>This is one reason AI is more interesting for design than the usual <em>&ldquo;will it replace designers?&rdquo;</em> debate suggests. The real change is not that designers can make more screens. Nobody needs more screens. The interesting change is that designers <strong>may need less permission</strong>.</p>
<div data-audience="non-subscriber" data-remove="true" class="feature-panel-container"><img decoding="async" loading="lazy" class="feature-panel-image-img" src="https://thenokiablog.com/wp-content/uploads/2026/07/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai.jpg" alt="Feature Panel" width="690" height="790"></div>


<h2 id="the-bull-case-designers-need-less-permission">The Bull Case: Designers Need Less Permission</h2>
<p>A good designer can now move from <em>&ldquo;we should fix this&rdquo;</em> to <em>&ldquo;I fixed this, and pushed it live.&rdquo;</em> They can prototype the alternative onboarding flow, write and test clearer product copy, build a rough working version of the interaction, clean up small pieces of design debt without waiting three months for a roadmap slot, and make the better thing <strong>visible enough</strong> that it becomes <strong>harder to ignore</strong>.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>That changes the politics of the work. Design has often relied on persuasion because designers lacked direct means of production. AI weakens that dependency. Not everywhere, and not for everything. Complex products still have architecture, infrastructure, data models, permissions, security, compliance, legacy systems, and all the other unglamorous reasons software is hard. But the boundary is moving.</p>
<blockquote><p>More of the gap between having the idea and making the idea real can now be crossed by a motivated designer with the right tools.</p></blockquote>
<p>In this version of the future, designers become <strong>less permission-dependent</strong>: less reliant on product to bless the problem, less reliant on engineering to make every small improvement real, less trapped in the role of internal critic, taste-provider, or Figma operator. More able to make, test, repair, and ship.</p>
<p>The best designers start to look less like traditional product designers and more like <strong>hybrid product leaders</strong>. They still care about interaction, hierarchy, language, flow, brand and craft, but they also understand the commercial shape of the problem. They can make trade-offs. They can prototype in code, or close enough to code. They can use AI to explore options quickly, then use judgment to throw most of them away. They can sit with a founder or PM and move from a vague product concern to something tangible by the end of the day.</p>
<p>There may be fewer of these people, but they will be harder to ignore. The current design-org model was partly built around <strong>scarcity</strong>: scarce engineering time, slow production, expensive prototypes, handoffs between specialists, heavy coordination across teams. If AI reduces some of that scarcity, it probably reduces the need for some of the roles that grew around it. The optimistic case is not that every designer keeps their job and gets a productivity boost. That feels like wishful thinking. The more believable version is that the total number of designers goes down, but the designers who remain have <strong>more direct influence over the product</strong>.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>That is not a bad outcome for the strongest designers. It may even be the thing many of them have wanted for years.</p>
<h2 id="the-bear-case-autonomy-exposes-the-gaps">The Bear Case: Autonomy Exposes The Gaps</h2>
<p>Autonomy has teeth. If AI gives designers more room to act, it also removes some of the cover. The same constraints that held good designers back have also protected weaker ones from being tested too directly.</p>
<p>For years, it has been easy to say: I had a better idea, but we never got the engineering time. Sometimes that was exactly what happened. Sometimes the better idea was never really more than a critique. It had not been made concrete. It had not been tested. It had not dealt with the awkward trade-offs. It sounded strong because it lived safely in opposition to the shipped thing.</p>
<blockquote><p>A lot of designers are good at noticing what is wrong. Fewer are good at deciding what should happen instead. Fewer still can make that alternative real enough for other people to judge. AI will expose this gap.</p></blockquote>
<p>If you can prototype the recommendation, the recommendation has to get better. If you can make the alternative flow, the flow has to survive contact with details. If you can test the product copy, you have to care what happens when users read it. If you can fix the small piece of design debt, you have to decide whether it was really worth fixing.</p>
<p>Some designers are not as strategic as they think they are. They have learned the language of strategy without the discomfort of <strong>owning outcomes</strong>. They can talk about user needs, business goals, systems thinking, and product quality, but struggle when asked to make a call. They want influence, but not the <strong>exposure</strong> that comes with it.</p>
<p>The profession has spent a long time arguing that design deserves more power. Fine. But more power means fewer excuses. It means the work is judged less by the elegance of the argument and more by the quality of the thing you made, tested, or changed. That is a better standard, but it will not be kind to everyone.</p>
<p>There is a second bear case, and it is probably the one large design teams should worry about most. Product and engineering already have more institutional power than design in most companies. They own the roadmap, the technical architecture, the sprint machinery, the metrics, and usually the language leadership understands. Design often has to translate its concerns into someone else&rsquo;s terms before they count.</p>
<p>AI may not rebalance that power. It may hand product and engineering enough <strong>design capability</strong> to make design easier to bypass. A PM who can generate a decent flow, decent copy, and a decent prototype may not feel the same need to involve design early. An engineer who can use AI to produce a reasonable interface may decide the design system covers enough of the decision-making. A founder who can get to a polished demo in an afternoon may confuse polish with product thinking.</p>
<p>The problem is not that these people will suddenly become great designers. The problem is that many companies do not know the difference between great design and plausible design. <strong>Plausible design is dangerous.</strong> It looks coherent in a product review. It uses the right components. The spacing is fine. The copy is not embarrassing. The flow mostly works. Nobody in the meeting feels strongly enough to object. So it ships.</p>
<blockquote><p>A lot of bad product decisions already survive because they look plausible. AI will produce more of them. This is where design could lose ground quickly: not because taste, judgment, research, and interaction thinking stop mattering, but because the visible outputs of design become easier for other functions to imitate.</p></blockquote>
<p>If a company already thinks design is mostly screens, prototypes, and polish, AI gives it a cheaper way to get those things.</p>
<p>In that world, design does not gain more agency. It gets narrowed. The remaining designers manage the design system, police component usage, review flows that have already been decided, tidy the interface, maintain brand consistency, and get pulled into high-stakes launches, executive demos, and the occasional messy cross-platform problem. Useful work, but a smaller surface area. Less shaping the product, more maintaining the furniture.</p>
<p>This is why the <em>&ldquo;AI will automate the boring 20%&rdquo;</em> argument feels too comforting. In some companies, perhaps that is what happens. But in large tech organisations, where design teams grew around coordination, production and process, the cut could be much deeper. Not 20%. Maybe 50%. Maybe more. Especially in places where leadership never really understood why the design team had grown so large in the first place.</p>
<h2 id="where-i-think-we-might-end-up">Where I Think We Might End Up</h2>
<p>The painful part is that both futures can be true at the same time. AI can make the best designers more capable and many average designers less necessary. It can give design more agency while reducing design headcount. It can help a small number of designers move closer to product leadership while pushing others into governance and clean-up work. It can free designers from waiting for permission, then reveal that some were more comfortable waiting than acting.</p>
<blockquote class="pull-quote">
<p>The designers who do well will not be the ones who merely use AI to produce more options. Options are cheap now. They will be the ones who know which option is worth pursuing, why it matters, how to test it, what to cut, where the product is lying to itself, and when &ldquo;good enough&rdquo; is quietly damaging the business.</p>
</blockquote>
<p>They will have taste, but taste will not be enough. They will need <strong>product judgment</strong>, <strong>technical curiosity</strong>, <strong>commercial awareness</strong> and the nerve to make decisions before every variable is settled. They will need to be comfortable moving between a customer conversation, a prototype, a pricing concern, a brand question, and a messy implementation detail without insisting that all of those belong to someone else.</p>
<p>I&rsquo;m not completely sure where we end up. I hope it is closer to the <em>bull case</em>: fewer permission structures, more making, more agency, better designers finally able to show what they can do without being held back by the machinery around them.</p>
<p>I fear it may be closer to the <em>bear case</em>: product and engineering absorb much of the work, companies decide plausible design is good enough, and design loses status, headcount, and strategic ground.</p>
<p>In reality, it will probably be some uncomfortable mix of the two. Some designers will use AI to gain more agency. Some companies will use it to need fewer designers. Some teams will produce better work because the distance between judgment and execution gets shorter. Others will ship more plausible mediocrity because nobody in the room can tell the difference.</p>
<p>For years, designers have said they could create more value if they were less constrained by the organisation around them. AI is about to test that claim. Some will finally get to prove it. Some will find out the constraints were doing them a favour.</p>
<h3 id="further-resources">Further Resources</h3>
<ul>
<li>&ldquo;Good from Afar, But Far from Good: AI Prototyping in Real Design Contexts,&rdquo; Huei-Hsin Wang and Megan Brown <em>(NN/Group)</em><br>Lately, the UX design field has been flooded with AI-powered prototyping tools that generate interfaces instantly from natural-language prompts. Despite the massive marketing hype, this evaluation with real design scenarios revealed that while these tools can follow instructions to achieve a general goal, they often lack the sophistication to weigh design tradeoffs and to produce thoughtful, high-quality designs without extensive guidance from humans.</li>
<li>&ldquo;AI Design Tools Are Marginally Better: Status Update,&rdquo; Megan Brown, Caleb Sponheim and Taylor Dykes <em>(NN/Group)</em><br>AI-powered design tools have improved, but we&rsquo;re still nowhere near the usefulness we&rsquo;ve been promised, nor are design professionals yet in danger of being replaced by AI. This article reviews in detail several tools and some specific AI-powered features, including: Figma&rsquo;s Rename Layers, Rewrite This, Find More Like; Khroma Color; and Midjourney. The authors also take a look at the wireframe and prototype generation capabilities of some AI tools.</li>
<li>design + AI conference</li>
</ul>
<div class="signature"><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai.png" alt="Smashing Editorial" width="35" height="46" loading="lazy"><br>
<span>(mb, yk)</span></div>
<p>The post <a href="https://thenokiablog.com/the-bull-and-bear-case-for-digital-design-in-the-age-of-ai/">The Bull And Bear Case For Digital Design In The Age Of AI</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution for .NET, and more (July 27, 2026)</title>
		<link>https://thenokiablog.com/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Mon, 27 Jul 2026 14:54:41 +0000</pubDate>
				<category><![CDATA[Nokia Mobile Phone]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Bedrock AgentCore]]></category>
		<category><![CDATA[Amazon CloudWatch]]></category>
		<category><![CDATA[Amazon Connect]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[Amazon Redshift]]></category>
		<category><![CDATA[Amazon SageMaker]]></category>
		<category><![CDATA[Amazon SageMaker AI]]></category>
		<category><![CDATA[Amazon SageMaker Unified Studio]]></category>
		<category><![CDATA[Analytics]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[AWS Local Zones]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Launch]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Serverless]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Sustainability]]></category>
		<category><![CDATA[Week in Review]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026/</guid>

					<description><![CDATA[<p>Last week I had the privilege of spending three days in S&#227;o Paulo with technical builders...</p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026/">AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution for .NET, and more (July 27, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Last week I had the privilege of spending three days in S&atilde;o Paulo with technical builders from across Latin America, brought together for a regional tech event full of deep-dive sessions, hands-on workshops, and conversations with customers and partners. What struck me most wasn&rsquo;t any single session, it was the energy of a technical community that so rarely gets to be in the same room. People traded architecture ideas over coffee, sketched out solutions on whiteboards, and left with a longer list of things to try than they arrived with. It&rsquo;s a good reminder that, for all the tooling we build, the community around it is what makes the technology stick.</p>
<p>That community spirit connects nicely to the week&rsquo;s biggest infrastructure news, which is all about bringing AWS closer to where builders actually are.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-105128" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026.jpg" alt width="1800" height="801"></p>
<p>Now, let&rsquo;s get into this week&rsquo;s AWS news&hellip;</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/html-element-select-envato-tuts/" class="template-2"><span class="cta">Read more</span><span class="postTitle">HTML Element: select | Envato Tuts+</span></a></div><p><strong>Headlines</strong><br>
        <br>AWS Local Zone in Athens, Greece: AWS has opened a new Local Zone in Athens, Greece, the second Local Zone in EMEA with support for Amazon S3 and Amazon EBS Local Snapshots, so you can store and process data within Greece to help meet local data residency requirements. The Athens Local Zone supports Amazon EC2 (C7i, M7i, and R7i instances), Amazon S3 with the One Zone-Infrequent Access storage class, Amazon EBS, Amazon ECS, and more.</p>
<p><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-613" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026-1.jpg" alt="Athens, Greece skyline" width="2560" height="846"></p>
<p>With this launch, you can process and store data in-country while delivering single-digit millisecond latency to your end users. AWS Local Zones place AWS infrastructure much closer to large population and industry hubs to support workloads such as financial services, healthcare, media production, and real-time gaming. For builders in Greece, this means running latency-sensitive workloads locally and meeting in-country data residency requirements, without managing your own data center infrastructure. To learn more, visit AWS Global Infrastructure and Sustainability Blog post.</p>
<p><strong>Last week&rsquo;s launches</strong><br>
        <br>Here are some launches and updates from this past week that caught my attention:</p>
<ul>
<li>Claude Opus 5 on AWS: You can use Anthropic&rsquo;s Claude Opus 5, the most advanced Opus model yet, matching Claude Fable 5&rsquo;s top-tier intelligence in many domains at Opus-tier pricing. Amazon Bedrock offers Claude Opus 5 with zero data retention (ZDR) enabled by default, giving you Opus&rsquo; top-tier intelligence while meeting your data governance requirements unlike Claude Fable 5. You have two ways to access Claude Opus 5: Amazon Bedrock and Claude Platform on AWS. To learn more, visit the deep dive blog post.</li>
<li>AWS Lambda durable execution SDK for .NET is now generally available: You can now build resilient, long-running workflows in C# using Lambda durable functions, without implementing custom progress tracking or integrating an external orchestration service. The SDK is a natural fit for multi-step applications like payment processing pipelines, AI agent orchestration, and human-in-the-loop approvals, it checkpoints progress automatically and can pause execution for up to a year. If you&rsquo;re a .NET developer building serverless workflows, this removes a lot of the plumbing you used to write by hand.</li>
<li>Amazon Bedrock AgentCore now delivers unified observability with traces and logs in a single log group: Amazon Bedrock AgentCore now delivers agent traces and prompts to the same Amazon CloudWatch log group as your agent&rsquo;s logs. Previously, telemetry was split across destinations, trace spans went to a shared log group while prompts, inputs, and outputs went to a separate one, so debugging a single agent invocation meant searching in multiple places. You can now debug an invocation in one place, and apply fine-grained access control and customer-managed key (CMK) encryption at the individual agent level.</li>
<li>Amazon Connect delivers more natural agentic voice experiences: Amazon Connect now supports more natural, human-sounding agentic voice experiences across 50+ languages, including Portuguese, Spanish, French, Italian, Japanese, Korean, and Thai, with over 100 new voice options and conversational improvements that make AI interactions sound more fluid. Connect&rsquo;s agentic self-service lets AI agents understand, reason, and take action across voice and digital channels, adapting to a customer&rsquo;s tone and sentiment. You can now build contact center experiences that feel natural to callers in far more of the languages your customers actually speak.</li>
<li>Amazon SageMaker Unified Studio now supports Amazon OpenSearch: You can now query and analyze your search and log analytics data from Amazon OpenSearch directly alongside other data assets in Amazon SageMaker Unified Studio. With this connection, you can combine operational search data in OpenSearch with data from sources like Amazon Redshift, Amazon S3, and relational databases, all within a single, governed environment. It&rsquo;s especially useful when you need to correlate analytical and operational workloads, such as joining application logs with transactional data to uncover insights.</li>
<li>Amazon CloudWatch announces coding agent insights: Amazon CloudWatch now gives engineering leaders visibility into how AI coding tools are driving value across their organization. Coding agent insights integrates with the Claude apps gateway for AWS to collect telemetry from Claude Code without additional instrumentation, and also supports agents like Codex and GitHub Copilot. As teams scale AI coding adoption, you can now measure the return on that investment with metrics built on OpenTelemetry, no custom instrumentation required.</li>
</ul>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/skipping-the-whm-getting-started-wizard-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Skipping the WHM Getting Started Wizard | cPanel Blog</span></a></div><p>For a full list of AWS announcements, be sure to keep an eye on the What&rsquo;s New with AWS page.</p>
<p><strong>Other AWS news</strong><br>
        <br>Here are some additional posts and resources that you might find interesting:</p>
<p><strong>Upcoming AWS events</strong><br>
        <br>Check your calendar and sign up for upcoming AWS events:</p>
<ul>
<li>AWS Summits: AWS Summits are free events that bring the cloud and AI community together to connect, learn, and explore the latest technologies. Browse the full calendar to find a Summit near you in the second half of 2026.</li>
<li>AWS Community Days: Community-led conferences where content is planned, sourced, and delivered by community leaders. If you&rsquo;re in Latin America, don&rsquo;t miss AWS Community Day Belo Horizonte on August 22, registration is open at awscommunityday.com.br.</li>
</ul>
<p>Join the AWS Builder Center to connect with builders, share solutions, and access content that supports your development. Browse here for upcoming AWS-led in-person and virtual events and developer-focused events.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/gone-phishing-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Gone Phishing | cPanel Blog</span></a></div><p>That&rsquo;s all for this week. Check back next Monday for another Weekly Roundup!</p>
<p><em>This post is part of our Weekly Roundup series. Check back each week for a quick roundup of interesting news and announcements from AWS!</em></p>
<p>       <!-- '"` --></p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-local-zone-in-athens-claude-opus-5-on-aws-lambda-durable-execution-for-net-and-more-july-27-2026/">AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution for .NET, and more (July 27, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cherish Your Tokens, Grumpy Designer</title>
		<link>https://thenokiablog.com/cherish-your-tokens-grumpy-designer/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Sun, 26 Jul 2026 09:24:13 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Dashboard]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Freelance Design]]></category>
		<category><![CDATA[Grumpy Designer]]></category>
		<category><![CDATA[SaaS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WordPress AI]]></category>
		<category><![CDATA[WordPress Plugins]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/cherish-your-tokens-grumpy-designer/</guid>

