RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent
RWB has implemented a company-wide database access management architecture centered on Trino and Open Policy Agent (OPA), replacing ad-hoc manual grants with a centralized, auditable process.
Previously, users received full database access rather than granular table or schema permissions. Revocation depended on manual HR synchronization, new access requests took between one and 17 days, and audit trails were incomplete. The company determined that these issues would not scale with growth and required a unified solution meeting strict requirements: no anonymous or password access, minimum necessary privileges, full operation logging, and a digital record of every access request and approval.
The architecture uses Trino Coordinator and Worker nodes to handle queries, OPA to evaluate Rego policies on every request, Keycloak for OIDC authentication, Vault for secrets, Kafka for security event delivery to SOC, and Kubernetes for orchestration. Policies are generated automatically from access matrices stored in GitLab, versioned, tested via CI/CD, and deployed to S3 without service restarts. Granularity reaches column level when needed, though catalog/schema/table is the standard operating scope.
Three request flows were established: project-level access matrices processed through merge requests with automated checks, point-in-time additions to existing groups via Service Desk with two-level approval, and temporary 24–72 hour access with automatic revocation. HR integration now triggers instant access removal upon employee departure, while an independent Access Management team can revoke rights in seconds during emergencies.
All Trino traffic is streamed through an event listener to Kafka and then to SOC, where custom alerts detect enumeration, unauthorized DDL/DML, anomalous query volumes, and impersonation. Incident escalation follows a three-tier model with SOC handling L1, DevOps and Access Management covering L2, and Data Security engaged at L3. Long-term logs reside in S3 per regulatory guidance.
Results include 1,250+ PostgreSQL clusters connected, 700+ daily users, 90+ projects onboarded, and access provisioning reduced to minutes. Real-time BI dashboards track cluster health and project maturity, while 24/7 support channels and training materials assist end users.
Related articles
Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent
Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.
FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s
The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.
Merkle Tree Certificates Proposed to Enable Lightweight Post-Quantum HTTPS in Chrome
Google Chrome developers, together with industry partners and the IETF PLANTS working group, are introducing Merkle Tree Certificates (MTC) as the first HTTPS change designed to address performance challenges of post-quantum cryptography. The new format replaces parts of traditional X.509 certificate chains with compact inclusion proofs inside a Merkle tree whose root is signed by a certificate authority. This approach significantly reduces the size of authentication data exchanged during TLS handshakes while preserving strong post-quantum security properties. MTC also enforces Certificate Transparency by design, making it impossible to issue a public certificate without recording it in a publicly verifiable log. Performance evaluations are currently underway with Cloudflare, and initial public MTC logs operated by experienced CT log providers are planned for early 2027. A dedicated post-quantum Chrome Root Store supporting only MTC is scheduled for the third quarter of 2027 and will run in parallel with the existing root store.
AI Resume Screening Barriers Push Young IT Talent Toward Cybercrime
Young Russian IT graduates with relevant projects and freelance experience are struggling to secure entry-level roles in information security and antifraud due to automated resume filters demanding prior commercial experience. Data from SuperJob and Habr Careers shows only 10-11% of IT vacancies in early 2026 were open to candidates without experience, compared to 37-38% across the broader labor market, with most junior openings limited to technical support. Russian court statistics reveal that 67.9% of those convicted for computer-related crimes under Article 272 were under 30, aligning with the age when graduates first seek professional experience. International studies, including research from Harvard Business School and Accenture, highlight how overly rigid automated screening discards capable candidates lacking formal tenure. Programs like the UK's National Crime Agency Cyber Choices demonstrate that providing legal pathways in cybersecurity can reduce recidivism. The article argues that excessive reliance on AI filters without human review of projects or practical tests exacerbates the pipeline problem in a sector claiming talent shortages.