<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: supachai jaturaprom</title>
    <description>The latest articles on DEV Community by supachai jaturaprom (@supachai).</description>
    <link>https://dev.to/supachai</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F460477%2F20e10616-0f88-482b-b400-ede82ef0a304.JPG</url>
      <title>DEV Community: supachai jaturaprom</title>
      <link>https://dev.to/supachai</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/supachai"/>
    <language>en</language>
    <item>
      <title>วิเคราะห์-วิจารณ์: KBTG กับความจริงของ "Agentic AI" ที่ยังไม่ได้ถูกพูดในสัมภาษณ์</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Sat, 26 Sep 2026 08:30:37 +0000</pubDate>
      <link>https://dev.to/supachai/kbtg-kabkhwaamcchringkhng-agentic-ai-emuuekhamokhsnaakabsingthiiekidkhuencchringainhngekhruueng-aimehmuuenepa-oa7</link>
      <guid>https://dev.to/supachai/kbtg-kabkhwaamcchringkhng-agentic-ai-emuuekhamokhsnaakabsingthiiekidkhuencchringainhngekhruueng-aimehmuuenepa-oa7</guid>
      <description>&lt;h1&gt;
  
  
  วิเคราะห์-วิจารณ์: KBTG กับความจริงของ "Agentic AI" ที่ยังไม่ได้ถูกพูดในสัมภาษณ์
&lt;/h1&gt;

&lt;p&gt;&lt;strong&gt;อ้างอิงจาก:&lt;/strong&gt; The Secret Sauce EP.998 "KBTG ชี้เป้า ทักษะแห่งอนาคตในยุค Agentic AI" สัมภาษณ์คุณวรนุช เดชะไกศยะ Executive Chairman, KBTG โดยเคนคริน[1]&lt;/p&gt;

&lt;h2&gt;
  
  
  บริบทที่ควรรู้ก่อนอ่าน
&lt;/h2&gt;

&lt;p&gt;อันดับแรก ต้องตั้งข้อสังเกตเรื่องจังหวะเวลาของการสัมภาษณ์นี้: เมษายน 2026 คุณกระทิง-เรืองโรจน์ พูนผล ลงจากตำแหน่งประธานกลุ่ม KBTG ไปเป็น Advisor to the Board ของ KBank และคุณวรนุช เดชะไกศยะ ซึ่งเป็น Executive Chairman อยู่แล้วขึ้นมารับช่วงบทบาทผู้นำหลักแทน[8] สัมภาษณ์นี้จึงเป็นการสื่อสารกลยุทธ์อย่างเป็นทางการครั้งแรกๆ ของผู้นำคนใหม่ ไม่ใช่แค่บทสนทนาสบายๆ — narrative แบบ "เรามาถูกทางแล้ว ROI กำลังจะมา" จึงมีแรงจูงใจด้าน stakeholder management ปนอยู่ด้วย ไม่ใช่แค่การแชร์ประสบการณ์เฉยๆ&lt;/p&gt;

&lt;h2&gt;
  
  
  จุดที่บทสัมภาษณ์พูดตรงและมีน้ำหนักดี
&lt;/h2&gt;