					<description><![CDATA[<p>In case you didn&#8217;t notice, it&#8217;s getting more expensive to ride the AI bandwagon. Web professionals...</p>
<p>The post <a href="https://thenokiablog.com/cherish-your-tokens-grumpy-designer/">Cherish Your Tokens, Grumpy Designer</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In case you didn&rsquo;t notice, it&rsquo;s getting more expensive to ride the AI bandwagon. Web professionals are using the technology to do more than write code. We&rsquo;re also employing it for just about every other task you can think of &ndash; even the most mundane ones. Tools like OpenClaw are taking our usage to new heights, literally. I mean, did you look at your latest bill?</p>
<p>Seriously, some of us are spending something close to a BMW&rsquo;s (or perhaps a Ferrari&rsquo;s) monthly payment on AI. What started as a small monthly fee to use ChatGPT, Claude, or Copilot has turned into something completely different. We have become the proverbial kids in the candy store.</p>
<p>It&rsquo;s a bad case of consumerism fueled by our desire to experiment with new toys. It doesn&rsquo;t help that AI companies are making it easy to spend significant money without a second thought. Integrating with your favorite SaaS or even WordPress is easy. Yet, the virtual cash register silently rings with each prompt and automation we create.</p>
<p>Perhaps all of this is happening too fast (maybe that&rsquo;s the intention). We may be falling into an AI-powered trap that will be difficult to escape.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>The Grumpy Designer likes to keep things rational. So, let&rsquo;s hit the brakes, take a step back, and analyze what we&rsquo;re doing. We&rsquo;re the only ones who can stop the insanity, after all.</p>
<h2><span id="Your_Monthly_AI_Plan_Isnt_All-Encompassing">Your Monthly AI Plan Isn&rsquo;t All-Encompassing</span></h2>
<p>The early days of AI (a whole 2-3 years ago) were exciting. I had fun playing around with ChatGPT and seeing what silly or productive things I could accomplish.</p>
<p>Its coding abilities may pale compared to what we have today. But it was still incredibly handy for troubleshooting and building basic WordPress plugins. I decided that their $20-per-month Plus plan was a relative bargain. It offered access to the latest models and improved performance.</p>
<p>And it&rsquo;s still a good deal, if you use it in your browser or their app. An individual performing occasional coding, image generation, or file analysis will get a lot for their money. It&rsquo;s once you step outside of those boundaries that things become costly and confusing.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>Such monthly plans typically don&rsquo;t provide you with API access. For that, you&rsquo;ll need to purchase tokens. It&rsquo;s a common practice across the big AI companies.</p>
<p>I won&rsquo;t argue with the premise of token-based usage. AI requires a lot of computing power to do its job. It must provide quick and accurate answers to user queries. Then there is the cost associated with training and improving each model.</p>
<p>The real problem lies in educating consumers on the differences. It&rsquo;s not until you need an API key that you realize your monthly plan won&rsquo;t cover you.</p>
<p><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/cherish-your-tokens-grumpy-designer.webp" alt="Monthly AI subscriptions typically don't include API access."></p>
<h2><span id="How_Much_Will_That_Task_Cost">How Much Will That Task Cost?</span></h2>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>Generating an API key and connecting your favorite AI model to a third-party service is simple. Figuring out how many tokens you&rsquo;ll need isn&rsquo;t so clear. That&rsquo;s the downside of not having a good/better/best pricing model.</p>
<p>Reputable AI companies let you set spending caps and disable auto-purchasing once you hit your limit. This will save you from a massive bill. It&rsquo;s also a good security measure, should your API key fall into the wrong hands.</p>
<p>However, experimentation is the only way to understand the costs of using AI tokens. Figure out what you want to do, ask AI to do it, and check your account dashboard to see how much you spent. The trick is to extrapolate that cost based on how many times you&rsquo;ll perform a given task.</p>
<p>The other challenge is that some tasks will use more tokens than others. For example, generating a headline for your blog post will likely cost less than generating a featured image. Thus, you&rsquo;ll want to watch your token usage carefully.</p>
<p>Setting a small spending limit may be fine for light-duty tasks. That strategy won&rsquo;t work for organizations with multiple users who are highly dependent on AI, though. You&rsquo;ll quickly run out of tokens and will have to go without the service or set a higher limit.</p>
<p>It appears that companies are beginning to realize that willy-nilly usage of AI is costly. Some will narrow the scope of what these tools do for them. It&rsquo;s also an argument for developing local AI models. Maybe we still need humans after all?</p>
<p><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/cherish-your-tokens-grumpy-designer-1.webp" alt="You'll need to experiment with tasks to see how many AI tokens they use."></p>
<h2><span id="Put_AI_in_Its_Place">Put AI in Its Place</span></h2>
<p>Sure, AI can do just about everything. But the decision on when and how to use it is ours to make. The increasing and uncertain token costs are reason enough to scrutinize every task. Some of what we&rsquo;re doing may not be worth the price.</p>
<p>There are other benefits to being less reliant on AI. Fewer tokens spent means less electricity (and less pollution). The environmental impact is real and only getting worse as more of us employ these models.</p>
<p>It&rsquo;s also an opportunity to stay connected to our humanity. Imagine all the knowledge we might lose if we cede every task to machines. There is also the potential to lose personal and professional relationships. Do you want to trade that for efficiency?</p>
<p>All of this makes me want to treat tokens as something to spend wisely. From now on, I&rsquo;ll ask myself: <em>Is this task tokenworthy?</em></p>
<div class="darp-related-posts">
<h2>Related Articles</h2>
</div>
<div class="topics">
<h2>Related Topics</h2>
</div>
<p>                                here. He recently started a writing service for WordPress products: WP Product Writeup.  He also has an opinion on just about every subject. You can follow his rants on Bluesky @karks.com.</p>
<p>
                        Read more articles by Eric Karkovack
                    </p>

<hr>
<p>The post <a href="https://thenokiablog.com/cherish-your-tokens-grumpy-designer/">Cherish Your Tokens, Grumpy Designer</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs</title>
		<link>https://thenokiablog.com/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Tue, 21 Jul 2026 10:00:00 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[Fonts]]></category>
		<category><![CDATA[Hosting]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs/</guid>

					<description><![CDATA[<p>While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same...</p>
<p>The post <a href="https://thenokiablog.com/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs/">Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><section aria-label="Quick summary" class="article__summary"><span id="article__start" class="summary__heading" aria-hidden="true"></span>While React Server Components rely on the custom Flight protocol to stream interactive UIs, this same mechanism introduces powerful deserialization sinks that attackers can exploit. Durgesh Pawar breaks down the mechanics behind the CVSS 10.0 &ldquo;React2Shell&rdquo; vulnerability to show how protocol manipulation can lead to remote code execution. It also covers a practical, ranked set of defenses, from strict schema validation to CSRF hardening, for securing React applications against these structural risks.</section>
</p>
<p>React Server Components don&rsquo;t send HTML to your browser. They don&rsquo;t send JSON either. When a server component renders, what actually travels over the wire is a custom streaming protocol called <strong>Flight</strong>. It&rsquo;s a line-delimited format with its own type system, its own reference resolution, and its own rules for reconstructing executable behavior on the client.</p>
<p>Most React developers have never opened the Network tab and actually looked at a Flight payload. It looks like a mix of JSON fragments, dollar-sign-prefixed references, and module pointers that the React runtime silently reassembles into a live component tree. The framework handles it, so nobody questions it.</p>
<p>I&rsquo;m not sure most teams have thought carefully about what that trust actually implies.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>I started pulling apart the Flight protocol after CVE-2025-55182 dropped in December 2025. The security community called it <strong>React2Shell</strong>, and for good reason. It was a CVSS 10.0, unauthenticated remote code execution vulnerability sitting in the Flight deserialization layer. One crafted HTTP request to a Server Function endpoint, and an attacker had shell access. No credentials needed.</p>
<p>The federal Cybersecurity &amp; Infrastructure Agency (CISA) added it to the Known Exploited Vulnerabilities catalog. Sysdig tied in-the-wild exploitation to North Korean state-sponsored actors deploying file-less implants through the Ethereum blockchain. That&rsquo;s the kind of CVE that gets your attention.</p>
<p>After spending time in the source (mostly <code>getOutlinedModel</code> and <code>getChunk</code>, which is where the resolution logic that matters actually lives), I realized React2Shell wasn&rsquo;t a one-off parsing bug. It was a symptom. Flight reconstructs executable references, lazy-loaded components, server RPC endpoints, and async state from a stream of text. That&rsquo;s a <strong>deserialization system</strong>.</p>
<p>The attack surface extends well beyond a single missing hasOwnProperty check. This article covers how Flight works on the wire, where the deserialization sinks are, what attackers have already weaponized, and what&rsquo;s still exposed.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>This leads to a <strong>ranked, practical set of defenses</strong> for your own Server Components: schema validation on every Server Action, the server-only package, cross-site request forgery (CSRF) hardening beyond framework defaults, and an assessment of what the Taint API and Web Application Firewalls (WAFs) provide.</p>
<div data-audience="non-subscriber" data-remove="true" class="feature-panel-container"><img decoding="async" loading="lazy" class="feature-panel-image-img" src="https://thenokiablog.com/wp-content/uploads/2026/07/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs.jpg" alt="Feature Panel" width="690" height="790"></div>


<h3 id="table-of-contents">Table of Contents</h3>
<h2 id="flight-on-the-wire">Flight On The Wire</h2>
<p>Open your browser&rsquo;s Network tab on any Next.js App Router page and look for requests returning <code>Content-Type: text/x-component</code>. That&rsquo;s Flight. It&rsquo;s not a single JSON blob. It&rsquo;s a streaming, line-delimited format where each line is a self-contained &ldquo;row&rdquo; that the client-side React runtime processes as it arrives over the connection.</p>
<p>Here&rsquo;s what a simple Flight payload looks like in practice:</p>
<div class="break-out">
<pre><code class="language-javascript">1:I["./src/components/ClientComponent.js",["chunks/main.js"],"default"]
2:J["$","article",null,{"children":"$1"}]
0:D{"name":"RootLayout","env":"Server"}
</code></pre>
</div>
<p>Row 1 is an import directive. It tells the client to load <code>ClientComponent.js</code> from the bundler&rsquo;s chunk map. Row 2 is a JSON tree that constructs an <code>&lt;article&gt;</code> HTML element, and the <code>"$1"</code> inside <code>children</code> is a reference back to chunk 1 (the imported component). Row 0 defines the server execution context, marking this as a <code>RootLayout</code> running in the <code>Server</code> environment. Even in this tiny example, you can see the mix of structural data, module references, and cross-chunk pointers that makes Flight different from plain JSON.</p>
<h3 id="the-row-format">The Row Format</h3>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>Every row follows the same syntax: <code>&lt;ROW_ID&gt;:&lt;ROW_TAG&gt;&lt;PAYLOAD&gt;n</code>. The row ID is a numeric identifier that other rows can reference. The tag is a single character (or short string) that tells the parser what kind of data follows. The payload is the actual content.</p>
<p>Here are the row tags I found while reading through the source:</p>
<table class="tablesaw break-out">
<thead>
<tr>
<th>Tag</th>
<th>Name</th>
<th>What it does</th>
</tr>
</thead>
<tbody>
<tr>
<td>J</td>
<td>JSON Tree</td>
<td>Serialized virtual DOM nodes, component props, and HTML elements.</td>
</tr>
<tr>
<td>M</td>
<td>Module</td>
<td>Metadata for a specific Client Component module or chunk.</td>
</tr>
<tr>
<td>I</td>
<td>Import</td>
<td>Tells the client to load a module from the bundler&rsquo;s chunk map.</td>
</tr>
<tr>
<td>HL</td>
<td>Hint/Preload</td>
<td>Instructs the browser to preload resources such as stylesheets or fonts.</td>
</tr>
<tr>
<td>D</td>
<td>Data</td>
<td>Server-rendered element context and environment info.</td>
</tr>
<tr>
<td>E</td>
<td>Error</td>
<td>Serialized server-side exceptions and error boundaries.</td>
</tr>
</tbody>
</table>
<p>So far, this might look like a benign structured data format with some custom tags, but the real complexity and attack surface live in the <strong>prefix system</strong>.</p>
<h3 id="the-prefix-system">The <code>$</code> Prefix System</h3>
<p>This is where I started paying closer attention.</p>
<p>When the client-side parser encounters a string value starting with <code>$</code>, it doesn&rsquo;t treat it as literal text. It intercepts the string, checks the prefix, and routes it through a type-specific resolution path. The <code>parseModelString</code> function in <code>ReactFlightClient.js</code> is where this happens. It&rsquo;s essentially a big switch statement on the character after <code>$</code>.</p>
<table class="tablesaw break-out">
<thead>
<tr>
<th>Prefix</th>
<th>Type</th>
<th>What the parser does with it</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>$</code></td>
<td>Model Reference</td>
<td>Resolves to another chunk in the stream (e.g., <code>$2</code> points to row 2).</td>
</tr>
<tr>
<td><code>$:</code></td>
<td>Property Access</td>
<td>Traverses into a resolved chunk&rsquo;s properties (e.g., <code>$1:user:name</code>).</td>
</tr>
<tr>
<td><code>$S</code></td>
<td>Symbol</td>
<td>Creates a native JavaScript <code>Symbol</code>.</td>
</tr>
<tr>
<td><code>$F</code></td>
<td>Server Reference</td>
<td>Represents a callable Server Action (an RPC endpoint on the server).</td>
</tr>
<tr>
<td><code>$L</code></td>
<td>Lazy Component</td>
<td>Defers component loading until it&rsquo;s needed in the render tree</td>
</tr>
<tr>
<td><code>$@</code></td>
<td>Promise/Raw Chunk</td>
<td>Returns the internal Chunk wrapper object itself (often acting as a Thenable/Promise), not its resolved value.</td>
</tr>
<tr>
<td><code>$B</code></td>
<td>Blob/Binary</td>
<td>Triggers the blob deserialization handler for binary data.</td>
</tr>
</tbody>
</table>
<p>Every other prefix resolves a chunk and gives you the parsed result. <code>$@</code> hands you the raw internal <code>Chunk</code> object instead, the wrapper React uses to track resolution state, pending callbacks, and internal metadata (which is why it&rsquo;s used for Promises and why exploits use it to get a mutable handle). Exposing framework plumbing through the protocol looks like a design mistake to me, though I&rsquo;d be interested to hear the rationale if there is one.</p>
<p>And <code>$:</code> (property access) is the other critical prefix. It lets the protocol specify a path like <code>$1:user:name</code>, which tells the parser to resolve chunk 1, then access <code>.user</code>, then access <code>.name</code> on the result. That&rsquo;s arbitrary property traversal driven by data in the stream. If you&rsquo;ve spent any time auditing JavaScript for prototype pollution, that pattern should feel familiar.</p>
<h3 id="this-is-not-just-a-data-format">This Is Not Just A Data Format</h3>
<p>Flight is not JSON with extra steps. JSON gives you data. Flight gives you <strong>behavior</strong>. It reconstructs module references that trigger client-side code loading, creates server action endpoints the client can invoke as RPC calls, sets up Promise chains that the React runtime will <code>await</code>, and builds lazy-loaded component boundaries that execute on demand.</p>
<p>Whether React developers think of it that way or not, the mechanics look very similar to deserialization systems that have historically caused problems. The stream doesn&rsquo;t just describe what the UI looks like. It instructs the client runtime on what code to load, what functions to call, and what to trust.</p>
<p>If you want to read the implementation yourself, fair warning: the chunk resolution path is miserable to follow. State transitions bounce between helper functions, and the naming obscures what the code is actually doing. I gave up on static reading and just set breakpoints. The key files are react-client/src/ReactFlightClient.js for the client-side parser (look for <code>parseModelString</code>, <code>getChunk</code>, <code>reviveModel</code>, and <code>getOutlinedModel</code>) and react-server/src/ReactFlightServer.js for the serialization side. The reply handler for Server Actions lives in react-server/src/ReactFlightReplyServer.js.</p>
<h2 id="why-flight-is-a-deserialization-sink">Why Flight Is A Deserialization Sink</h2>
<p>The deserialization pattern is familiar: Java&rsquo;s <code>ObjectInputStream</code> gave us ysoserial, Python&rsquo;s <code>pickle</code> executes code on <code>load()</code>, PHP&rsquo;s <code>unserialize</code> chains <code>__wakeup</code> and <code>__destruct</code> methods, and .NET&rsquo;s <code>BinaryFormatter</code> was deprecated entirely.</p>
<blockquote><p>The pattern: deserialize attacker-controlled input &rarr; invoke behavior during reconstruction &rarr; lose control of execution.</p></blockquote>
<p>So JavaScript should be immune to this, right? <code>JSON.parse()</code> only produces plain data objects. No constructors fire. No magic methods run. You get back exactly what the JSON string describes, nothing more.</p>
<p>That&rsquo;s true for raw <code>JSON.parse()</code>. But it stops being true the moment a framework wraps custom deserialization logic around it. And that&rsquo;s exactly what Flight does.</p>
<h3 id="prototype-pollution">Prototype Pollution</h3>
<p>JavaScript uses prototype-based inheritance. Every object has a <code>__proto__</code> link to its prototype, and property lookups walk up this chain. If an attacker injects <code>__proto__</code> or <code>constructor.prototype</code> as a key during reconstruction, they modify the shared base prototypes that all objects inherit from. Downstream code reads attacker-controlled values without knowing.</p>
<p>Flight&rsquo;s <code>$:</code> prefix performs property traversal on deserialized objects. The <code>getOutlinedModel</code> function walks colon-separated paths like <code>$1:user:name</code> by iterating through each segment and accessing it on the parent object. If those path segments include <code>__proto__</code> or <code>constructor</code>, the traversal walks straight up the prototype chain. That&rsquo;s not a theoretical risk. It&rsquo;s exactly how React2Shell worked.</p>
<h3 id="duck-typing-and-thenables">Duck Typing and Thenables</h3>
<p>The V8 engine (and the JavaScript spec) treats any object with a <code>.then</code> property as a <strong>Thenable</strong>. When you <code>await</code> something, the runtime checks for <code>.then</code> and calls it if it exists. No class check. No internal slot verification. If <code>.then</code> is callable, it gets invoked.</p>
<p>Flight resolves chunks asynchronously. If an attacker constructs an object with a manipulated <code>.then</code> property and gets it into the chunk resolution pipeline, the runtime calls the attacker&rsquo;s function during normal await behavior. The language semantics do the work.</p>
<p>I initially focused on <code>$F</code> because forging Server Action references seemed like the obvious attack surface. After tracing the resolution path, <code>$:</code> property traversal looked much more interesting. I also spent a few hours examining chunk status transitions (pending, blocked, resolved, errored) to see if you could force a chunk into an unexpected state, though that approach didn&rsquo;t yield any results.</p>
<h3 id="the-core-problem">The Core Problem</h3>
<p>These two risks converge in Flight because the protocol doesn&rsquo;t just deserialize data. It deserializes <em>behavior</em>. The <code>$</code> prefix system dictates which execution path the parser takes: <code>$F</code> creates a callable server endpoint, <code>$L</code> sets up lazy code loading, <code>$B</code> triggers a blob handler, <code>$@</code> exposes internal framework state. The parser&rsquo;s control flow is driven entirely by what&rsquo;s in the stream.</p>
<p>If an attacker can influence the stream&rsquo;s content, they control which functions the parser calls, which objects it constructs, and which internal state it exposes.</p>
<h2 id="the-mechanics-of-react2shell">The Mechanics Of React2Shell</h2>
<p>This is the CVE that proved the theory. CVE-2025-55182, nicknamed React2Shell, is a CVSS 10.0 unauthenticated remote code execution vulnerability in the Flight deserialization layer. One HTTP request, no login required, full shell access.</p>
<p>I want to walk through the entire gadget chain because understanding it reveals how much power the Flight protocol hands to an attacker who can control the stream.</p>
<h3 id="the-root-cause">The Root Cause</h3>
<p>The vulnerability sits in <code>getOutlinedModel</code>, a function responsible for resolving deep property paths from the <code>$:</code> reference system. The instance used in the exploit chain lives in the server-side reply handling code (<code>ReactFlightReplyServer.js</code>). When the parser encounters a reference like <code>$1:user:name</code>, it splits on the colons and walks the path segment by segment. Here&rsquo;s the vulnerable loop:</p>
<pre><code class="language-javascript">for (key = 1; key &lt; reference.length; key++)
    parentObject = parentObject[reference[key]];
</code></pre>
<p>Two lines. No <code>hasOwnProperty</code> check. No validation that the property exists on the object itself rather than somewhere up the prototype chain. Just <code>parentObject[reference[key]]</code> and move on.</p>
<p>So an attacker supplies <code>$1:__proto__:constructor:constructor</code>, and the loop traverses from a plain JSON object up through <code>Object.prototype</code> to the <code>Object</code> constructor to the <code>Function</code> constructor. <code>Function</code> in JavaScript behaves like <code>eval()</code>. <code>Function("arbitrary code")()</code> executes.</p>
<p>No allowlist on property names. No check for <code>__proto__</code>. I searched <code>reviveModel</code> and the chunk initialization path for any filtering. Nothing.</p>
<h3 id="the-gadget-chain">The Gadget Chain</h3>
<p>Getting from <em>&ldquo;I can reach the Function constructor&rdquo;</em> to <em>&ldquo;I have RCE&rdquo;</em> requires chaining several Flight protocol features together. The Resecurity write-up covers the full chain in detail; here&rsquo;s the high-level sequence:</p>
<ul>
<li><strong>Step 1: Prototype walk to Function.</strong><br>The <code>$:</code> path <code>__proto__:constructor:constructor</code> walks from any plain object to <code>Object.prototype</code>, then to the <code>Object</code> constructor, then to <code>Function</code> &mdash; JavaScript&rsquo;s built-in <code>eval()</code> equivalent.</li>
<li><strong>Step 2: Raw chunk self-reference.</strong><br><code>$@0</code> returns the raw internal <code>Chunk</code> wrapper instead of its resolved value, giving the attacker a mutable handle on React&rsquo;s internal state machine.</li>
<li><strong>Step 3: Thenable hijack.</strong><br>The attacker sets the chunk&rsquo;s <code>.then</code> to <code>Chunk.prototype.then</code>, so React&rsquo;s resolution pipeline treats the manipulated chunk as a legitimate Promise-like object and awaits it.</li>
<li><strong>Step 4: Context confusion.</strong><br>During the second deserialization pass, the payload overwrites <code>_response._formData.get</code> to point to the hijacked <code>Function</code> constructor and places the attacker&rsquo;s shell command into <code>_response._prefix</code>.</li>
<li><strong>Step 5: Trigger via blob handler.</strong><br><code>$B0</code> invokes the blob handler, which internally calls <code>response._formData.get(response._prefix + blobId)</code> &mdash; now equivalent to <code>Function("attacker_shell_command")()</code>. That&rsquo;s arbitrary code execution with whatever privileges the Node.js process has.</li>
</ul>
<p>Each step uses a legitimate Flight protocol feature in a way the designers didn&rsquo;t anticipate. There&rsquo;s no single &ldquo;broken&rdquo; feature. The vulnerability emerges from how these features compose when an attacker controls the input.</p>
<h3 id="impact">Impact</h3>
<p>The numbers on this one are stark:</p>
<ul>
<li>CVSS 10.0. The maximum possible score.</li>
<li>Unauthenticated and pre-auth. No credentials needed &mdash; and the deserialization happens before any application-level auth checks run, so even endpoints behind login walls are exposed.</li>
<li>Single HTTP request. One POST to a Server Function endpoint.</li>
<li>Affected React 19.0.0, 19.1.0, 19.1.1, and 19.2.0, across <code>react-server-dom-webpack</code>, <code>react-server-dom-parcel</code>, and <code>react-server-dom-turbopack</code>.</li>
<li>CISA added it to the Known Exploited Vulnerabilities catalog within days.</li>
</ul>
<h3 id="what-happened-in-the-wild">What Happened In The Wild</h3>
<p>Exploitation was immediate. Sysdig published research linking <strong>EtherRAT</strong> deployments to North Korean state-sponsored actors who weaponized the vulnerability within hours of disclosure. EtherRAT is a file-less implant that uses the Ethereum blockchain for command-and-control communication &mdash; a technique researchers call &ldquo;EtherHiding&rdquo; &mdash; making takedown nearly impossible because you can&rsquo;t seize a blockchain.</p>
<p>Separately, Palo Alto&rsquo;s Unit 42 documented a backdoor called <strong>KSwapDoor</strong> that masquerades as <code>[kswapd1]</code> on infected Linux systems, blending into process lists alongside the legitimate <code>kswapd0</code> kernel swap daemon; their analysis confirms KSwapDoor uses RC4 encryption to protect its internal strings and configuration data, while C2 communications run over AES-256-CFB with Diffie-Hellman key exchange across a P2P mesh network. The speed and sophistication of these campaigns &mdash; state-sponsored actors deploying novel implants through a single unauthenticated HTTP request &mdash; underscores why a CVSS 10.0 in a deserialization layer demands immediate patching, not triage.</p>
<h2 id="the-fix">The Fix</h2>
<p>The React team&rsquo;s patch is clean and targeted. The core change caches the genuine <code>hasOwnProperty</code> method at module load time:</p>
<pre><code class="language-javascript">var hasOwnProperty = Object.prototype.hasOwnProperty;
</code></pre>
<p>Then every property check in the deserialization path uses <code>.call()</code> to invoke the cached reference:</p>
<pre><code class="language-javascript">hasOwnProperty.call(value, i);
</code></pre>
<p>Even if an attacker shadows <code>hasOwnProperty</code> on a malicious object, the check uses the original prototype method. The prototype chain traversal that powered the gadget chain is blocked. This fix shipped in React 19.0.1, 19.1.2, and 19.2.1.</p>
<p>The fix is correct. But reading through the patches, I noticed the React team hardened ownership checks while leaving the property traversal model intact. The <code>$:</code> prefix still walks colon-separated paths; it just validates each step now. I think exposing arbitrary property traversal through a network protocol was a design mistake, and the patch treats the symptom. If future bugs emerge, they&rsquo;ll likely come from this same area.</p>
<p>The framework patch closes the known gadget chain, but it doesn&rsquo;t change the fundamental dynamic: the Flight protocol still reconstructs behavior &mdash; executable references, module imports, RPC endpoints, async state &mdash; from a stream of text. That reconstruction happens before your application code runs, before your validation logic fires, before your auth middleware even sees the request. Relying solely on the framework to protect your Server Components means trusting that every edge case in a complex deserialization parser has been found and fixed. The defenses that follow are the practical steps you can take to limit the blast radius on your own.</p>
<h2 id="defenses-ranked-by-impact">Defenses, Ranked By Impact</h2>
<p>Some of these close real attack paths. Others mostly make you feel safer than you are. I&rsquo;ve ranked these from most-to-least impactful based on what I&rsquo;ve seen in the vulnerability research. If you only have time for one change, start at the top.</p>
<h3 id="1-input-validation-on-server-actions-zod-valibot">1. Input Validation On Server Actions (Zod, Valibot)</h3>
<p>This is the single most impactful thing you can do at the application level. The Flight deserializer processes raw, unvalidated network input before your code takes control. Strict schema validation is your primary defense against whatever the protocol reconstructs.</p>
<p>Put a schema validation call at the very top of every Server Action, before any business logic runs &mdash; and I mean before <em>anything</em>, including logging. If you log an argument before validating it, and that argument triggers the stringification bug from CVE-2025-55183, you&rsquo;ve leaked source code before your validation even had a chance to run.</p>
<p>Zod and Valibot both work well for this. Validate types, shapes, string lengths, numeric bounds, and enumerated values. Reject anything that doesn&rsquo;t match. Use <code>.safeParse()</code>, not <code>.parse()</code> &mdash; the throwing variant can surface internal error details in the response if you&rsquo;re not careful with your error boundaries.</p>
<pre><code class="language-typescript">"use server"
import { z } from "zod"

