redb.Identity Adds gRPC Transport for OpenID Server Alongside Existing HTTP Facade
redb.Identity has added a gRPC facade to its OpenID server, placing it alongside the existing HTTP transport on the same core routes. The server remains transport-agnostic: all authorization logic resides behind direct-vm://identity-* addresses, and both HTTP and gRPC now act as interchangeable facades over this kernel.
The new surface implements the protocol operations required by relying parties: Token at /identity.v1.Identity/Token (RFC 6749 §3.2), Introspect (RFC 7662), Revoke (RFC 7009), UserInfo (OIDC Core §5.3), Discovery, and Jwks (RFC 7517). A gRPC health check is also exposed via grpc.health.v1.Health/Check. Forty administrative operations across five services (Users, Applications, Groups, Scopes, Tokens) are available on a dedicated management port.
Requests accept the same key-value pairs defined by the RFCs plus a map<string, string> for extensions. Responses type the fields fixed by the specifications and place open sets such as claims into google.protobuf.Struct. OAuth errors are returned as gRPC status codes (UNAUTHENTICATED, PERMISSION_DENIED, RESOURCE_EXHAUSTED, INVALID_ARGUMENT) with the original error code and correlation identifier carried in trailers.
The same token issued through dynamic client registration over HTTP is accepted by the gRPC endpoint and yields identical authorization decisions. Scope evaluation occurs once inside the kernel at direct-vm://identity-authz-check, eliminating the risk of divergent policy between transports.
Browser flows (authorize, login, consent, MFA), DPoP proofs (RFC 9449), and user self-service remain exclusively on HTTP. The gRPC listener uses its own port because it requires HTTP/2 while the HTTP facade supports both HTTP/1.1 and HTTP/2.
Configuration is placed in the shared context.json under the identity.grpc section, allowing independent host, port, TLS, and compression settings. The EmitHttpCompatHeaders flag is enabled by default to preserve IP-based rate limiting and device metadata collection.
Related articles
Why 99% Attack Detection Rules Generate 99.9% False Positives in Real SOC Environments
A detection rule claiming 99% attack coverage with only 1% false positive rate sounds effective on paper, yet in practice it produces roughly one thousand false alerts for every genuine incident. Using a realistic example of 200,000 daily logins containing just two real compromises, the article demonstrates that 1.98 true positives are buried among 2,000 false positives. Bayes' theorem explains why sensitivity improvements barely move the needle while reducing the false-positive rate or narrowing the population yields dramatic gains in precision. The piece outlines three practical levers—lowering FPR, scoping rules to high-risk accounts, and cascading cheap-then-expensive checks—that cut analyst workload by orders of magnitude without sacrificing meaningful coverage. It also warns that chronically low-precision rules train analysts to ignore alerts, eventually leading to the rule being disabled despite remaining in compliance matrices. The recommended metric pair is therefore confirmed detections alongside coverage, rather than coverage alone.
ChatGPT Knows Your Company but Google Doesn't: Step-by-Step Guide to Diagnosing AI Visibility Issues
The complaint that a brand is missing from AI answers often masks six distinct technical problems that require opposite fixes. The guide separates three visibility layers—model knowledge without search, pre-indexed search bots such as OAI-SearchBot, and on-demand agent bots such as ChatGPT-User—and explains how to measure each one. It details checks for robots.txt entries, nosnippet and max-snippet meta tags, Cloudflare AI bot toggles, and server logs that reveal 403, 429, and 404 responses from specific crawlers. Additional steps cover JavaScript-rendered content, repeated query testing across 20 prompts, official reports in Yandex Webmaster and Google Search Console, and hidden prompt-injection instructions that may have been planted in page metadata. The article stresses that aggregated “AI visibility” percentages are meaningless without layer separation and warns that blocking training can unintentionally harm ordinary search indexing.
Nvidia to Cease Regular GeForce Driver Updates for Windows 10 After October 2026
Nvidia has announced the end of regular driver support for Windows 10 in its GeForce Game Ready and Nvidia Studio driver lines starting October 2026. The first driver package without Windows 10 support will arrive in November of that year. Microsoft ended the base lifecycle of Windows 10 on October 14, 2025, and Nvidia is extending support by one additional year. Existing games and applications will continue to function after the change, while quarterly security patches for critical vulnerabilities will remain available until October 2029. Users will no longer receive optimizations for new games, fixes for graphics issues, or new GPU features. Newer technologies such as DLSS may also skip Windows 10 compatibility. The transition is described as gradual rather than abrupt, allowing older titles to keep running while newer releases increasingly encourage migration to a supported Windows version.
Rospotrebnadzor Introduces Age-Based Screen Time Limits for Russian School Students
Russia's consumer protection agency Rospotrebnadzor has established recommended maximum durations for schoolchildren working with computers and interactive whiteboards during lessons. The limits vary by grade, ranging from 20 minutes for first and second graders up to 35 minutes for students in grades 10 and 11. Separate rules apply to interactive boards, capping usage at 20 minutes for children under 10 and 30 minutes for older students. Schools must ensure students perform eye exercises when electronic devices are used, while traditional paper-based classes require such exercises only during breaks. Starting September 1 2026, a nationwide ban on mobile phones during lessons will also take effect, with individual schools deciding rules for recess periods.