&lt;p&gt;ก่อนจะวิจารณ์ ต้องให้เครดิตในจุดที่คุณวรนุชพูดอย่างระมัดระวังและตรงกับ evidence ภายนอกจริง:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1) ตัวเลขที่ระบุอย่างเจาะจง ไม่ได้ overclaim&lt;/strong&gt; — คุณวรนุชบอกชัดว่า coding เพียงอย่างเดียวเร็วขึ้น "200-300%" แต่ทั้ง SDLC (Software Development Life Cycle) ลดเวลาได้แค่ "10-15%" เพราะ coding เป็นแค่ส่วนหนึ่งของ requirement → design → coding → test → deploy[1] ตัวเลขนี้ตรงกับที่ Techsauce รายงานอย้างเป็นทางการจาก KBTG เอง: ปี 2025 AI ช่วยเขียนโค้ดได้ราว 21 ล้านบรรทัด (~10% ของโค้ดทั้งหมด) และเป้าปี 2026 อยู่ที่ราว 15%[2] — คือกรณีตัวอย่างที่ดีของการไม่ปล่อยให้ productivity ของ "แค่การเขียนโค้ด" ไปกลบตัวเลข end-to-end ที่ realistic กว่า ตรงข้ามกับ vendor pitch ทั่วไปที่มักโฆษณา multiplier ของ coding assistant เป็น business-wide productivity gain&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2) ยอมรับเรื่อง token cost อย่างตรงไปตรงมา&lt;/strong&gt; — มีช่วงที่คุณวรนุชพูดชัดเจนว่า "AI Coding นี่แหละที่เบิร์น token มากที่สุด" และเตือนว่าองค์กรต้อง optimize ว่าจะใช้โมเดลไหนกับงานแบบไหน ไม่งั้น "ตาย"[1] เป็นมุมที่วงการ enterprise AI มักไม่พูดถึงตรงๆ เพราะกลัวทำลาย hype แต่คุณวรนุชพูดออกมาเปิดเผย&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3) Human-in-the-loop และ observability เป็นแกนหลัก ไม่ใช่แค่ buzzword&lt;/strong&gt; — ประเด็นที่ว่า "ถ้า input/requirement มาไม่ถูก AI เช็คยังไงก็ไม่ถูก" และต้องรู้ว่า agent เข้าถึงข้อมูลระดับไหน หยุดที่จุดไหน — ตรงกับหลักการ AI governance ที่ธนาคารทั่วโลกกำลังทำตาม (data access control, agent identity, kill-switch) ไม่ใช่การพูดลอยๆ&lt;/p&gt;

&lt;h2&gt;
  
  
  จุดที่ควรถามต่อ / มีแหล่งอิสระที่ให้ภาพต่างออกไป
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;1) กรอบ "ROI จะมาแน่ ถ้าโฟกัส Pain Point ให้ถูก" ข้ามประเด็นที่ว่าองค์กรส่วนใหญ่ล้มเหลวจริงๆ&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;คุณวรนุชแนะนำ CEO ที่ฟังอยู่ว่าให้เริ่มจาก Pain Point ที่แท้จริง อย่ารอ ROI ชัดร้อยเปอร์เซ็นต์ค่อยเริ่ม[1] คำแนะนำนี้ฟังดูสมเหตุสมผล แต่ไม่ได้พูดถึงตัวเลขที่หนักที่สุดในวงการตอนนี้: รายงาน "The GenAI Divide" ของ MIT NANDA (2025) ซึ่งสำรวจองค์กรกว่า 300 โครงการ AI พบว่า &lt;strong&gt;95% ขององค์กรที่ลงทุนใน GenAI ไม่ได้ผลตอบแทนที่วัดผลได้ต่องบกำไรขาดทุนเลย&lt;/strong&gt; แม้จะมีเงินลงทุนรวมกันถึง 30-40 พันล้านดอลลาร์[3] ที่สำคัญกว่านั้น รายงานชี้ว่าความสำเร็จไม่ได้ขึ้นกับคุณภาพโมเดล แต่ขึ้นกับ "แนวทาง" — โครงการที่ built-in-house ล้วนๆ โดยทีมกลางประสบความสำเร็จเพียง ~33% ในขณะที่โครงการที่ทำร่วมกับ vendor เฉพาะทางสำเร็จถึง ~67%[3]&lt;/p&gt;