const UpdateProfileSchema = z.object({
  name: z.string().min(1).max(100),
  email: z.string().email(),
  role: z.enum(["user", "editor"]),
})

export async function updateProfile(formData: FormData) {
  const parsed = UpdateProfileSchema.safeParse({
    name: formData.get("name"),
    email: formData.get("email"),
    role: formData.get("role"),
  })
  if (!parsed.success) return { error: "Invalid input" }
  // proceed with parsed.data, this is now the only shape
  // your business logic ever sees
}
</code></pre>
<p><strong>One important nuance</strong>: If your Server Action accepts a plain object argument (not <code>FormData</code>), validate the whole argument &mdash; don&rsquo;t destructure first and validate fields individually. Destructuring before validation means you&rsquo;re already accessing properties on the unvalidated input, which is exactly the kind of operation the Flight deserializer can exploit.</p>
<pre><code class="language-typescript">"use server"
import { z } from "zod"

const CommentSchema = z.object({
  postId: z.string().uuid(),
  body: z.string().min(1).max(5000),
})

// Good: validate the raw argument first
export async function addComment(data: unknown) {
  const parsed = CommentSchema.safeParse(data)
  if (!parsed.success) return { error: "Invalid input" }
  await db.comments.create(parsed.data)
}

// Bad: destructuring before validation
export async function addCommentUnsafe(
  { postId, body }: { postId: string; body: string }
) {
  // by the time this runs, you've already accessed properties
  // on the deserialized input
  const parsed = CommentSchema.safeParse({ postId, body })
  // ...
}
</code></pre>
<p>If your Server Action doesn&rsquo;t start with a schema parse, it&rsquo;s a vulnerability waiting to happen. I&rsquo;d argue this should be a lint rule &mdash; and if you&rsquo;re running <code>eslint-plugin-react</code>, consider writing a custom rule that flags any <code>"use server"</code> export without a validation call in its first statement.</p>
<h3 id="2-the-server-only-package">2. The <code>server-only</code> Package</h3>
<p>The <code>server-only</code> package is straightforward and effective.</p>
<p>Import <code>server-only</code> at the top of any file that contains database credentials, raw API calls, internal business logic, or anything else that should never cross the server-client boundary. If a Client Component tries to import that file (directly or transitively), the build fails with a clear error.</p>
<pre><code class="language-typescript">import "server-only"
import { db } from "./database"

export async function getUser(id: string) {
  return db.query("SELECT * FROM users WHERE id = $1", [id])
}
</code></pre>
<p>The failure mode to watch for is barrel files. If you re-export a server-only function through an <code>index.ts</code> that also exports client-safe utilities, any Client Component importing from that barrel will pull in the <code>server-only</code> module transitively and break the build &mdash; or worse, if the barrel doesn&rsquo;t include the <code>server-only</code> import itself, it may silently let server code through. Keep server-only modules in separate files with their own import paths.</p>
<pre><code class="language-typescript">// Don't do this: barrel re-export mixes boundaries
// src/utils/index.ts
export { getUser } from "./users"     // has "server-only"
export { formatDate } from "./dates"  // client-safe

// Do this: separate import paths
// Client Component imports from "src/utils/dates" directly
// Server Component imports from "src/utils/users" directly
</code></pre>
<p>It also won&rsquo;t protect you from data leaking through <em>return values</em>. If a Server Component calls <code>getUser()</code> and passes the full user object (including <code>passwordHash</code> or <code>internalRole</code>) as props to a Client Component, that data rides the Flight stream to the browser. The <code>server-only</code> guard prevents the <em>code</em> from crossing the boundary, not the <em>data</em> the code returns. You must explicitly filter your return shapes.</p>
<h3 id="3-csrf-protections">3. CSRF Protections</h3>
<p>After CVE-2026-27978, relying solely on Next.js&rsquo;s built-in <code>Origin</code> vs. <code>Host</code> header check isn&rsquo;t enough. The <code>Origin: null</code> bypass showed that framework-level CSRF protection has edge cases.</p>
<p>For state-changing Server Actions (anything that writes data, deletes records, or modifies permissions), layer your own protections on top of the framework&rsquo;s defaults.</p>
<p><strong>Cookie configuration.</strong><br>Set <code>SameSite=Strict</code> or <code>SameSite=Lax</code> on session cookies. If you&rsquo;re using <code>next-auth</code> or a custom session library, verify this is set explicitly &mdash; don&rsquo;t rely on browser defaults, which vary.</p>
<pre><code class="language-typescript">// next.config.js or your auth configuration
cookies: {
  sessionToken: {
    name: "__session",
    options: {
      httpOnly: true,
      sameSite: "strict",
      secure: process.env.NODE_ENV === "production",
      path: "/",
    },
  },
}
</code></pre>
<p><strong>Explicit CSRF tokens.</strong><br>For high-value operations (password changes, role assignments, payment actions), generate a per-session CSRF token on the server, embed it in a hidden form field or custom header, and validate it in the Server Action before proceeding.</p>
<pre><code class="language-typescript">"use server"
import { cookies } from "next/headers"
import { validateCsrfToken } from "@/lib/csrf"

export async function deleteAccount(formData: FormData) {
  const token = formData.get("csrf_token") as string
  const sessionToken = (await cookies()).get("csrf_secret")?.value
  if (!validateCsrfToken(token, sessionToken)) {
    return { error: "Invalid request" }
  }
  // proceed with deletion
}
</code></pre>
<p><strong>The <code>allowedOrigins</code> gotcha.</strong><br>Never, under any circumstances, add <code>'null'</code> to <code>experimental.serverActions.allowedOrigins</code> in your Next.js config (even if the officially advisory is more nuanced, saying <em>&ldquo;unless intentionally required and additionally protected&rdquo;</em>). That string literal matches <code>Origin: null</code> &mdash; the exact header that sandboxed iframes send &mdash; and it reopens the CVE-2026-27978 bypass. If you&rsquo;re seeing CSRF failures from legitimate requests, the fix is to configure your reverse proxy to set the correct <code>Origin</code> and <code>Host</code> headers, not to weaken the validation.</p>
<pre><code class="language-javascript">// Never do this
module.exports = {
  experimental: {
    serverActions: {
      allowedOrigins: ["null"],  // reopens CSRF bypass
    },
  },
}
</code></pre>
<h3 id="4-the-hasownproperty-patch">4. The <code>hasOwnProperty</code> Patch</h3>
<p>I covered this in detail in the React2Shell section. The fix is correct, and it completely neutralizes the known gadget chain. It shipped fast, which I respect.</p>
<p>The action item here is to verify you&rsquo;re actually running a patched version. The RCE fix landed in React 19.0.1, 19.1.2, and 19.2.1. Check your lockfile:</p>
<pre><code class="language-bash"># npm
npm ls react react-dom react-server-dom-webpack

# pnpm
pnpm ls react react-dom react-server-dom-webpack

# yarn
yarn why react-server-dom-webpack
</code></pre>
<p>If you see 19.0.0, 19.1.0&acirc;&euro;&ldquo;19.1.1, or 19.2.0, you&rsquo;re vulnerable to the RCE. Update immediately. And don&rsquo;t stop there: the DoS fixes (CVE-2025-55184, CVE-2025-67779, CVE-2026-23864) require 19.0.4+, 19.1.5+, or 19.2.4+. If you updated after React2Shell and then stopped paying attention, you may still be running a version vulnerable to the DoS variants.</p>
<p>It&rsquo;s a reactive patch, not a structural redesign.</p>
<p><strong>Note</strong>: <em>More on that in Where This Goes Next.</em></p>
<h3 id="5-the-taint-api">5. The Taint API</h3>
<p>React&rsquo;s <code>taintObjectReference</code> and <code>taintUniqueValue</code> functions register objects or strings with the runtime. If tainted data tries to pass through the Flight serializer, it throws an error. The idea is to prevent sensitive data &mdash; user records, API keys, tokens &mdash; from accidentally leaking into the client.</p>
<p>Here&rsquo;s how it looks in practice:</p>
<div class="break-out">
<pre><code class="language-typescript">import {
  experimental_taintObjectReference as taintObjectReference
} from "react"
import "server-only"

export async function getUserRecord(id: string) {
  const user = await db.users.findUnique({ where: { id } })
  taintObjectReference(
    "Do not pass the full user object to Client Components. " +
    "Select only the fields you need.",
    user
  )
  return user
}
</code></pre>
</div>
<p>If a Server Component passes the tainted <code>user</code> object as props to a Client Component, React throws it at serialization time with your custom error message. That&rsquo;s genuinely useful as a development-time guardrail.</p>
<p>The catch &mdash; and it&rsquo;s a significant one &mdash; is that taint tracks <em>object references</em>, not data content. Any derivation breaks the tracking:</p>
<pre><code class="language-typescript">const user = await getUserRecord(id)

// taint is lost. Spread creates a new object.
&lt;ClientProfile user={{ ...user }} /&gt;

// taint is lost. Individual properties aren't tracked.
&lt;ClientProfile token={user.apiToken} /&gt;

// taint is lost. Serialization round-trip creates new refs.
&lt;ClientProfile user={JSON.parse(JSON.stringify(user))} /&gt;

// taint fires. Same object reference.
&lt;ClientProfile user={user} /&gt;
</code></pre>
<p><code>taintUniqueValue</code> works on specific strings (like API keys), but it&rsquo;s also reference-based. If the same key value appears in a different variable, the taint doesn&rsquo;t follow.</p>
<p>Think of taint as a development guardrail, not a security boundary. It catches honest mistakes: a developer accidentally passing a full user object to the client. It won&rsquo;t stop an attacker who can influence what gets serialized, and it won&rsquo;t survive routine data transformations that your own code performs. It&rsquo;s a useful defense-in-depth layer, but shouldn&rsquo;t be your primary boundary.</p>
<h3 id="6-wafs">6. WAFs</h3>
<p>Web Application Firewalls can add a detection layer for known attack patterns. They can inspect POST requests carrying the <code>Next-Action</code> header, block payloads containing <code>constructor:constructor</code> or <code>__proto__</code> chains, and flag error responses containing <code>E{"digest"</code> patterns that indicate the server is leaking internal error details.</p>
<p>If you&rsquo;re running a WAF, here are specific patterns worth adding:</p>
<pre><code class="language-bash"># Block prototype pollution attempts in request bodies
Rule: body contains "__proto__" OR "constructor:constructor"
Action: BLOCK
Scope: POST requests with header "Next-Action"

# Flag potential Flight error leakage in responses
Rule: response body matches /E{"digest":"[^"]+"/
Action: LOG + ALERT
Scope: responses with Content-Type "text/x-component"

# Block excessively large Server Action payloads
Rule: Content-Length &gt; 1MB for POST with "Next-Action" header
Action: BLOCK (mitigates CVE-2026-23864 zipbomb vector)
</code></pre>
<p>But attackers know about WAF inspection buffers, and they&rsquo;re usually around 128KB. Prepend 130KB of padding before the malicious payload, and the WAF inspects the padding, finds nothing, and lets the request through. Chunked Transfer-Encoding tricks accomplish the same thing.</p>
<p>The failure mode is treating WAF coverage as a security boundary rather than a noise-reduction layer. WAFs catch automated scanners and low-effort attacks, and that has real value. But a motivated attacker will bypass them with padding or encoding tricks. The defenses that actually stop sophisticated attacks are the ones earlier in this list: validating input before it reaches your business logic, keeping sensitive code off the wire, and staying on patched versions.</p>
<h2 id="what-came-after-react2shell">What Came After React2Shell</h2>
<p>React2Shell wasn&rsquo;t the end of it. The security audits that followed the December 2025 disclosure shook out a series of related vulnerabilities in the same deserialization surface. None of them are as severe as the original RCE, but they&rsquo;re worth tracking because some of them required multiple rounds of patching.</p>
<table class="tablesaw break-out">
<thead>
<tr>
<th>CVE</th>
<th>CVSS</th>
<th>Type</th>
<th>Description</th>
<th>Fixed In</th>
</tr>
</thead>
<tbody>
<tr>
<td>CVE-2025-55184</td>
<td>7.5</td>
<td>DoS</td>
<td>Infinite recursion of nested Promises in Server Function deserialization. Hangs the Node.js event loop.</td>
<td>19.0.2, 19.1.3, 19.2.2</td>
</tr>
<tr>
<td>CVE-2025-67779</td>
<td>7.5</td>
<td>DoS</td>
<td>Incomplete fix for CVE-2025-55184. Same loop via edge cases the first patch missed.</td>
<td>19.0.4, 19.1.5, 19.2.4</td>
</tr>
<tr>
<td>CVE-2026-23864</td>
<td>7.5</td>
<td>DoS/OOM</td>
<td>Unbounded request body buffering and zipbomb-style decompression. Memory exhaustion. Disclosed Jan 2026.</td>
<td>19.0.4+, 19.1.5+, 19.2.4+</td>
</tr>
<tr>
<td>CVE-2025-55183</td>
<td>5.3</td>
<td>Info Disclosure</td>
<td>Crafted requests reflect Server Function source code when the function stringifies an argument.</td>
<td>19.0.1, 19.1.2, 19.2.1</td>
</tr>
<tr>
<td>CVE-2026-27978</td>
<td>5.3</td>
<td>CSRF Bypass</td>
<td>Next.js treated <code>Origin: null</code> (sandboxed iframes) as &ldquo;missing&rdquo; instead of &ldquo;cross-origin.&rdquo;</td>
<td>Next.js 16.1.7</td>
</tr>
</tbody>
</table>
<p>The DoS pair (CVE-2025-55184 and CVE-2025-67779) is a textbook example of why deserialization parsers are hard to patch correctly. The first fix shipped, researchers found edge cases it missed, and a second round was needed. CVE-2026-23864 added a third DoS vector through unbounded memory allocation rather than CPU exhaustion. (See the defenses section above for specific version checks.)</p>
<p>CVE-2025-55183 is the sneaky one. It&rsquo;s a source code exposure bug that triggers when a Server Function calls <code>JSON.stringify</code> (or any implicit stringification) on one of its arguments. Developers do this constantly for logging, debugging, or error reporting.</p>
<p>The attacker sends a crafted argument that, when stringified, causes the deserialization parser to reflect the function&rsquo;s own source code back in the response. Business logic, database queries, and any hardcoded secrets sitting in Server Action files become readable by anyone who can send an HTTP request.</p>
<p>CVE-2026-27978 is a different class of bug entirely. It&rsquo;s a CSRF bypass in Next.js&rsquo;s Server Action handling. Next.js validates that the <code>Origin</code> header matches the <code>Host</code> header to prevent cross-site request forgery. But when a request comes from a sandboxed <code>&lt;iframe&gt;</code>, the browser sends <code>Origin: null</code>.</p>
<p>The Next.js parser in <code>action-handler.ts</code> treated the string <code>'null'</code> as a missing origin rather than an explicit cross-origin indicator. So an attacker could embed a form inside a sandboxed iframe, submit it, and invoke Server Actions using the victim&rsquo;s authenticated session cookies. Fixed in Next.js 16.1.7.</p>
<h2 id="what-s-still-exposed-a-name-whats-still-exposed-a">What&rsquo;s Still Exposed </h2>
<p>The CVEs above have patches. But some of the risk is structural, baked into how Flight is designed to work.</p>
<h3 id="man-in-the-middle-mitm-on-the-flight-stream">Man-In-The-Middle (MITM) On The Flight Stream</h3>
<p>If an attacker can sit between server and client (CDN compromise, cache poisoning, rogue proxy), modifying the Flight stream in transit looks feasible. The format is plain text with a predictable structure.</p>
<p>Assuming stream control, an attacker could alter <code>$I</code> (Import) rows to redirect component loading to a different module in the webpack chunk map. They could inject <code>$F</code> (Server Reference) tags to embed hidden RPC triggers in the rendered UI. They could modify <code>D</code> (Data) rows to change component props, and if the target component uses <code>dangerouslySetInnerHTML</code>, that&rsquo;s a direct XSS vector.</p>
<p>Flight escapes <code>$</code> prefixes in user-supplied strings to prevent data from being interpreted as protocol instructions. But that only applies to data flowing through the serializer. A MITM attacker writes raw protocol directly into the stream. The escaping doesn&rsquo;t help.</p>
<h3 id="server-action-enumeration">Server Action Enumeration</h3>
<p>Server Action IDs are obfuscated hashes generated at build time. They look random. But <code>server-reference-manifest.json</code> maps every action ID to its source implementation. A public manifest hands an attacker a complete API map. This exposure usually stems from misconfigured hosting, an exposed <code>.next</code> directory, or path traversal.</p>
<p>Known action IDs expose Server Actions to standard IDOR and parameter tampering attacks. An attacker can forge direct requests with manipulated arguments. Developers often trust these inputs blindly because they originate from React&rsquo;s internal machinery. The architectural consequences of that misplaced trust will be the focus of my next piece.</p>
<h3 id="encrypted-closure-tampering">Encrypted Closure Tampering</h3>
<p>When a Server Action captures variables from its surrounding scope (closures), Next.js encrypts them before sending to the client. The key is in <code>NEXT_SERVER_ACTIONS_ENCRYPTION_KEY</code>, AES with a base64-encoded key (16, 24, or 32 bytes). <code>decryptActionBoundArgs</code> handles decryption on each invocation.</p>
<p>By default, this key regenerates every build. But multi-server setups often use a static key. If an attacker gets file read access (path traversal, SSRF), they extract the key, decrypt the closure state, modify it (changing a <code>userId</code>, a <code>role</code>, a query parameter), and re-encrypt. The server accepts the forged closure as legitimate.</p>
<h3 id="supply-chain-activation-via-module-ids">Supply Chain Activation via Module IDs</h3>
<p>I haven&rsquo;t demonstrated this end-to-end, but the theory is straightforward.</p>
<p>Flight references client components by module ID, something like <code>["360","static/chunks/app/page-7f3480.js"]</code>. The bundler assigns these IDs at build time based on the module graph. A compromised npm package sitting in <code>node_modules</code> as a transitive dependency gets bundled into a chunk but never loaded because no component references it. Inert.</p>
<p>But if an attacker injects <code>$I</code> import references into the Flight stream (via MITM, cache poisoning, or server-side injection), the parser should load that dormant module. There may be chunk-level validation I&rsquo;m not seeing. But if the module ID is valid and present in the manifest, I don&rsquo;t see what stops it. The attack doesn&rsquo;t require the package to be imported anywhere in your code. It just needs to exist in the bundle output.</p>
<h2 id="this-has-happened-before">This Has Happened Before</h2>
<p>React Flight isn&rsquo;t the first framework to invent a custom serialization format for server-client communication and then discover it&rsquo;s an attack surface. And it won&rsquo;t be the last.</p>
<p>Google Web Toolkit (GWT) used a custom RPC protocol to sync Java objects between browser and server. BishopFox demonstrated that attackers could manipulate the wire format to achieve arbitrary deserialization; GWT eventually disabled binary serialization entirely. It took years.</p>
<p>Java Server Faces (JSF) and ASP.NET both serialized <strong><code>ViewState</code></strong> to the client as a hidden form field. When cryptographic signing was weak or missing, attackers tampered with the serialized state and achieved remote code execution. Microsoft and Oracle patched it repeatedly. The underlying pattern kept resurfacing.</p>
<p>The pattern is always the same: a framework invents a custom wire format to move rich, stateful, sometimes executable data between server and client. The designers assume the server is the sole producer of that data and the client is a trusted consumer. Then someone demonstrates that the wire format can be manipulated in transit, or that the server can be tricked into deserializing attacker-controlled input. React Flight is the latest entry in this pattern. It is <strong>not an anomaly</strong>.</p>
<h2 id="where-this-goes-next">Where This Goes Next</h2>
<p>The React Flight protocol solves a genuinely hard problem: streaming interactive component trees from server to client in a way that enables progressive hydration, async data loading, and server-driven code splitting. It works. I don&rsquo;t want to lose sight of that.</p>
<p>But it works by serializing executable references, async state, module pointers, and RPC endpoints over a streaming text protocol, and then trusting the structure of that stream on both ends. The React team has patched the known gadgets. The <code>hasOwnProperty</code> fix is correct. The DoS fixes are in place. The source code exposure bug is closed.</p>
<p>I think exposing arbitrary property traversal and executable Thenable reconstruction through a network-facing protocol was a <strong>design mistake</strong>. <code>$:</code>, <code>$@</code>, and <code>$B</code> are powerful internal primitives that were reachable through a parser that didn&rsquo;t validate ownership of the properties it traversed. One check was missing, and the result was CVSS 10.0.</p>
<blockquote class="pull-quote">
<p>As more frameworks adopt server-driven UI patterns, the industry is going to need stronger primitives than &ldquo;the server is trusted&rdquo;: cryptographic validation of serialized payloads, signed component trees, and content integrity checks on the Flight stream itself.</p>
</blockquote>
<p>Hoping the parser handles every edge case hasn&rsquo;t worked historically, and I don&rsquo;t see why it would start working now.</p>
<p>The code is in <code>react-client/src/ReactFlightClient.js</code>. If you ship Server Components, read it. Know what your framework is trusting on your behalf.</p>
<div class="signature"><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs.png" alt="Smashing Editorial" width="35" height="46" loading="lazy"><br>
<span>(gg, yk)</span></div>
<p>The post <a href="https://thenokiablog.com/weaponizing-and-defending-the-react-flight-protocol-deserialization-sinks-in-rscs/">Weaponizing And Defending The React Flight Protocol: Deserialization Sinks In RSCs</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)</title>
		<link>https://thenokiablog.com/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Mon, 20 Jul 2026 16:37:34 +0000</pubDate>
				<category><![CDATA[Nokia Mobile Phone]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Cognito]]></category>
		<category><![CDATA[Amazon DynamoDB]]></category>
		<category><![CDATA[Amazon Simple Storage Service (S3)]]></category>
		<category><![CDATA[Analytics]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[AWS Glue]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[AWS Support]]></category>
		<category><![CDATA[AWS WAF]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Dashboard]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Kiro]]></category>
		<category><![CDATA[Messaging]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Serverless]]></category>
		<category><![CDATA[Startup]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Strands Agents]]></category>
		<category><![CDATA[Week in Review]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/</guid>

					<description><![CDATA[<p>Last week, my team visited Seoul to meet AWS Korea User Group (AWSKRUG) leaders. AWSKRUG is...</p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/">AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<table id="amazon-polly-audio-table">
<tbody>
<tr>
<td id="amazon-polly-audio-tab">
<div id="amazon-polly-by-tab">
            <img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026.png" alt="Voiced by Polly" width="554" height="56">
           </div>
</td>
</tr>
</tbody>
</table>
<p>Last week, my team visited Seoul to meet AWS Korea User Group (AWSKRUG) leaders. AWSKRUG is the largest cloud developer community in Korea, with 20 meetup groups organized by topic and area that collectively host over 100 events each year, primarily in Seoul.</p>
<p>My team regularly visits countries across the Asia-Pacific region, listens to feedback from user group leaders, and works to support their communities. At this meeting, leaders honestly shared what they did well in the first half of the year, what needs improvement, and what they asked of AWS Developer Experience team. We also enjoyed a pleasant conversation during our Chimaek time together.</p>
<p><img decoding="async" class="aligncenter size-full wp-image-105075" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026.jpg" alt width="1800" height="991"></p>
<p>Now, let&rsquo;s take a closer look at key launches of last week.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/html-element-select-envato-tuts/" class="template-2"><span class="cta">Read more</span><span class="postTitle">HTML Element: select | Envato Tuts+</span></a></div><p>A one-click Lambda setup prompt for coding agents caught my eye most last week. This prompt configures your agent with AWS Serverless skills and the Serverless Model Context Protocol (MCP) server, embedding serverless best practices from the start. This prompt references the Lambda agent setup guide, which includes installation commands for Claude Code, Kiro, Cursor, GitHub Copilot, Codex, Devin Desktop, and OpenCode.</p>
<p>To get started, choose the <strong>Copy agent prompt</strong> button on the Lambda console screen or copy <code>fetch https://docs.aws.amazon.com/lambda/latest/dg/samples/aws-lambda-agent-setup.md</code> directly, and paste this URL in your preferred AI agent.</p>
<p><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-105071" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026-1.jpg" alt width="1800" height="1124"></p>
<p>You can also use Agent Toolkit for AWS to give your coding agent current AWS knowledge and safe resource access. Use <code>fetch https://raw.githubusercontent.com/aws/agent-toolkit-for-aws/refs/heads/main/setup-instructions/setup.md</code> for installing AWS MCP Server.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/skipping-the-whm-getting-started-wizard-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Skipping the WHM Getting Started Wizard | cPanel Blog</span></a></div><p><strong>Last week&rsquo;s launches</strong><br>
        <br>Here are last week&rsquo;s launches that caught my attention:</p>
<ul>
<li>OpenAI GPT-5.6 Sol, Terra, and Luna on Amazon Bedrock: You can use the smartest family of models from OpenAI yet on Bedrock&rsquo;s next-generation inference engine built for high performance, security, and reliability. The three models span capability tiers from flagship reasoning (Sol) to balanced performance (Terra) to fast, cost-efficient inference (Luna), all accessible through the Responses API on Amazon Bedrock.</li>
<li>Same-day transitions to Amazon S3 Standard-IA and S3 One Zone-IA: You can now transition objects to S3 Standard-Infrequent Access (S3 Standard-IA) and S3 One Zone-Infrequent Access (S3 One Zone-IA) as soon as the day they are created, without the previous 30-day minimum retention period in S3 Standard. These storage classes offer up to 40% lower storage costs than S3 Standard while still providing millisecond access when needed, making them ideal for backups, log analytics, and compliance workloads where data becomes cold within hours or days.</li>
<li>Self-managed code storage on AWS Lambda: With self-managed Amazon S3 buckets for code storage, you can reference source code directly from your own S3 buckets without Lambda creating intermediate copies. This eliminates code storage limits and reduces function activation time after function creates and updates by removing the copy step.</li>
<li>Importing users with password hashes on Amazon Cognito: You can now import users with password hashes in CSV user imports. Previously, imported users had to reset their passwords on first sign-in. Now, you can include password hashes in the CSV import, enabling users to sign in immediately with their existing credentials. When creating a CSV import, you specify the password hashing algorithm used by your source system.</li>
</ul>
<p>For a full list of AWS announcements, be sure to keep an eye on the What&rsquo;s New with AWS page.</p>
<p><strong>Additional updates</strong><br>
        <br>Here are some additional news items that you might find interesting:</p>
<ul>
<li>Amazon SQS turns 20: Two decades of reliable messaging at scale: When Amazon SQS launched publicly in July 2006, it made this pattern available to every AWS customer. Twenty years later, that core function, decoupling producers from consumers, remains the reason customers use SQS. Let&rsquo;s look back important milestones after&nbsp;Jeff&rsquo;s 15th anniversary post.</li>
<li>Open Protocols with the Strands Agents SDK: Learn how open AI protocols such as MCP, A2A, UTCP, AG-UI, and x402 work together using Strands Agents SDK for building AI agents as an example implementation, though the patterns apply to any agent framework.</li>
<li>Open source Bulk Executor for Amazon DynamoDB: Performing bulk operations against all items in a DynamoDB table has historically required custom coding. The Bulk Executor for DynamoDB simplifies bulk tasks like these. You can use this feature to invoke commands like <code>count</code>, <code>find</code>, <code>delete</code>, or <code>update</code>. No coding is required, even when running at large scale.</li>
<li>Transform AWS Support Case Workflows with Kiro CLI: Explore how Kiro CLI&rsquo;s MCP integration accelerates support case workflows by combining investigation, documentation lookup, and case creation into a single conversational interface across three real-world scenarios: AWS Glue job failures, AWS Lambda cold start investigation, and AWS WAF false positive analysis.</li>
</ul>
<p>For a full list of AWS blog posts, be sure to keep an eye on the AWS Blogs page.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/gone-phishing-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Gone Phishing | cPanel Blog</span></a></div><p>Learn more about AWS, browse and join upcoming AWS-led in-person and virtual events, startup events, and developer-focused events including AWS Summits. Join the AWS Builder Center to connect with builders, share solutions, and access content that supports your development.</p>
<p>Finally, some customers experienced an issue with Cost Explorer displaying inaccurate estimated billing data in last weekend. They may have received erroneous budget and cost anomaly detection alerts, and observed inflated estimated cost and usage data. The issue has been resolved, and all AWS services are operating normally. We apologize for the concern this incident caused our customers and are conducting a thorough retrospective to prevent events like this from reoccurring, as well as improving our response when billing incidents occur. For more information, visit the AWS Health Dashboard.</p>
<p>That&rsquo;s all for this week. Check back next Monday for another Weekly Roundup!</p>
<p>&mdash; Channy</p>
<p>       <!-- '"` --></p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-one-click-lambda-setup-prompt-openai-gpt-5-6-models-on-bedrock-and-more-july-20-2026/">AWS Weekly Roundup: One-click Lambda setup prompt, OpenAI GPT-5.6 models on Bedrock, and more (July 20, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>20+ Best Color Grading LUTs for Lightroom</title>
		<link>https://thenokiablog.com/20-best-color-grading-luts-for-lightroom/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Sun, 19 Jul 2026 09:38:43 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Adobe Lightroom]]></category>
		<category><![CDATA[Color]]></category>
		<category><![CDATA[Color Schemes & Swatches]]></category>
		<category><![CDATA[Lightroom Presets]]></category>
		<category><![CDATA[LUTs]]></category>
		<category><![CDATA[Photo Effects]]></category>
		<category><![CDATA[Photography]]></category>
		<category><![CDATA[Photography LUTs]]></category>
		<category><![CDATA[WordPress]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/20-best-color-grading-luts-for-lightroom/</guid>