&lt;p&gt;ข้อนี้สำคัญเพราะ KBTG เลือกเส้นทาง build-in-house เป็นหลัก (มี playground, POC เอง, ทีมภายในลงมือสร้าง Agent เอง) — ซึ่งตาม MIT NANDA เป็นกลุ่มที่มีอัตราความสำเร็จต่ำกว่า ไม่ได้แปลว่า KBTG จะล้มเหลว (เป็นธนาคารที่มีทรัพยากรและ track record เฉพาะทางสูง) แต่คำแนะนำทั่วไปที่ให้กับ "อุตสาหกรรมอื่นๆ ทั้งหมด" ในบทสัมภาษณ์ควรมาพร้อมคำเตือนว่าอัตราความล้มเหลวของโมเดล build-in-house สูงกว่าที่คิด ไม่ใช่แค่เรื่อง "เริ่มให้ถูกจุด" อย่างเดียว&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2) ตัวเลข productivity ของ AI coding ยังมีข้อโต้แย้งในวงการที่บทสัมภาษณ์ไม่ได้แตะ&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;บทสัมภาษณ์บอกว่า coding assistant ทำให้เร็วขึ้น 200-300% ซึ่งอาจจะจริงสำหรับ context การเขียนโค้ดใหม่ (greenfield) ที่มี spec ชัด แต่งานวิจัยที่ทำแบบ randomized controlled trial (RCT) — วิธีวัดผลที่เข้มงวดกว่าการประเมินตนเอง — ของ METR (2025) กลับพบผลตรงข้าม: เมื่อให้ developer ที่มีประสบการณ์สูงทำงานจริงบน open-source repository ของตัวเอง (ซึ่งใกล้เคียงกับ "แก้ระบบ legacy" มากกว่างานสร้างใหม่) การอนุญาตให้ใช้ AI ทำให้ &lt;strong&gt;ใช้เวลานานขึ้น 19%&lt;/strong&gt; ทั้งที่ developer เองคาดว่าจะเร็วขึ้น 24% และหลังทำเสร็จยังเข้าใจผิดว่าตัวเองเร็วขึ้น 20%[4] — ช่องว่างระหว่างความรู้สึกกับความจริงนี้เป็นประเด็นสำคัญที่องค์กรควรระวังเวลาวัดผล productivity จาก self-report เพียงอย่างเดียว&lt;/p&gt;

&lt;p&gt;ต้องเป็นธรรมกับทั้งสองฝั่ง: METR เองก็ตามผลต่อในเดือนกุมภาพันธ์ 2026 พบสัญญาณว่า developer อาจเร็วขึ้นจริงในช่วงปลายปี 2025 เมื่อโมเดลดีขึ้น แต่ methodology มีปัญหาเรื่อง selection bias จนบอกขนาดผลกระทบที่แท้จริงไม่ได้ชัด[5] ส่วน Stanford AI Index 2026 รายงานว่า software developer ที่ใช้ AI มี productivity เพิ่มขึ้นเฉลี่ย 26% จากการสำรวจ firm-level หลายแห่ง[6] — ตัวเลขนี้สอดคล้องในทิศทางกับที่ KBTG พูดถึงมากกว่า METR RCT ในปี 2025&lt;/p&gt;

&lt;p&gt;สรุปคือ: มีทั้ง evidence ที่หนุนและย้อนแย้งกับคำกล่าวอ้างเรื่อง coding productivity ขึ้นกับ methodology (survey/self-report vs. controlled experiment) และ task type (greenfield feature vs. maintaining complex legacy code) — บทสัมภาษณ์นำเสนอตัวเลขเชิงบวกโดยไม่ได้บอกบริบทว่าวัดจากอะไร ซึ่งเป็นจุดที่ผู้ฟังควรถามต่อก่อนเชื่อ 100%&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3) เรื่อง "เด็กจบใหม่ต้องปรับสกิล ไม่ใช่ถูกแทนที่" — ตัวเลขจริงเริ่มบอกอีกเรื่องแล้ว&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;คุณวรนุชให้มุมมองที่ระมัดระวังและมีเหตุผลว่า KBTG ไม่ได้ตัดเด็กจบใหม่ออก แต่ปรับ role ให้ใช้ AI tools เป็นและเข้าใจภาพรวมมากขึ้น ไม่ใช่แค่เขียนโค้ด[1] เป็นมุมมองที่ฟังดูสมดุลและตรงกับสิ่งที่ KBTG ทำจริง (ยังรับเด็กฝึกงานเยอะ, เริ่มตั้งแต่ปี 1) แต่ในภาพรวมของอุตสาหกรรม ข้อมูลอิสระเริ่มมีสัญญาณที่ specific กว่านั้น: Stanford HAI AI Index 2026 รายงานว่า &lt;strong&gt;การจ้างงาน software developer อายุ 22-25 ปี ลดลงเกือบ 20% นับตั้งแต่ปี 2024&lt;/strong&gt; ขณะที่การจ้างงาน developer อาวุโสยังคงเพิ่มขึ้นต่อเนื่อง[6] เป็นครั้งแรกที่รายงานนี้ระบุการหดตัวเฉพาะกลุ่มอายุใน white-collar occupation เดียวชัดเจนขนาดนี้ และรายงานเดียวกันยังเตือนว่า "การพึ่งพา AI มากเกินไปอาจสร้าง long-term learning penalty" — เด็กจบใหม่ที่ยังถูกจ้างอาจเรียนรู้ทักษะ judgment ที่จำเป็นสำหรับตำแหน่งอาวุโสได้ช้าลงกว่าเดิม เพราะใช้เวลาไปกับการกำกับ AI มากกว่าลงมือทำเอง[6]&lt;/p&gt;