					<description><![CDATA[<p>You can use Lightroom Look-Up Tables (LUTs) to improve the look of any photo. They provide...</p>
<p>The post <a href="https://thenokiablog.com/20-best-color-grading-luts-for-lightroom/">20+ Best Color Grading LUTs for Lightroom</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>You can use Lightroom Look-Up Tables (LUTs) to improve the look of any photo. They provide an easy way to add all manner of professional effects. They are a must-have addition to every designer&rsquo;s toolbox.</p>
<p>Today, we&rsquo;ll introduce you to some fantastic color-grading LUTs for Adobe&rsquo;s Lightroom. These presets help you tell visual stories by adjusting aspects of your images, such as color, saturation, curves, and white balance. It&rsquo;s a way to convey emotion, mood, and even time.</p>
<p>Our collection features a variety of color grading options. Use them to depict times of day, seasons, and color temperature, among other unique effects. The possibilities are nearly endless!</p>
<p>You might be surprised at what can be accomplished through these simple add-ons. Not to mention the time you&rsquo;ll save by not having to edit your images manually.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>Ready to get started? Keep reading to find the perfect fit for your visual storytelling project.</p>
<p>You may also like our free collection of Lightroom LUTs.</p>
<p>Add warmth to your photos with these Lightroom presets. They&rsquo;re designed to bring out orange, red, and yellow tones. Use them to improve landscapes and portraits with a sunny glowing effect.</p>
<p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom.jpg" alt="Warm Tone Color Grading Lightroom LUTs" width="900" height="500"></p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>Are you looking to add a cool touch to your shots? These LUTs accentuate cool color tones, making your image stand out to a whole new level. They&rsquo;re perfect for making your subject pop.</p>
<p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-1.jpg" alt="Cool Tone Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Quickly add beautiful vintage film effects to your images with this collection. You can use these presets to bring out rich film tones and create a sense of magic. You&rsquo;ll find everything you need to design a classic look.</p>
<p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-2.jpg" alt="Vintage Film Color Grading Lightroom LUTs" width="900" height="500"></p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>This LUT collection offers a variety of cinematic styles. You&rsquo;ll find presets for different color temperatures and moods. It&rsquo;s an easy way to add a bit of Hollywood to your work.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-3.jpg" alt="Cinematic Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Enhance your lifestyle photography with this set of muted tone presets. They&rsquo;re great for setting a dark or serious mood. Even better, you can apply these eye-catching looks with a single click.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-4.jpg" alt="Muted Tone Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Create just the right mood with these LUTs. Inspired by a good cup of coffee, they bring rich, warm tones to photos. The large number of presets will help you find the perfect effect for your project.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-5.jpg" alt="Rich Color Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>These color-grading LUTs are designed to add cinematic tones to your photographs. Bring out a dramatic matte finish in an instant. You can also adjust these presets to fit your needs.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-6.jpg" alt="Matte Finish Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Soft pastel tones are great for portrait and landscape photography. They add a gentle touch and create a light mood. This LUT collection will help you add a look that will produce smiles.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-7.jpg" alt="Pastel Tone Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Enhance your urban landscapes with this set of desaturated Lightroom LUTs. Use them to create a moody and contemporary look with just a click. You&rsquo;ll find a variety of presets here to achieve your desired result.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-8.jpg" alt="Desaturated Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Nothing stands out more than an image with rich color contrast. These presets will help you create high-end contrast effects with minimal effort. Add them to your collection and bring out the best in your photos.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-9.jpg" alt="High Contrast Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>The warm glow of the &ldquo;golden hour&rdquo; is a longtime staple of photography. The color-grading LUTs in this pack can help you improve or even simulate the effect. Best of all, they work well with just about any photograph.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-10.jpg" alt="Golden Hour Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Use this collection of presets to add cool blue tones to your photos. They can bring a moody vibe to your landscapes and portraits. The effect is gentle on the eyes and easy to implement.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-11.jpg" alt="Blue Hour Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Bring your images to life with a bright, sun-kissed effect. The presets in this collection can improve even the dullest low-light photos. The gorgeous glow of a sunset is within your reach.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-12.jpg" alt="Sunset Glow Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Here&rsquo;s a fun collection to make your images look otherworldly. Multiple styles are available, each with a unique spin on infrared film effects. Experiment with these presets to discover a whole world of possibilities.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-13.jpg" alt="Infrared Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Ensure your color stands out with this set of cross-processed LUTs. Choose your desired color, and the preset will do the rest. It&rsquo;s a great way to add a dominant hue to your photos.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-14.jpg" alt="Cross Processed Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>These LUTs will desaturate your image &ndash; resulting in an understated tone. They&rsquo;re an excellent choice for fashion and landscape photos where a touch of nostalgia is needed. You&rsquo;ll have professional effects in no time.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-15.jpg" alt="Bleach Bypass Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Add a vibrant touch with these color-popping presets. You can turn your images from dull to vivid with just one click. Use them to create attention-grabbing social media, web, or print photos.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-16.jpg" alt="Color Pop Lightroom LUTs" width="900" height="500">#</p>
<p>Transform your photos with rich autumn tones that evoke the season&rsquo;s spirit. Each LUT offers cinematic quality with an array of options to choose from. A simple way to decorate your images for fall!</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-17.jpg" alt="Autumn Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Think of lush greens, pastel yellows, and bright whites. Bring out these springtime colors with a collection that&rsquo;s blooming with potential. It&rsquo;s perfect for outdoor nature shots and portraits.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-18.jpg" alt="Spring Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>Turn up the intensity with this collection of summer-themed LUTs. They&rsquo;re designed to accentuate the rich, warm tones of your photos. Use them to beautify your summer shots without breaking a sweat.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-19.jpg" alt="Summer Color Grading Lightroom LUTs" width="900" height="500"></p>
<p>These presets create a sharp and cool style reminiscent of winter. Each option focuses on a different shade, giving you multiple ways to make a statement. Use them on fashion, lifestyle, and outdoor images.</p>
<p><img decoding="async" loading="lazy" src="https://thenokiablog.com/wp-content/uploads/2026/07/20-best-color-grading-luts-for-lightroom-20.jpg" alt="Winter Color Grading Lightroom LUTs" width="900" height="500"></p>
<hr>
<p>More Lightroom Presets </p>

<div class="darp-related-posts">
<h2>Related Articles</h2>
<ul class="darp-related-posts-list">
<li class="darp-related-post">
<p>								20+ Free Lightroom Color Grading LUTs for Stunning Photo Effects</p>
<p>Make your photos stand out with our collection of free Lightroom LUTs. These presets will add stunning color grading effects to your images.</p>
</li>
<li class="darp-related-post">
<p>								20+ Seasonal Lightroom Presets &amp; LUTs for Photographers</p>
<p>Lightroom presets and LUTs created for seasonal photography. Adjust colors, tones, and moods for spring, summer, autumn, and winter photos with professional-quality edits.</p>
</li>
<li class="darp-related-post">
<p>								25+ Tutorials to Learn &amp; Master Adobe Lightroom</p>
<p>From basic techniques to advanced tips, these Lightroom tutorials cover topics such as adjusting exposure, color correction, noise reduction, and more.</p>
</li>
<li class="darp-related-post">
<p>								25+ Best Lightroom Presets for Wedding Photographers</p>
<p>Improve your wedding photography with these stunning Lightroom presets (both free and premium). All will add professional effects and improve the beauty of your photos.</p>
</li>
<li class="darp-related-post">
<p>								10+ Best Free Lightroom Presets for Black &amp; White Photography</p>
<p>A collection of free black and white Lightroom presets that offer various styles and dramatic effects, including classic, film, and sepia.</p>
</li>
</ul></div>
<div class="topics">
<h2>Related Topics</h2>
</div>
<p>                                here. He recently started a writing service for WordPress products: WP Product Writeup.  He also has an opinion on just about every subject. You can follow his rants on Bluesky @karks.com.</p>
<p>
                        Read more articles by Eric Karkovack
                    </p>

<hr>
<p>The post <a href="https://thenokiablog.com/20-best-color-grading-luts-for-lightroom/">20+ Best Color Grading LUTs for Lightroom</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>When It Makes Sense To “Block” The Main Thread</title>
		<link>https://thenokiablog.com/when-it-makes-sense-to-block-the-main-thread/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Fri, 17 Jul 2026 08:00:00 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Compute]]></category>
		<category><![CDATA[CSS]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[JavaScript]]></category>
		<category><![CDATA[Messaging]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/when-it-makes-sense-to-block-the-main-thread/</guid>

					<description><![CDATA[<p>The common rule of thumb is to never &#8220;block&#8221; the browser&#8217;s main thread when running JavaScript...</p>
<p>The post <a href="https://thenokiablog.com/when-it-makes-sense-to-block-the-main-thread/">When It Makes Sense To “Block” The Main Thread</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><section aria-label="Quick summary" class="article__summary"><span id="article__start" class="summary__heading" aria-hidden="true"></span>The common rule of thumb is to never &ldquo;block&rdquo; the browser&rsquo;s main thread when running JavaScript tasks. But is this a hard rule? Victor Ayomipo describes a use case he encountered involving a screenshot extension where he made an exception to the rule and decided that blocking the main thread was absolutely the right thing to do.</section>
</p>
<p>We&rsquo;ve all heard of the sacred rule in modern web development, the rule never to be broken. The rule of <em>&ldquo;Never block the main thread.&rdquo;</em></p>
<p>You almost can&rsquo;t miss it as a web developer; it&rsquo;s in almost every performance guide, and to be fair, it is good advice. We all know the browser&rsquo;s main thread is <strong>single-threaded</strong>, meaning it can only do one thing at a time.</p>
<p>Plus, as we know, the main thread isn&rsquo;t ours alone; we share it with the browser&rsquo;s rendering engine, input handlers, and other critical tasks. As a result, the less time we hold onto the main thread, the more responsive an app feels. That leads us to share tasks with background workers as we&rsquo;ve convinced ourselves there should be a hard line between the UI and any computation, and that line shouldn&rsquo;t be crossed.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>And that is what a &ldquo;recommended&rdquo; architecture looks like.</p>
<p>But I dare say that *sometimes*<em>,</em> moving the data to a worker is slower than just letting the main thread do the work.</p>
<p>I found this out a few months ago while building a Chrome extension with screenshotting features called Fastary. I kept finding a latency of about 2 to 3 seconds in all my testing, even after using an Offscreen Document (a background process in Chrome extensions) to handle the canvas operations. A screenshot task should feel instant without lag, after all.</p>
<p>It is quite ironic that by reflex, we move work away from the main thread to avoid freezing the UI, but sometimes the act of moving that work (e.g., serializing, copying, and deserializing) can also freeze the UI. And <em>sometimes</em> the recommended approach of letting the background do the work can be slower than just doing the work on the main thread.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>Let&rsquo;s talk about that.</p>
<div data-audience="non-subscriber" data-remove="true" class="feature-panel-container"><img decoding="async" loading="lazy" class="feature-panel-image-img" src="https://thenokiablog.com/wp-content/uploads/2026/07/when-it-makes-sense-to-block-the-main-thread.png" alt="Feature Panel" width="481" height="698"></div>


<h2 id="the-architecture-of-browser-context-isolation">The Architecture Of Browser Context Isolation</h2>
<p>To put things in perspective, let&rsquo;s understand why we isolate browser contexts and how they communicate with each other, with emphasis on the <em>communication</em> part.</p>
<p>A browser is more than a single environment. Different environments are running at the same time, each having its own memory space, what it can access, and rules:</p>
<ul>
<li>The <strong>main thread</strong> is what we are most familiar with; this is where JavaScript logic runs, where the DOM lives, where styles get rendered, and where users interact.</li>
<li>The <strong>Web Workers</strong> are separate threads that can also execute JavaScript without DOM access. We mostly use this for heavy data tasks.</li>
<li>The <strong>Service Workers</strong> are network-related proxies in charge of intercepting network requests and can even run when the page is closed.</li>
<li>And then there are <strong>Chrome extension contexts</strong>, where we have background service workers, content scripts, and Offscreen Documents (the relevant ones for this article).</li>
</ul>
<p>Each one of these is isolated from the others. A web worker or background script lives in a different memory space from the main thread. They cannot just reach and read each other&rsquo;s variables or logic, and this is known as the <strong>&ldquo;shared-nothing&rdquo; architecture</strong>.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>How do these isolated environments communicate? They explicitly message each other back and forth using APIs, like <code>postMessage()</code>.</p>
<h3 id="the-structured-clone-algorithm">The Structured Clone Algorithm</h3>
<p><code>postMessage()</code> tells the browser to take a piece of data and deliver it to the context that requested it. But to do this, the browser relies on the Structured Clone Algorithm (SCA).</p>
<p>You&rsquo;re probably familiar with <code>JSON.stringify()</code>. SCA is similar, but much stronger and smarter. In its simplest form, SCA is a deep, recursive copy operation, i.e., cloning. It walks through the entire data structure it is given, clones every single value, serializes it into a transportable format, ships those bytes to the target contexts, and then reconstructs the original object on the receiving side.</p>
<p>SCA is fast, or maybe fast-<em>ish</em>&hellip; For a small regular config object like <code>{theme: "dark"}</code>, it is imperceptible; you don&rsquo;t even notice it. The story changes, however, when dealing with heavy data because the SCA is a synchronous blocking <code>O(n)</code> operation, i.e., the cost increases linearly with the size of your data.</p>
<p>Let&rsquo;s put that into perspective. A user clicks a button, and internally, an 8MB image payload is sent to a background worker for processing. When you call <code>postMessage()</code>, the main thread must immediately stop what it is doing to run this serialization and copying process.</p>
<blockquote><p>So, if the time it takes to pack, ship, unpack the data, and go back to the start is longer than the time to just process the data on the main thread, why not do that instead?</p></blockquote>
<h2 id="what-about-transferable-objects">What About Transferable Objects?</h2>
<p>I&rsquo;m sure some of you are already thinking, <em>&ldquo;Why not just use Transferable objects?&rdquo;</em> And that is a valid point. Let&rsquo;s talk about that.</p>
<p>Developers who really pursue ultra-high-performance web apps usually use Transferable objects (e.g., <code>ArrayBuffer</code>, <code>ImageBitmap</code>, or <code>MessagePort</code>) to bypass the Structured Clone Algorithm. This is because when you transfer an object, you&rsquo;re not making a copy (like SCM). Instead, the browser switches ownership of the data from one context to another.</p>
<p>The browser performs a hand-off whereby the sending context loses access to the data instantly, and the receiving context takes full control. It is actually insanely fast. According to Chrome Developers&rsquo; benchmark, transferring a massive 32MB <code>ArrayBuffer</code> can take under 7ms, compared to about 300ms when cloning with SCM. That&rsquo;s a 43x speed boost.</p>
<figure><img decoding="async" loading="lazy" width="800" height="315" src="https://thenokiablog.com/wp-content/uploads/2026/07/when-it-makes-sense-to-block-the-main-thread-1.png" alt="Structured cloning vs. Transferable Objects by Chrome Developers"><figcaption class="op-vertical-bottom">Structured cloning vs. Transferable Objects by Chrome Developers. (Image source: Chrome for Developers) (Large preview)</figcaption></figure>
<p>But like all good things, there are downsides. To name a few:</p>
<ul>
<li><strong>You lose it once you send it.</strong><br>If the UI still needs that data (like to show an image preview), you can&rsquo;t access it anymore.</li>
<li><strong>Not all data is transferable.</strong><br>A plain JS object is not. A Blob is not. Even a Base64 string is not.</li>
<li><strong>API limitations.</strong><br>In the context of browser extensions, Chrome&rsquo;s internal messaging (<code>chrome.runtime.sendMessage</code>) traditionally forces everything through JSON serialization.</li>
</ul>
<p>So, as far as my screenshot extension went, Transferable objects were not an option.</p>
<h2 id="why-we-isolate-contexts-anyway">Why We Isolate Contexts Anyway</h2>
<p>Why do we even bother isolating contexts at all? Why not just leave it all to the main thread?</p>
<p>Offloading long-running CPU tasks to a background thread is absolutely the right thing to do. The browser needs to paint a new frame <strong>every 16.6ms</strong> to keep things fluid; that means any task that takes &gt;50ms is generally considered &ldquo;long&rdquo;. Offloading to the background is absolutely the right thing to do.</p>
<p>The issue, however, is that we&rsquo;ve turned this <em>&ldquo;never block the main thread&rdquo;</em> into an absolute rule, without asking <em>is this task expensive to process or expensive to move?</em></p>
<blockquote class="pull-quote">
<p>I have come to realize now that the rule is less &ldquo;never block the main thread&rdquo; than &ldquo;never block the main thread for too long.&rdquo;</p>
</blockquote>
<h2 id="when-the-right-architecture-is-the-wrong-architecture">When The Right Architecture Is The Wrong Architecture</h2>
<p>My goal with the Fastary extension was to make it feel like a native app, running as smoothly and instantly as you would expect a native app to.</p>
<p>As you already know, I took the recommended approach to use the Offscreen Document to handle DOM work in the background. But to my surprise, that took a different turn.</p>
<p>The Offscreen Document API is a clear winner. You create a hidden, undisplayed document that runs entirely in the background. It has a DOM and supports Canvas. For example, if I want to crop a screenshot, stitch multiple screenshots together, perform heavy image manipulation, or add a watermark, Offscreen Document was made for that.</p>
<p>Turns out that was not the best approach. This was my architecture:</p>
<ol>
<li>The background Service Worker captures a screenshot with <code>chrome.tabs.captureVisibleTab()</code>, which returns a Base64-encoded data URL string.</li>
<li>The background Service Worker uses <code>chrome.runtime.sendMessage()</code> to ship this image payload to the Offscreen Document.</li>
<li>The Offscreen Document receives the image, loads it into an <code>&lt;img&gt;</code> element, then draws it onto a canvas before it applies the user&rsquo;s crop coordinates, encodes the result, and sends the processed image back to the background worker.</li>
</ol>
<p>But when I tested it, the screenshot didn&rsquo;t feel instant. As I said earlier, there was a consistent 2&ndash;3 second lag.</p>
<p>I figured out that when <code>captureVisibleTab()</code> takes a screenshot, it returns a Base64 URL string, and on a standard 1080p screen, that string could be approximately 1MB or more, depending on how detailed the image is. It gets even more interesting on modern Retina displays (e.g., MacBooks) as they tend to automatically double the image&rsquo;s size by default.</p>
<p>Keep in mind that since the image payload could be doubled and extension messaging relies on JSON serialization (as of this writing), we potentially deal with <strong>massive synchronous communication</strong> that costs an entire round trip.</p>
<p>The image string data is JSON-serialized at least twice: once when going into the Offscreen Document and once coming back out with the processed results to the background worker. The actual image processing (cropping) done inside the Offscreen Document was fast, no doubt, but I can&rsquo;t say the same about the transfer overhead.</p>
<h3 id="the-retina-high-dpi-problem">The Retina High-DPI Problem</h3>
<p>As if the latency itself wasn&rsquo;t enough, I noticed a rather subtle bug &mdash; which, now that I think of it, was more of my ignorance. After a screenshot was taken, the crop result was completely off in a way that either weirdly scaled the image or resulted in incorrect coordinates.</p>
<p>It turns out that when a user selects a region to crop, the content script gets the box coordinates using <code>getBoundingClientRect()</code>, which is measured in <strong>CSS pixels</strong>; this is what the DOM uses. But when the screenshot is captured natively in Chrome, the browser doesn&rsquo;t crop it automatically; it instead uses the <strong>physical hardware pixels</strong> to get the full screen capture. And the browser uses <code>devicePixelRatio</code> (DPR) to know how many physical pixels should represent one CSS pixel. Basically, if a user on a Retinal display (DPR = 2) highlights an area of 400&times;300 CSS pixels, the actual captured image area is 800&times;600 physical pixels.</p>
<blockquote><p><strong>Note:</strong> One CSS pixel is equal to 1 physical pixel (DPR of 1) on a standard monitor. On a Mac Retina display or a modern 4K monitor, however, the DPR is usually 2 or 3.</p></blockquote>
<p>For an accurate crop, I needed to apply these two different measurement systems with the right DPR, i.e., scale the crop coordinates by the DPR. But remember, Offscreen Documents have no physical display. Processing any image would have a default DPR equal to 1. To fix this, I would have to capture the exact <code>devicePixelRatio</code> from the active tab, serialize it, pass it alongside the image payload, and manually do the scaling math inside the Offscreen Document. The complexity starts to compound.</p>
<p><em>What if I broke the golden rule and did the work on the main thread instead?</em></p>
<h2 id="working-on-the-main-thread">Working On The Main Thread</h2>
<p>Some developers will argue that UI tasks are the only things that should run on the main thread, but I don&rsquo;t fully agree with that. Personally, I believe that user explicitly-invoked actions that need immediate results can sometimes get a solid pass to run on the main thread, provided the work is incredibly <em>fast</em> (e.g., 1s).</p>
<p>That&rsquo;s what I did: scrap out the Offscreen Document and reengineer the logic. Instead of:</p>
<div class="break-out">
<pre><code class="language-markdown">Background &rarr; [serialize] &rarr; Offscreen Document &rarr; [serialize] &rarr; Background &rarr; Content Script</code></pre>
</div>
<p>&hellip;I decided to run the whole image processing in the active tab:</p>
<ol>
<li>The background Service Worker captures the screen and gets the Base64 string (same as before).</li>
<li>The background sends the payload directly to the content script in the active tab using <code>chrome.scripting.executeScript()</code>.</li>
<li>The content script (running on the main thread) receives the payload, draws it to a canvas, performs the crop using the correct DPR value, and copies the result to the clipboard.</li>
</ol>
<div class="break-out">
<pre><code class="language-javascript">// Background Script
const screenshotUrl = await chrome.tabs.captureVisibleTab(undefined, { format: "png" });

// Inject the processing function into the active tab as a content script
await chrome.scripting.executeScript({
  target: { tabId: activeTab.id },
  func: processAndCopyImage,
  args: [{ base64Image: screenshotUrl, cropData: userSelection }]
});
</code></pre>
</div>
<p>This approach completely clears out multiple context hops and round trips that JSON serialization requires. The only cross-context transfer involves sending the data URL from the background to the content script.</p>
<p>The Retina DPI issue essentially solved itself, as the content script runs directly inside the real, active browser tab because it knows the monitor&rsquo;s real <code>devicePixelRatio</code>.</p>
<p>But there&rsquo;s an elephant in the room that you may have noticed.</p>
<p>Sure, the image is now processed on the main thread, and the background manipulates the canvas in the active tab. I could technically be blocking the main thread. That&rsquo;s where I amended the &ldquo;no blocking the main thread&rdquo; rule to &ldquo;no blocking the main thread <em>for too long</em>.&rdquo; In this specific case, at least, blocking the main thread for a task the user requests for approximately one second is justifiable. It works conversely as well: maybe <strong>don&rsquo;t isolate processes if the data transfer cost is greater than the processing cost</strong>.</p>
<h2 id="conclusion-when-to-isolate-and-when-not-to">Conclusion: When To Isolate And When Not To</h2>
<p>I&rsquo;ve boiled it down to a mental model that depends on whether the task is:</p>
<h3 id="1-compute-heavy-tasks-cpu-bound">1. Compute-Heavy Tasks (CPU-Bound)</h3>
<p>These are tasks where the primary cost is computation and not the size of the data itself. These are tasks where most of the time is spent on doing calculations or heavy transformations, e.g., image compression, audio profiling, physics simulation, etc.</p>
<p>The transfer cost for these tasks is minuscule compared to the actual work.</p>
<h3 id="2-data-heavy-tasks-data-bound">2. Data-Heavy Tasks (Data-Bound)</h3>
<p>These tasks are the exact opposite. These tasks are only expensive because of the size. The processing time is almost insignificant, but the data is expensive to transport, e.g., image cropping, filtering an array, shallow copy, etc.</p>
<p>In my specific case, offloading the task to the background falls mostly into <strong>negative-sum efficiency</strong>. If we are talking about moving megabytes of data to perform a 50ms operation, there is no benefit to offloading it to the background.</p>
<p>Perhaps we can think of it like this:</p>
<pre><code class="language-markdown">Total Time = Serialization Cost
  + Transit
  + Background Processing Time
  + Deserialization Cost
</code></pre>
<p>Looking at this, if the <strong>&ldquo;background processing time&rdquo;</strong> is the most dominant task in your operation, then isolation is the clear winner. But if serialization, plus deserialization, plus transit exceeds that cost, then there&rsquo;s no need to isolate things.</p>
<p>And if you can&rsquo;t figure out if the task is CPU-heavy or data-heavy, it certainly doesn&rsquo;t hurt to measure it, for example, using performance.mark() and performance.measure() around <code>postMessage</code> calls to profile the transfer cost.</p>
<div class="signature"><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/when-it-makes-sense-to-block-the-main-thread-5.png" alt="Smashing Editorial" width="35" height="46" loading="lazy"><br>
<span>(gg, yk)</span></div>
<p>The post <a href="https://thenokiablog.com/when-it-makes-sense-to-block-the-main-thread/">When It Makes Sense To “Block” The Main Thread</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>No, People Don’t Want More AI In Their Life</title>
		<link>https://thenokiablog.com/no-people-dont-want-more-ai-in-their-life/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Wed, 15 Jul 2026 10:00:00 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/no-people-dont-want-more-ai-in-their-life/</guid>

					<description><![CDATA[<p>Many companies assume everyone craves new AI features. But the reality is that most people don&#8217;t...</p>
<p>The post <a href="https://thenokiablog.com/no-people-dont-want-more-ai-in-their-life/">No, People Don’t Want More AI In Their Life</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="c-garfield-summary">
<section aria-label="Quick summary" class="article__summary"><span id="article__start" class="summary__heading" aria-hidden="true"></span>Many companies assume everyone craves new AI features. But the reality is that most people don&rsquo;t want more AI &mdash; at least not in the way most AI leaders envision it. Brought to you by Design Patterns For AI Interfaces, <strong>friendly video courses on UX</strong> and design patterns by Vitaly.</section>
</div>
<p>Many companies silently assume that everybody wants more AI in their lives. That people are <strong>craving new AI features</strong>, new AI products, new AI workflows &mdash; that would all magically replace all existing outdated practices and broken ways of working.</p>
<p>But in reality, it seems like <strong>people don&rsquo;t want more AI</strong> at all &mdash; at least not in the way most AI leaders envision it. Unsurprisingly, many AI features have low adoption and retention &mdash; at a very high cost of delivery, and a high risk of reputation damage.</p>
<h2 id="the-ai-people-don-t-need">The AI People Don&rsquo;t Need</h2>
<p>It&rsquo;s remarkably difficult to make a strong argument with senior leadership, but AI is not a value proposition. New AI features don&rsquo;t magically make for happy or excited customers. Because AI features are often bolt-ons and separate tools for employees to use, they typically <strong>take people out</strong> of their regular way of working.</p>
<p>AI is pretty good at <strong>amplifying shortcuts and shortcomings</strong> in organizations &mdash; from data quality to decision making. It can&rsquo;t magically fix years of accumulated quick patches, technical debt, broken culture and internal politics. If anything, they become more visible with AI as inconsistencies or conflicting priorities and get handed directly to users, who are then left to make sense of the mess themselves.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>Because in most organizations, work typically requires hopping on and off between plenty of disconnected and fragmented systems, with a new AI tool, they now have yet another system that they also need to hop on and off. Often it produces more work, and typically it&rsquo;s not particularly rewarding work either.</p>
<p>On top of that, people are very much aware of the cost of finding and fixing AI hallucinations. Asking AI to generate a response <strong>might feel easier</strong> than writing from scratch, but it has a cost:</p>
<ul>
<li><strong>Skim through</strong> the entire AI output,</li>
<li><strong>Spot key points</strong> to focus attention on,</li>
<li><strong>Review/verify key points</strong>, one-by-one,</li>
<li><strong>Check rationale</strong> for what follows next,</li>
<li><strong>Articulate corrections</strong> + regenerate,</li>
<li><strong>Review the response</strong> (a number of times).</li>
</ul>
<figure><img decoding="async" loading="lazy" width="800" height="576" src="https://thenokiablog.com/wp-content/uploads/2026/07/no-people-dont-want-more-ai-in-their-life.jpg" alt="A Business Model Canvas annotated in green and red marker: &lsquo;AI goes here&rsquo; points to Key Activities and Key Resources, while &lsquo;not here&rsquo; crossed out in red points to Value Propositions."><figcaption class="op-vertical-bottom">AI goes in Key Activities and Key Resources &mdash; not in Value Propositions. Image by David Bland. (Large preview)</figcaption></figure>
<p>For many people, AI isn&rsquo;t something they can proactively choose and explore on their own &mdash; it arrives uninvited, at someone else&rsquo;s pace. On top of that, plenty of messages amplify <strong>fears and worries about AI</strong> replacing work &mdash; so it&rsquo;s hardly surprising that the perception of AI isn&rsquo;t excitement. It&rsquo;s <strong>resistance to change</strong> and deep anxiety about one&rsquo;s place in a world that seems to be changing without them.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="576" src="https://thenokiablog.com/wp-content/uploads/2026/07/no-people-dont-want-more-ai-in-their-life.png" alt="A dark-background slide listing 9 AI productivity study findings: email time up 104%, chat/messaging up 145%, business tools up 95%, working Saturdays up 46%, working Sundays up 58%, focus mode down 9%, costly mistakes up 39%, dealing with AI slop up 41%, and &lsquo;AI doesn't reduce work. It intensifies it&rsquo;."><figcaption class="op-vertical-bottom">AI Productivity Study / US: AI doesn&rsquo;t reduce work &mdash; it intensifies it. Via Mike Rosenberg, NBC News, HBR, WSJ, Activtrak. (Large preview)</figcaption></figure>
<p>At best, AI features might be silently accepted or nodded away. At worst, AI <strong>raises concerns</strong>, doubts, caution &mdash; and calls for a healthy dose of skepticism. And sometimes it&rsquo;s perceived as a threat or <strong>liability</strong> &mdash; because unlike other features, AI is neither predictable nor reliable.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>People don&rsquo;t dream of <strong>AI art museums</strong> or AI fridges or AI hotel reception or AI-narrated children&rsquo;s books. They don&rsquo;t want their children to have <strong>romantic AI partners</strong>. Most people don&rsquo;t want to actively manage (and clean up after) a <strong>swarm of AI agents</strong> roaming in their bank accounts and acting on their behalf in the real world. And most notably, people don&rsquo;t really want a magical box to speak to or type into all the time.</p>
<h2 id="the-ai-people-actually-need">The AI People Actually Need</h2>
<p>I&rsquo;m always puzzled by the comparison of AI features with how unreliable humans are. But people don&rsquo;t compare software with other people. They <strong>compare features with features</strong> &mdash; and if one feature in one product is unreliable, while a similar feature works flawlessly in another, they choose the latter. It&rsquo;s not about AI or not AI, but rather what works consistently and reliably, and what doesn&rsquo;t.</p>
<p>Many conversations about AI are conversations about the speed of delivery. But to many people, there is little value in increasing the speed of delivery. They want to do things well, with enough time to think and make good decisions. They also want to <strong>enjoy the time they spend working on things</strong>, rather than just ship faster. There is an enormous feeling of reward and achievement that slowly disappears, one vibe-coded change at a time.</p>
<p>People don&rsquo;t change much. And after all these years, they (still) want features that are fast, accessible, <strong>reliable, predictable and useful</strong> &mdash; every single time. And ideally not the ones that replace their entire workflow, but that <strong>augment</strong> their way of working &mdash; and that take over the most mundane, annoying, and boring tasks that they find no pleasure in.</p>
<figure><img decoding="async" loading="lazy" width="800" height="806" src="https://thenokiablog.com/wp-content/uploads/2026/07/no-people-dont-want-more-ai-in-their-life-1.jpg" alt="A bubble chart showing jobs least and most vulnerable to AI, with axes for exposure and adaptability. Software developers and public relations specialists are most exposed; firefighters are least exposed."><figcaption class="op-vertical-bottom">Jobs least and most vulnerable to AI. Sources: GovAI and Brookings Institution, via The Washington Post. (Large preview)</figcaption></figure>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>Many jobs are exposed to AI automation, but in many of them there is a rewarding, unique, creative part that requires taste, point of view, and perhaps even human intuition. And if AI <strong>automates boring parts</strong> of it, that&rsquo;s an advantage for everyone. That&rsquo;s also what enhances productivity and brings more joy in daily life.</p>
<p>When AI automates tedious and mentally exhausting tasks, its value is much easier to grasp. But for that, AI shouldn&rsquo;t feel like a bolt-on. It should be <strong>deeply integrated</strong> into people&rsquo;s existing workflows. It must also match existing <strong>mental models</strong> that they have developed and fine-tuned for years or decades. AI should adapt to how people think and make decisions, not the other way around.</p>
<p>And it doesn&rsquo;t really matter if these features are branded as &ldquo;AI&rdquo;, &ldquo;smart&rdquo; or &ldquo;automation&rdquo;. However, they must work well for people using them. And that means that people must be <strong>aware of use cases</strong> where it actually helps them, and be inspired to find more use cases on their own.</p>
<p>Ironically, tools that work well there aren&rsquo;t &ldquo;AI-first&rdquo; &mdash; they are <strong>&ldquo;AI-second&rdquo;</strong>. Subtle, humble, calm, ambient, taking a supportive role in the background for work that otherwise is remarkably dull and unnecessary.</p>
<blockquote><p>I don&rsquo;t want to read <strong>books written by AI</strong>. I don&rsquo;t want to gaze upon paintings by AI. I don&rsquo;t want AI to teach my children. I don&rsquo;t want to have an AI therapist. I don&rsquo;t want AI making my medical decisions. I want AI to do all the <strong>physical and mental labor</strong> that taxes me so I can read books written by humans and go to art galleries to engage with art made by humans. I want AI that makes my life easier rather than forces me to change myself.</p>
<p>&mdash; Bo Young Lee</p>
</blockquote>
<h2 id="wrapping-up">Wrapping Up</h2>
<p>Perhaps I&rsquo;m missing a bigger picture, and perhaps I&rsquo;m just old school &mdash; but <strong>I really do like people</strong>. Their stories, their thinking, their emotions, their enthusiasm, their laughing. AI can be remarkably helpful in many situations, but so are people. And between the two, I would favor <strong>spending time with a human</strong> &mdash; however imperfect they are &mdash; every single time.</p>
<p>No, <strong>people don&rsquo;t need more AI in their lives</strong> &mdash; they need AI to automate all the boring stuff they have to deal with every day, so they have more time and headspace to do things that they actually love and enjoy doing. That doesn&rsquo;t mean spending more time with AI &mdash; but spending more time with people they love.</p>
<h2 id="meet-design-patterns-for-ai-interfaces">Meet &ldquo;Design Patterns For AI Interfaces&rdquo;</h2>
<p>Meet Design Patterns For AI Interfaces, Vitaly&rsquo;s new <strong>video course</strong> with practical examples from real-life products &mdash; with a live UX training happening soon. Jump to a free preview.</p>
<figure class="article__image"><img decoding="async" loading="lazy" width="800" height="414" src="https://thenokiablog.com/wp-content/uploads/2026/07/no-people-dont-want-more-ai-in-their-life-1.png" alt="Design Patterns For AI Interfaces promo picture"><figcaption class="op-vertical-bottom">Meet Design Patterns For AI Interfaces, Vitaly&rsquo;s video course on interface design &amp; UX.</figcaption></figure>
<h2 id="useful-resources">Useful Resources</h2>
<div class="signature"><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/no-people-dont-want-more-ai-in-their-life-2.png" alt="Smashing Editorial" width="35" height="46" loading="lazy"><br>
<span>(yk)</span></div>
<p>The post <a href="https://thenokiablog.com/no-people-dont-want-more-ai-in-their-life/">No, People Don’t Want More AI In Their Life</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Amazon SQS turns 20: Two decades of reliable messaging at scale</title>
		<link>https://thenokiablog.com/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 18:13:57 +0000</pubDate>
				<category><![CDATA[Nokia Mobile Phone]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon EC2]]></category>
		<category><![CDATA[Amazon EventBridge]]></category>
		<category><![CDATA[Amazon Simple Queue Service (SQS)]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[AWS Lambda]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[Launch]]></category>
		<category><![CDATA[Messaging]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Regions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Storage]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/</guid>

					<description><![CDATA[<p>On July 13, 2006, we launched Amazon Simple Queue Service (Amazon SQS) as one of the...</p>
<p>The post <a href="https://thenokiablog.com/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/">Amazon SQS turns 20: Two decades of reliable messaging at scale</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<table id="amazon-polly-audio-table">
<tbody>
<tr>
<td id="amazon-polly-audio-tab">
<div id="amazon-polly-by-tab">
            <img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale.png" alt="Voiced by Polly" width="554" height="56">
           </div>
</td>
</tr>
</tbody>
</table>
<p>On July 13, 2006, we launched Amazon Simple Queue Service (Amazon SQS) as one of the first three services available to customers, alongside Amazon EC2 and Amazon S3. We had learned firsthand that distributed systems need a reliable way to pass messages between components without creating tight dependencies. If one service called another directly and that service was slow or unavailable, failures cascaded through the entire system. Message queuing solved this by letting services communicate asynchronously: a producer could drop a message into a queue and move on, while a consumer picked it up when ready. This approach kept individual service failures from affecting the rest of the system.</p>
<p>When Amazon SQS launched publicly in July 2006, it made this pattern available to every AWS customer. Twenty years later, that core function, decoupling producers from consumers, remains the reason customers use SQS. The scale, performance, and operational controls around it look very different now though.</p>
<p>Jeff Barr covered the first 15 years of SQS milestones in his&nbsp;15th anniversary post, from the original 8 KB message limit in 2006 through FIFO queues, server-side encryption, and Lambda integration. Over the last five years, we have continued to scale SQS, added stronger security defaults, and introduced new capabilities that address increasingly complex workload patterns.</p>
<p><span><strong>Key milestones between 2021 and 2026</strong></span><br>
        <br><strong>High throughput mode for FIFO queues (2021):</strong>&nbsp;In May 2021, we launched general availability of high throughput mode for FIFO queues, supporting up to 3,000 transactions per second (TPS) per API action, a tenfold increase over the previous limit. We continued raising this ceiling over the following two years: to 6,000 TPS in October 2022, to 9,000 TPS in August 2023, and to 18,000 TPS in October 2023, before reaching 70,000 TPS per API action in select Regions by November 2023.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/html-element-select-envato-tuts/" class="template-2"><span class="cta">Read more</span><span class="postTitle">HTML Element: select | Envato Tuts+</span></a></div><p><strong>Server-side encryption with SSE-SQS (2021):</strong>&nbsp;In November 2021, we introduced server-side encryption with Amazon SQS-managed encryption keys (SSE-SQS), giving customers an encryption option that required no key management. In October 2022, we made SSE-SQS the default for all newly created queues, so customers no longer needed to explicitly enable it.</p>
<p><strong>Dead-letter queue redrive enhancements (2021):</strong>&nbsp;We progressively expanded how customers recover unconsumed messages from dead-letter queues. In December 2021, we added DLQ redrive to source queue directly in the SQS console. In June 2023, we extended this capability to the AWS SDK and CLI through new APIs, including <code>StartMessageMoveTask</code>,&nbsp;<code>CancelMessageMoveTask</code>, and&nbsp;<code>ListMessageMoveTasks</code>. In November 2023, we added redrive support for FIFO queues.</p>
<p><strong>Attribute-based access control, ABAC (2022):</strong>&nbsp;In November 2022, we introduced ABAC, giving customers the ability to configure access permissions based on queue tags rather than maintaining static policies as resources scaled.</p>
<p><strong>JSON protocol support (2023):</strong>&nbsp;In November 2023, we added support for the JSON protocol in the AWS SDK, reducing end-to-end message processing latency by up to 23% for a 5 KB payload and lowering client-side CPU and memory usage.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/skipping-the-whm-getting-started-wizard-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Skipping the WHM Getting Started Wizard | cPanel Blog</span></a></div><p><strong>Amazon EventBridge Pipes console integration (2023):</strong>&nbsp;We added the ability to connect a queue directly to EventBridge Pipes from the SQS console, routing messages to a broad range of AWS service targets without writing custom integration code.</p>
<p><strong>Extended Client Library for Python (2024):</strong>&nbsp;We brought the Extended Client Library, previously available for Java, to Python developers, allowing messages up to 2 GB to be sent through SQS by storing the payload in Amazon S3 and passing a reference through the queue.</p>
<p><strong>FIFO in-flight message limit increase (2024):</strong>&nbsp;We increased the in-flight message limit for FIFO queues from 20,000 to 120,000 messages, so consumers can process significantly more messages concurrently without being constrained by the previous ceiling.</p>
<p><strong>Fair queues for multi-tenant workloads (2025):</strong>&nbsp;We introduced fair queues to mitigate the noisy neighbor problem in multi-tenant standard queues. By including a message group ID when sending messages, customers can prevent a single tenant from delaying message delivery for others, without any changes required on the consumer side.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/gone-phishing-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Gone Phishing | cPanel Blog</span></a></div><p><strong>1 MiB maximum message payload size (2025):</strong>&nbsp;We increased the maximum message payload from 256 KiB to 1 MiB for both standard and FIFO queues, helping customers send larger messages without offloading data to external storage. AWS Lambda event source mapping for SQS was updated in parallel to support the new payload size.</p>
<p><span><strong>The constant underneath the change</strong></span><br>
        <br>Despite two decades of feature additions, the fundamental use case for SQS has not shifted. Customers use it to decouple services, buffer bursts of traffic, and build systems that stay resilient when individual components fail. That same pattern now extends to AI workloads. Customers use SQS queues to buffer requests to large language models, manage inference throughput, and coordinate communication between autonomous AI agents operating as independent services. For an example of this architecture in practice, read Creating asynchronous AI agents with Amazon Bedrock.</p>
<p>To learn more about Amazon SQS, visit the&nbsp;Amazon SQS product page, review the&nbsp;developer guide, or explore recent updates on the AWS Blogs.</p>
<p>       &mdash; Esra <!-- '"` --></p>
<p>The post <a href="https://thenokiablog.com/amazon-sqs-turns-20-two-decades-of-reliable-messaging-at-scale/">Amazon SQS turns 20: Two decades of reliable messaging at scale</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)</title>
		<link>https://thenokiablog.com/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Mon, 13 Jul 2026 16:18:20 +0000</pubDate>
				<category><![CDATA[Nokia Mobile Phone]]></category>
		<category><![CDATA[Amazon Aurora]]></category>
		<category><![CDATA[Amazon Bedrock]]></category>
		<category><![CDATA[Amazon Bedrock AgentCore]]></category>
		<category><![CDATA[Amazon CloudWatch]]></category>
		<category><![CDATA[Amazon Elastic Container Service]]></category>
		<category><![CDATA[Amazon Elastic Kubernetes Service]]></category>
		<category><![CDATA[Amazon Kinesis]]></category>
		<category><![CDATA[Amazon SageMaker]]></category>
		<category><![CDATA[Amazon SageMaker Studio]]></category>
		<category><![CDATA[Announcements]]></category>
		<category><![CDATA[AWS IAM Identity Center]]></category>
		<category><![CDATA[AWS Security Hub]]></category>
		<category><![CDATA[AWS Trainium]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Database]]></category>
		<category><![CDATA[Developer]]></category>
		<category><![CDATA[DSQL]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Kiro]]></category>
		<category><![CDATA[Launch]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Regions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Serverless]]></category>
		<category><![CDATA[Storage]]></category>
		<category><![CDATA[Strands Agents]]></category>
		<category><![CDATA[Week in Review]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/</guid>

					<description><![CDATA[<p>AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform...</p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/">AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<table id="amazon-polly-audio-table">
<tbody>
<tr>
<td id="amazon-polly-audio-tab">
<div id="amazon-polly-by-tab">
            <img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026.png" alt="Voiced by Polly" width="554" height="56">
           </div>
</td>
</tr>
</tbody>
</table>
<p>AWS Builder Center turned one year old last week. Launched on July 9, 2025, the platform has grown from a community hub with Wishlist voting, community profiles, and a toolbox into a full ecosystem with sandbox environments, workshops, Spaces, and a Builders&rsquo; Library. To mark the anniversary, Rick Suttles published a full feature timeline covering everything shipped over the past year: AWS Capabilities by Region (1,500+ services across 37 Regions), Spaces for community-created groups, workshops with category and complexity filters, badges and streaks, article series, view counts, saved items, student status, availability notifications, sign-in with GitHub and Amazon, and sandbox environments.</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-105048" src="https://thenokiablog.com/wp-content/uploads/2026/07/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026-1.png" alt width="1200" height="655"></p>
<p>Jeff Barr published a retrospective summarizing Builder Center&rsquo;s first year. Since launch, 5,548 authors have published 6,448 articles with more than 10.4 million page views combined. Builders have earned 99,226 badges since the badge system launched in March 2026. Community members have submitted 565 wishes, 10 of which have shipped with another 20 on the near-term roadmap.</p>
<p>The top community article Building an AWS Study Buddy with MCP + Strands Agents SDK by Dineshraj Dhanapathy reached 50,000+ views. Chris Miller&rsquo;s Migrating an EOL Linux Server to AWS in 8 Hours with Kiro followed at 45,000+, and Yash Aggarwal&rsquo;s AIdeas: NeuroVoice &ndash; Multimodal AI for Early Screening of Neurological Diseases article reached 38,000+.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/html-element-select-envato-tuts/" class="template-2"><span class="cta">Read more</span><span class="postTitle">HTML Element: select | Envato Tuts+</span></a></div><p>The week&rsquo;s headline addition is Sandbox Environments by Rick Suttles. Sandboxes give you a free, pre-provisioned AWS account to complete a workshop exercise. Each environment is active for 8 hours, after which the account and all its resources are automatically de-provisioned. You can have one active sandbox at a time and request one per week. No personal AWS account, credit card, or manual cleanup required.</p>
<p><span><strong>Last week&rsquo;s launches<br>
          <br></strong></span>Here&rsquo;s what else happened this week.</p>
<ul>
<li>AWS Security Hub introduces Network Scanning &ndash; Security Hub introduced Network Scanning, a capability that identifies resources in your environment that are reachable from the public internet. Network Scanning probes your resources from the internet to detect actual reachability, complementing the existing network reachability findings in Security Hub that identify configurations that could make a resource reachable. It discovers public IP addresses, virtual machines, and load balancers across your AWS and Azure environments, identifies reachable ports, and determines what services are running behind them. Each reachable port generates a Security Hub finding with evidence of the port and service discovered. Security Hub Exposures then automatically correlates these findings with other findings and resource configurations to determine broader risk. Existing customers can enable Network Scanning in individual accounts and Regions, or across an organization through a configuration policy. For new customers, Network Scanning is on by default. It is included with Security Hub Essentials at no additional cost.</li>
<li>Security Hub also extends unified security management to Microsoft Azure &ndash; Security Hub now monitors Microsoft Azure resources, providing unified posture management, vulnerability management, and security response across both clouds. It automatically discovers Azure VMs, container images, Function Apps, and identities, and evaluates them for misconfigurations, internet exposure, and software vulnerabilities. AWS and Azure findings appear in the same prioritized view with the same formats and automation workflows.</li>
<li>Amazon SageMaker Studio integrates with Hugging Face for one-click model deployment and customization &ndash; You can now go from discovering a model on Hugging Face to working with it in SageMaker Studio in a single click. Select any supported model on Hugging Face and choose &ldquo;Customize on SageMaker AI&rdquo; or &ldquo;Deploy on SageMaker AI&rdquo; to land directly on the corresponding workflow page with the model pre-loaded. New customers receive a Studio environment created in seconds with pre-configured permissions for serverless model customization (including fine-tuning with custom reward functions for reinforcement learning), model evaluation, and deployment to SageMaker or Bedrock endpoints. Verified customers receive default GPU access to G5, G6, and G4dn instances without requesting quota increases, and quota utilization is visible directly inside the Studio environment.</li>
<li>Amazon EKS Auto Mode and Amazon ECS Managed Instances reduce GPU management fees by up to 60% &ndash; Beginning July 1, 2026, EKS Auto Mode and ECS Managed Instances reduce management fees for accelerated instance types: G-series fees are down 35%, and P-series and AWS Trainium fees are down 60%. The reductions apply automatically to existing clusters and require no action from customers. Both services include capabilities built for accelerated workloads. EKS Auto Mode provides automatic parallel image pulling on GPU instances with local NVMe storage and accelerator-aware node repair. ECS Managed Instances provides GPU metrics through Amazon CloudWatch Container Insights and automatic health monitoring for GPU hardware failures.</li>
<li>Amazon Aurora DSQL change data capture (CDC) is now generally available &ndash; Aurora DSQL CDC streams the results of insert, update, and delete operations as change events to Amazon Kinesis Data Streams. You can use it to synchronize data across microservices, trigger Lambda functions, or deliver changes to S3, Redshift, and OpenSearch Service through Amazon Data Firehose. CDC streaming is designed to have zero impact on database workload performance and requires no infrastructure to manage.</li>
</ul>
<p>For a full list of AWS announcements, be sure to keep an eye on the What&rsquo;s New with AWS page.</p>
<p><span><strong>Other AWS news<br>
          <br></strong></span>Here are some additional posts you may find useful:</p>
<ul>
<li>Building secure AI agents at scale: Introducing Loom for AWS &ndash; Loom is an open-source enterprise platform for building agents with AWS Strands Agents and deploying them on Amazon Bedrock AgentCore Runtime. It provides a unified management UI and backend API with identity provider integration, scope-based authorization, multi-persona navigation, and full lifecycle management for agents, memory, MCP servers, and agent-to-agent integrations. Loom enforces automated resource tagging for cost attribution, implements RBAC and ABAC for multi-tenant security, uses paved-path blueprints for agent deployments, manages identity propagation through delegated actor chains, integrates with AWS Agent Registry for discovery and governance, and supports human-in-the-loop review before sensitive actions. The project is available in AWS Labs on GitHub.</li>
<li>Introducing Claude apps gateway for AWS &ndash; The Claude apps gateway is a self-hosted control plane that gives organizations centralized control over access, cost, and policy for Claude Code and Claude Desktop. It connects to any OIDC-compliant identity provider, enforces managed settings on every request, routes inference to Amazon Bedrock or Claude Platform on AWS, and supports per-user and per-group spend caps. The gateway runs as a stateless container in your private network, backed by a PostgreSQL database for short-lived sign-in state. No long-lived secrets are stored on developer machines. Deploy it through Amazon Bedrock to keep data within the AWS security boundary, or through Claude Platform on AWS for the native Claude platform experience.</li>
<li>Introducing OAuth support for AWS MCP Server &ndash; You can now connect agents to the AWS MCP Server using browser-based OAuth with the same credentials you use for the AWS Console or CLI. The new sign-in path supports IAM federation, AWS IAM Identity Center, and root or IAM users. AWS Sign-In issues short-lived access tokens and refresh tokens, with automatic token management so developers stay authenticated across restarts. For headless use cases, a non-interactive flow lets applications with existing AWS credentials obtain OAuth access tokens through the <code>create-oauth2-token-with-iam</code> API. New governance controls include OAuth-specific IAM condition keys, token introspection and revocation, dynamic client registration, and CloudTrail audit elements.</li>
</ul>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/skipping-the-whm-getting-started-wizard-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Skipping the WHM Getting Started Wizard | cPanel Blog</span></a></div><p>For a full list of AWS blog posts, be sure to keep an eye on the AWS Blogs page.</p>
<p><span><strong>Upcoming AWS events</strong></span><br>
        <br>Check your calendar and sign up for upcoming AWS events:</p>
<ul>
<li>AWS Summits &ndash; Free in-person events for builders and innovators to learn, think big, and make new connections. Coming up: Taipei (July 15), Bogot&aacute; (July 30), Jakarta (August 6), Ciudad de M&eacute;xico (August 12), Johannesburg (August 19), and Zurich (September 2).</li>
<li>AWS Community Days &ndash; Community-led conferences planned and delivered by community leaders. Upcoming events include Yaound&eacute;, Cameroon (July 25), Ahmedabad, India&nbsp;(July 25), Belo Horizonte, Brazil (August 22), Ottawa, Canada (August 22), Tulsa, USA (August 22), and Toronto, Canada (August 29).</li>
</ul>
<p>Visit the AWS Builder Center to meet other builders, contribute solutions, and find resources that help you keep building.</p>
<p>Wishing everyone a restful and enjoyable summer. Whether you&rsquo;re building, learning, or recharging, I hope you find time for all three. I&rsquo;ll be heading to Scandinavia for a few weeks to trade the heat for some cooler weather and longer evenings. Come back next week for more news!</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/gone-phishing-cpanel-blog/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Gone Phishing | cPanel Blog</span></a></div><p>       &mdash; Esra <!-- '"` --></p>
<p>The post <a href="https://thenokiablog.com/aws-weekly-roundup-aws-builder-center-at-1-year-network-scanning-in-security-hub-loom-for-aws-and-more-july-13-2026/">AWS Weekly Roundup: AWS Builder Center at 1 year, Network Scanning in Security Hub, Loom for AWS, and more (July 13, 2026)</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>AI in the WordPress Dashboard: Which Tasks Are Worth It?</title>
		<link>https://thenokiablog.com/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Sat, 11 Jul 2026 12:30:27 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[Dashboard]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[WordPress AI]]></category>
		<category><![CDATA[WordPress Developer]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it/</guid>

					<description><![CDATA[<p>AI-based features have been available in WordPress for quite some time. Several third-party plugins facilitate connections...</p>
<p>The post <a href="https://thenokiablog.com/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it/">AI in the WordPress Dashboard: Which Tasks Are Worth It?</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>AI-based features have been available in WordPress for quite some time. Several third-party plugins facilitate connections to various AI models. However, WordPress 7.0&rsquo;s Connectors API is the first official solution baked into the core software.</p>
<p>Much of the excitement around this development surrounds AI&rsquo;s potential to transform WordPress. It opens the door to easier site management and (hopefully) a better onboarding experience for new users. We&rsquo;re only beginning to see what this technology can do when combined with the content management system (CMS).</p>
<p>Now that AI integration is available to the masses, the question is: <strong>What tasks is AI best-suited for?</strong></p>
<p>You can theoretically use it for everything from changing a post title to generating new plugins on the fly. That&rsquo;s great, but there are a few considerations.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>The first is practicality. We likely don&rsquo;t need AI to check a box on a settings page for us. Seriously, you could do it yourself in the time it takes to write a prompt. But there are also complex tasks that would be too dangerous or inefficient to perform on a production website.</p>
<p>Then there is the cost of using AI tokens. Connecting your website to for-profit models like Anthropic or OpenAI means paying for every prompt or automation. Thus, using AI for <em>everything</em> isn&rsquo;t for the budget-conscious among us.</p>
<p>Developers and website owners must decide how to get the most value from AI. Here are a few questions to ask yourself or your client before taking the plunge.</p>
<h2><span id="Can_AI_Do_It_Better_or_More_Efficiently">Can AI Do It Better or More Efficiently?</span></h2>
<p>The overlap of what humans and AI can do inside WordPress depends on your experience. A professional who has used the software for years will have more capabilities than a beginner. The longer you use WordPress, the more likely you&rsquo;ll understand its features and quirks.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>So, the trick is to identify what AI can do <em>better</em> or <em>more efficiently</em> than you. Relatively small tasks like inserting an image or formatting text are probably best left to humans. There isn&rsquo;t much time to be saved unless you&rsquo;re struggling with the basics.</p>
<p>Advanced jobs, such as creating page layouts in the Block Editor, are where things get murky. Here&rsquo;s where experience really matters. A web designer may have no problem building layouts, while a novice may become stuck. Therefore, the decision comes down to your comfort level.</p>
<p>On the other hand, AI&rsquo;s potential to perform tasks at scale is where it shines. For example, maybe you want to find every image on your site without an ALT attribute and implement descriptive text. That could take hours for a human. Meanwhile, you can use AI to search for and identify such images. From there, you can manually write the text or ask for help.</p>
<p>It&rsquo;s also worth noting that using AI isn&rsquo;t a replacement for learning. In fact, you can use it to guide you through various tools and processes. You may find that you no longer need AI to do something after it shows you how. That&rsquo;s a powerful and perhaps underrated use case.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it.webp" alt="AI can save you signficant time on certain tasks." width="900" height="600"></p>
<h2><span id="How_Often_Will_I_Need_the_Task">How Often Will I Need the Task?</span></h2>
<p>The frequency of a given task is also a consideration. A one-off task, such as a deep code analysis, could be a wise use of AI. Spending a few tokens may be well worth the time saved when compared to other methods.</p>
<p>Automation is another great example, as it&rsquo;s available any time you need it. You can run a task in the middle of the night or first thing in the morning &ndash; it doesn&rsquo;t care or complain. AI models can schedule and perform such jobs. There is also the potential for it to recognize changing needs and adjust accordingly.</p>
<p>Perhaps the best measure of value is how much time a task takes a human. Consider creating custom data reports, for example. It can be extremely complicated, depending on the data you need. You can use plain language to describe what you need, and AI will do the rest.</p>
<p>This approach also works at scale. Agencies and freelancers managing dozens or even hundreds of websites can use AI as an extra set of eyes. Even something like troubleshooting a buggy plugin could be performed in the background while you tend to other things.</p>
<p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it-1.webp" alt="You can use AI to automate common tasks." width="900" height="600"></p>
<h2><span id="Is_There_a_Suitable_Non-AI_Solution">Is There a Suitable Non-AI Solution?</span></h2>
<p>Here&rsquo;s the elephant in the room: we don&rsquo;t need AI to do most things inside of WordPress. As such, the technology may be overkill for some tasks.</p>
<p>There are plugins for virtually every need. They can manage automations, data exports, and everything else under the sun. This is how we got by for the 20-odd years before AI came along.</p>
<p>A non-AI plugin is still a viable option. You&rsquo;re likely to get the functionality you need, along with cost certainty. There is also a human ready to support you if you run into problems.</p>
<p>However, plugins can&rsquo;t cover every niche, and they aren&rsquo;t always easy to use. Some require coding skills to get the most out of them. Using AI makes perfect sense in these scenarios.</p>
<p>The benefits of AI include speed and a seamless experience. But in many cases, a plugin will suffice. It&rsquo;s a matter of looking at your needs and determining the best fit.</p>
<p><img loading="lazy" decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it-2.webp" alt="Existing plugins can often be the best option for a task." width="900" height="600"></p>
<h2><span id="AI_in_WordPress_Is_Helpful_but_Not_Always_Necessary">AI in WordPress Is Helpful, but Not Always Necessary</span></h2>
<p>The most interesting part of WordPress AI integration may be in how people decide to use it. The CMS powers all types of websites, from small bespoke blogs to corporate multisite installations. There is a nearly endless supply of use cases.</p>
<p>And using AI in the dashboard could benefit users of all skill levels. The challenge is in finding the tasks that make the most sense for you. It&rsquo;s a more personal decision than you might think.</p>
<p>Our advice? Experiment with this new tool and think of ways it can help you get more done. Keep track of token usage and determine what&rsquo;s most valuable to your workflow.</p>
<p>You might find that you&rsquo;re more productive than ever, or that you can safely hold off on using AI for all the things. It&rsquo;s your choice!</p>
<div class="topics">
<h2>Related Topics</h2>
</div>
<p>                here. He recently started a writing service for WordPress products: WP Product Writeup.  He also has an opinion on just about every subject. You can follow his rants on Bluesky @karks.com.</p>
<p>
                        Read more articles by Eric Karkovack
                    </p>

<hr>
<p>The post <a href="https://thenokiablog.com/ai-in-the-wordpress-dashboard-which-tasks-are-worth-it/">AI in the WordPress Dashboard: Which Tasks Are Worth It?</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>From Kickoff To First Concept: How To Turn Brand Strategy Into Visual Direction</title>
		<link>https://thenokiablog.com/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction/</link>
		
		<dc:creator><![CDATA[Mister Nokia]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 13:00:00 +0000</pubDate>
				<category><![CDATA[Design]]></category>
		<category><![CDATA[Branding]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Color]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[Figma]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[Photography]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Startup]]></category>
		<guid isPermaLink="false">https://thenokiablog.com/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction/</guid>

					<description><![CDATA[<p>The strongest visual concepts don&#8217;t start in Figma. They start with the right questions. Explore the...</p>
<p>The post <a href="https://thenokiablog.com/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction/">From Kickoff To First Concept: How To Turn Brand Strategy Into Visual Direction</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><section aria-label="Quick summary" class="article__summary"><span id="article__start" class="summary__heading" aria-hidden="true"></span>The strongest visual concepts don&rsquo;t start in Figma. They start with the right questions. Explore the pre-concept phase of brand identity design, where teams research brand context, uncover hidden assumptions with stakeholders, and turn shared direction into a visual foundation before a single concept is created.</section>
</p>
<p>When a branding project fails, it usually happens long before the logo stage: in the strategy phase, when words like &ldquo;modern,&rdquo; &ldquo;trustworthy,&rdquo; &ldquo;premium,&rdquo; &ldquo;friendly,&rdquo; and &ldquo;disruptive&rdquo; are left undefined. The result is a gap between what the brand is supposed to communicate and what the designer is expected to create. This is the space I like to call the <strong>&ldquo;pre-concept&rdquo; phase</strong>.</p>
<p>At the beginning of a project, designers usually receive many inputs: a brief, a few stakeholder conversations, competitor references, maybe a moodboard or a list of adjectives. From there, they are expected to create visual concepts that feel right. But &ldquo;right&rdquo; is difficult to judge when the team has not agreed on what the brand is supposed to communicate in the first place.</p>
<p>As an example, a health tech company we worked with said they wanted to look modern, trustworthy, and disruptive. At first, &ldquo;disruptive&rdquo; sounded like a push toward something bold and unconventional. But as we talked, it became clear that disruption, for them, still had to feel credible inside a conservative healthcare environment. Their clients were large government medical institutions. A brand that felt too rebellious, experimental, or visually loud would not create the right kind of trust.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/rose-gold-design/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Rose gold design</span></a></div><p>In other words, their version of &ldquo;disruptive&rdquo; looked more traditional than the word suggested.</p>
<p>The problem was not that the client used the wrong language. The problem was that the language was too broad to guide design decisions. Before a designer can turn strategy into a visual concept, those words need to become more specific. What kind of modern? Trustworthy in what way? Disruptive compared to whom? And how far can the brand move away from category expectations before it starts to feel wrong for its audience?</p>
<p>This article is about that pre-concept phase: the work that happens after the kickoff but before the first visual direction. While the broader brand identity process for digital products includes strategy, concepts, implementation, and the assets a product team needs to build consistently, this article focuses on the earlier work that makes the first concept possible: researching the brand context, uncovering hidden assumptions with stakeholders, and <strong>turning shared direction into a visual foundation</strong>. Rather, a practical bridge between what the brand needs to mean and how it might begin to look.</p>
<p>The first place to build that bridge is the brand workshop, where broad discovery needs to become a clearer understanding of the brand context.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="450" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction.png" alt="pre-concept phase: Look and feel (general concept), design code (ideas), brand identity (graphics level)"><figcaption class="op-vertical-bottom">A pre-concept reference board showing how brand character can move from overall look and feel to design code and early brand identity cues. The board uses publicly available visual references to discuss mood, principles, and possible graphic directions before original concept work begins. (Large preview)</figcaption></figure>
<div data-audience="non-subscriber" data-remove="true" class="feature-panel-container"><img decoding="async" loading="lazy" class="feature-panel-image-img" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-1.png" alt="Feature Panel" width="481" height="698"></div>


<h2 id="stage-1-research-the-brand-context">Stage 1: Research The Brand Context</h2>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/passion-work/" class="template-2"><span class="cta">Read more</span><span class="postTitle">Passion &amp; work</span></a></div><p>A brand workshop will naturally cover the standard discovery topics: the business, its goals, the product or service, the competitive landscape, and the target audience. This article will not try to list every question a designer should ask in that workshop. For readers who want a broader starting point, we prepared a Brand Workshop Toolkit: Questions and Exercises, a FigJam framework we use in our studio to structure discovery conversations.</p>
<p>Here, I want to focus on a smaller set of questions that are easy to skip but extremely useful before visual work begins. These questions are less about collecting facts and more about clarifying perception. They help the team understand what the brand needs to make people believe, where it needs to feel credible, and which category assumptions it should follow or challenge.</p>
<p><strong>Perception</strong> sits at the center of brand discovery because the brand is shaped in someone else&rsquo;s mind.</p>
<blockquote><p>&ldquo;A brand is a person&rsquo;s gut feeling about a product, service, or company.&rdquo;</p>
<p>&mdash; Marty Neumeier, The Brand Gap</p>
</blockquote>
<p>If the brand ultimately lives in someone else&rsquo;s perception, the workshop has to clarify what perception the team is trying to create.</p>
<div class="internal-linking-related-contents"><a href="https://thenokiablog.com/the-joy-of-art/" class="template-2"><span class="cta">Read more</span><span class="postTitle">The joy of art</span></a></div><p>The perception questions I focus on are:</p>
<ul>
<li>What should people believe about the company after seeing the brand for the first time?</li>
<li>What would make the brand feel credible in this category?</li>
<li>If the brand were a person in the room, how would they speak?</li>
<li>What do customers currently misunderstand about the company, product, or category?</li>
<li>Where does the brand need to fit the category, and where does it need to break from it?</li>
</ul>
<p>These questions help reveal the assumptions behind people&rsquo;s opinions, instead of simply adding more opinions to the room. The <strong>questions matter</strong> because brand attributes often sound aligned before they are actually understood. A stakeholder may say the brand should feel &ldquo;premium,&rdquo; and everyone may nod. But one person may mean refined and editorial. Another may mean expensive and exclusive. Another may mean clean, quiet, and minimal. The word sounds shared, but it can lead to three completely different visual systems.</p>
<p>For instance, in the health tech project mentioned earlier, the client described the desired brand as &ldquo;disruptive.&rdquo; In many categories, that might suggest something bold, loud, or unconventional. But their audience was large government medical institutions, so disruption had to be expressed through clarity, efficiency, and confidence rather than rebellion. If we had taken the word at face value, the visual direction could easily have moved too far from what their audience would trust.</p>
<p>In another project, a fintech team wanted the brand to feel &ldquo;bold&rdquo; without losing credibility. That word created useful tension. The word bold could mean bright colors, oversized typography, and a highly expressive system. But in a financial category, it also had to carry signals of security, control, and competence. The question was not whether the brand should be bold, but what kind of boldness would still feel trustworthy.</p>
<p>When the team can define what these attributes mean in <strong>context</strong>, the designer is no longer working from broad adjectives. They are working from a clearer design problem.</p>
<h2 id="stage-2-reveal-hidden-assumptions-with-stakeholders">Stage 2: Reveal Hidden Assumptions With Stakeholders</h2>
<p>Strategically selected questions can uncover part of the verbal layer, but words alone are rarely enough. To move from language into visual direction, it helps to incorporate exercises that make stakeholders think through images, associations, and relative perception.</p>
<p>Jake Knapp makes a similar point in GV&rsquo;s Three-Hour Brand Sprint:</p>
<blockquote><p>&ldquo;The point of these exercises is to make the abstract idea of &ldquo;our brand&rdquo; into something concrete.&rdquo;</p>
<p>&mdash; Jake Knapp</p>
</blockquote>
<p>The following two exercises help translate what stakeholders say about the brand into material that can later inform look and feel, design principles, and concept development.</p>
<p>This is also where stakeholder participation becomes important. When clients only receive a strategy presentation, they can stay passive. They may agree in the meeting without noticing the assumptions they are bringing into the process. But when they have to place a competitor on a map, choose an image, or explain why a certain reference feels credible, they become active participants. Their attitudes, beliefs, and disagreements become visible before they have a chance to derail the first concept review.</p>
<p>I usually start by looking outward at the <strong>category</strong>, then inward at the brand itself.</p>
<h3 id="exercise-1-competitor-perception-mapping">Exercise 1: Competitor Perception Mapping</h3>
<p>Before the workshop, collect screenshots of competitor brands, websites, product interfaces, social visuals, or other visible brand touchpoints. During the workshop, ask the client team to place those competitors on a simple two-axis map.</p>
<p>This exercise is not about deciding which competitors have &ldquo;good&rdquo; or &ldquo;bad&rdquo; design. It is about understanding <strong>how the client reads the category</strong>: what feels credible, what feels generic, what feels too conservative, what feels too experimental, and where there may be an open visual territory for the brand.</p>
<p>The axes should be chosen based on the tension the brand needs to solve. For example:</p>
<ul>
<li>Traditional to progressive.</li>
<li>Corporate to human.</li>
<li>Understated to bold.</li>
<li>Accessible to exclusive.</li>
</ul>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="806" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-2.png" alt="A completed competitor perception map"><figcaption class="op-vertical-bottom">A completed competitor perception map showing how stakeholders positioned category references across two axes: understated to bold and accessible to exclusive. The references are used to discuss perception, not to define final design choices. (Large preview)</figcaption></figure>
<p>For a health tech company that wants to feel innovative but works with conservative medical institutions, the map might use <strong>traditional to progressive</strong> and <strong>corporate to human</strong>. For a fintech brand that wants to stand out without losing trust, it might use <strong>understated to bold</strong> and <strong>accessible to exclusive</strong>.</p>
<p>The most useful part of this exercise is often not the final map, but the disagreement it creates. One stakeholder may read a competitor as progressive, while another sees it as generic. One may see a brand as premium, while another reads it as cold. These disagreements reveal how different people define trust, innovation, credibility, and differentiation. That is exactly the kind of ambiguity that needs to be resolved before design begins.</p>
<h3 id="exercise-2-visual-brand-driver">Exercise 2: Visual Brand Driver</h3>
<p>After the team has discussed the category, I like to turn the conversation inward. One exercise we use for this is called <strong>Visual Brand Driver</strong>. Each stakeholder is asked to choose images for a set of unrelated categories: transport, typeface, activity, furniture, mood, object, animal, architecture, and drink.</p>
<p>The instruction is important: the images should not represent the person&rsquo;s personal taste. They should represent the company.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="387" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-3.png" alt="A completed Visual Brand Driver exercise"><figcaption class="op-vertical-bottom">A completed Visual Brand Driver exercise, where stakeholders use images and adjectives to describe how they perceive the company. (Large preview)</figcaption></figure>
<p>For example, if the company were a type of transport, what would it be? A quiet electric car, a high-speed train, a private jet, a bicycle, a delivery van? If it were a piece of furniture, would it be a soft lounge chair, a precise modular desk, or a heavy boardroom table?</p>
<p>After choosing the images, each person adds four or five adjectives to explain why they selected them. This part matters more than the image itself. The same object can mean different things to different people. A train might suggest speed, structure, reliability, mass accessibility, or a fixed route. A lounge chair might suggest comfort, calm, informality, or lack of urgency.</p>
<p>The exercise helps create a deeper layer of brand perception. Instead of asking people to describe the company directly, it asks them to think through <strong>metaphor</strong> and <strong>association</strong>. Patterns and contradictions become visible. One stakeholder may see the brand as refined and calm, another as energetic and experimental. One may describe the company as precise and structured, another as warm and flexible.</p>
<p>Those differences are not a problem. They are useful materials. They show what needs to be clarified before the visual concept phase begins.</p>
<p>This exercise is also helpful because it separates brand perception from aesthetic preference. A stakeholder may personally like a certain image, but if it does not describe the company, it should not be part of the exercise. That distinction is important throughout the branding process. The question is not <em>&ldquo;Do we like this?&rdquo;</em> but <em>&ldquo;Does this express the right thing about the brand?&rdquo;</em></p>
<h2 id="stage-3-turn-shared-direction-into-a-visual-foundation">Stage 3: Turn Shared Direction Into A Visual Foundation</h2>
<p>Once the workshop has revealed the main assumptions, the next client meeting can turn that shared understanding into a visual foundation. This is still not the first identity concept. It is a working layer between strategy and design, where the client can react to perception, visual principles, and early asset directions before the designer invests time in full concepts.</p>
<p>We usually structure this meeting around three connected layers:</p>
<ol>
<li><strong>Look and feel</strong><br>What should the brand feel like?</li>
<li><strong>Design code</strong><br>How can key brand ideas become visual principles?</li>
<li><strong>Branding assets</strong><br>What early choices should guide typography, color, logo direction, imagery, and illustration?</li>
</ol>
<p>Together, these layers move the conversation from perception to practical design boundaries.</p>
<h3 id="look-and-feel">Look And Feel</h3>
<p><em>Look and feel</em> boards are not collections of visuals the team likes. They are <strong>perception boards</strong>. The designer collects references based on the workshop: desired perception, category tension, competitor codes, stakeholder disagreements, and brand character.</p>
<p>If the brand needs to feel trustworthy, modern, and human, the board should help the team discuss what kind of trust, modernity, and humanity are appropriate. Is the brand calm and institutional, or warm and accessible? Is it progressive through precision, or through a more expressive editorial tone?</p>
<p>The point is to let the client respond to perception before reacting to a logo, color palette, or finished visual system.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="450" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-4.png" alt="Look And Feel Board"><figcaption class="op-vertical-bottom">Look And Feel Board For A Prop Tech PR Agency. The board includes third-party visual references gathered for inspiration and discussion during the design process. (Large preview)</figcaption></figure>
<h3 id="design-code">Design Code</h3>
<p><em>Design code</em> makes the direction more specific by translating key brand ideas into visual principles.</p>
<p>For a parenting app in Germany, <strong>personalized support for your unique journey</strong> might become organic shapes, handwritten lines, and softer compositions. <strong>Parenting is messy and magical</strong> might become soft gradients, layered imagery, and playful irregularity. <strong>Research-backed support for real life</strong> might introduce doctor calls, data snapshots, infographics, and editorial layouts that make the brand feel credible.</p>
<p>For a PR agency working with prop tech companies, <strong>momentum in motion</strong> might become lines, arrows, ripple effects, or motion blur. <strong>Springboard</strong> might become a lift-off moment and elastic visual energy. <strong>Building blocks</strong> might become modular shapes or stacked compositions.</p>
<p>The team is not choosing the final graphic expression here. It is testing whether the visual metaphors make sense before concept design begins.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="450" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-5.png" alt="Design Code, which includes Personalized support for your unique journey (Organic shapes, handwritten lines), Parenting is messy and magical (Organic chaos, soft gradients), Research-backed support for real life (Conference photos, calls with doctors, infographics)"><figcaption class="op-vertical-bottom">Design Code For A Parenting App. The board includes third-party visual references gathered for inspiration and discussion during the design process. (Large preview)</figcaption></figure>
<h3 id="brand-assets">Brand Assets</h3>
<p>The final layer brings the conversation down to the building blocks of identity: typography, color, logo style, photography, illustration, and graphic language.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="450" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-6.png" alt="Brand Asset Direction (logo / color / typography / photo style)"><figcaption class="op-vertical-bottom">Early Brand Asset Direction for an Infrastructure AI Startup. The board includes third-party visual references gathered for inspiration and discussion during the design process. (Large preview)</figcaption></figure>
<p>At this stage, the team can discuss questions such as:</p>
<ul>
<li>Should the typography feel editorial, technical, warm, precise, expressive, or restrained?</li>
<li>Should the color palette follow category codes or create contrast?</li>
<li>Should the logo be a quiet typographic mark, a flexible symbol, or a more expressive character?</li>
<li>Should photography feel documentary, polished, intimate, product-led, everyday, or aspirational?</li>
<li>Should illustration explain complex ideas, add warmth, or become a distinctive brand language?</li>
</ul>
<p>This gives the designer <strong>boundaries</strong> without making the final identity predictable. The next step is still concept design, but the team is no longer starting from vague adjectives or private expectations.</p>
<figure class="break-out article__image"><img decoding="async" loading="lazy" width="800" height="450" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-7.png" alt="Brand Asset Direction (logo / color / typography / photo style)"><figcaption class="op-vertical-bottom">Early Brand Asset Direction For A Parenting App. The board includes third-party visual references gathered for inspiration and discussion during the design process. (Large preview)</figcaption></figure>
<h2 id="pre-concept-checklist">Pre-Concept Checklist</h2>
<p>Before moving into the first concept, it helps to pause and check whether the team has enough <strong>shared direction</strong>. The checklist is not meant to make every decision in advance. It is meant to make sure the designer is not starting from vague words, hidden assumptions, or unresolved disagreements.</p>
<p>Before creating the first concept, check whether the team has:</p>
<ul>
<li>A clear understanding of what the brand needs to communicate.</li>
<li>A defined brand character.</li>
<li>A shared sense of what that character means and what it does not mean.</li>
<li>Visual references tied to perception, not taste.</li>
<li>Key brand ideas translated into visual principles.</li>
<li>Early direction for typography, color, imagery, and graphic language.</li>
<li>Documented areas of agreement and disagreement.</li>
<li>A clear sense of which concept directions would be wrong before designing them.</li>
</ul>
<p>This last point is especially useful. A strong pre-concept phase not only tells the designer what to explore. It also clarifies what to avoid: directions that would be too expected, too cold, too playful, too conservative, too loud, too generic, or too far from what the audience can trust.</p>
<p>When the team can name those boundaries, the first concept becomes easier to evaluate. The conversation shifts from <em>&ldquo;I like it&rdquo;</em> or <em>&ldquo;I do not like it&rdquo;</em> to <em>&ldquo;Does this express the brand we agreed on?&rdquo;</em></p>
<h2 id="the-first-concept-should-not-be-a-guess">The First Concept Should Not Be A Guess</h2>
<p>The first concept should not feel like a guess or a surprise reveal. It should feel like the next step in a direction the team already understands.</p>
<p>That does not mean removing intuition, experimentation, or creative risk from the branding process. It means giving those things a <strong>sharper problem to solve</strong>. When the team has clarified the brand character, tested visual perception, translated ideas into design principles, and discussed the early building blocks of the identity, the designer can explore with more confidence.</p>
<p>Pre-concept work does not need to make the final identity predictable. It needs to <strong>make the conversation around it more meaningful</strong>. Instead of asking whether the work matches someone&rsquo;s private expectation, the team can ask a better question: Does this visual direction express what the brand needs to become?</p>
<div class="signature"><img decoding="async" src="https://thenokiablog.com/wp-content/uploads/2026/07/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction-8.png" alt="Smashing Editorial" width="35" height="46" loading="lazy"><br>
<span>(yk)</span></div>
<p>The post <a href="https://thenokiablog.com/from-kickoff-to-first-concept-how-to-turn-brand-strategy-into-visual-direction/">From Kickoff To First Concept: How To Turn Brand Strategy Into Visual Direction</a> appeared first on <a href="https://thenokiablog.com">The NOKIA Blog</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