&lt;p&gt;นี่ไม่ได้แปลว่าคุณวรนุชพูดผิด — สถานการณ์ของ KBTG อาจต่างจากค่าเฉลี่ยอุตสาหกรรมจริง (เพราะลงทุนเรื่อง internship pipeline เฉพาะตัว) แต่การพูดถึง "เด็กจบใหม่" ในฐานะเรื่องของ "demand-supply" และ "สกิลเปลี่ยน" โดยไม่กล่าวถึงตัวเลขการจ้างงานที่ลดลงจริงในระดับอุตสาหกรรม ทำให้ผู้ฟังอาจเข้าใจว่าปัญหานี้ soft กว่าที่ข้อมูลจริงบ่งชี้&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4) "ถ้าคู่แข่งใช้เครื่องมือเดียวกัน อะไรคือความต่าง" — คำตอบที่ได้อาจ underplay ความเสี่ยงของการ scale agentic AI เอง&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;คำตอบในบทสัมภาษณ์คือ "อยู่ที่คุณเอาเครื่องมือมาใช้ให้เกิดประโยชน์และเก่งกว่าคนอื่น"[1] เป็นคำตอบที่ถูกแต่ค่อนข้าง generic และไม่ได้พูดถึงความเสี่ยงเชิงระบบของการ scale agentic AI ที่ Gartner เตือนไว้อย่างเจาะจง: &lt;strong&gt;มากกว่า 40% ของโครงการ agentic AI จะถูกยกเลิกภายในสิ้นปี 2027&lt;/strong&gt; เพราะต้นทุนบานปลาย, มูลค่าทางธุรกิจไม่ชัดเจน, หรือ risk control ไม่เพียงพอ[7] กล่าวคือ การแข่งขันด้วย Agentic AI ไม่ใช่แค่เรื่อง "ใครใช้เก่งกว่า" แต่ยังมีความเสี่ยงเชิงโครงสร้างที่ทำให้โครงการล้มก่อนจะได้ประโยชน์เลยด้วยซ้ำ — ซึ่งสอดคล้องกับสิ่งที่คุณวรนุชพูดถึงเรื่อง observability และ human-in-the-loop จริง แต่ไม่ได้เชื่อมโยงให้ผู้ฟังเห็นภาพว่านี่คือความเสี่ยงระดับอุตสาหกรรม ไม่ใช่แค่รายละเอียดปฏิบัติการ&lt;/p&gt;

&lt;h2&gt;
  
  
  สรุป
&lt;/h2&gt;

&lt;p&gt;บทสัมภาษณ์นี้มีจุดแข็งตรงที่คุณวรนุชพูดด้วยตัวเลขเจาะจงและยอมรับข้อจำกัดของ AI อย่างตรงไปตรงมามากกว่าสัมภาษณ์ enterprise AI ทั่วไปในตลาด (โดยเฉพาะเรื่อง token cost และ SDLC ลดแค่ 10-15% ไม่ใช่ 200%) แต่ในฐานะเนื้อหาที่ให้คำแนะนำกับ "CEO อุตสาหกรรมอื่นๆ ทั้งหมด" ยังขาดการเชื่อมโยงกับข้อมูลอิสระที่บ่งชี้ความเสี่ยงเชิงระบบสามเรื่องหลัก: (1) อัตราความล้มเหลวของโครงการ AI ในภาพรวมสูงถึง 95% ตาม MIT NANDA (2) ผลของ AI coding ต่อ productivity ยังมีหลักฐานขัดแย้งกันขึ้นกับวิธีวัดและประเภทงาน และ (3) ผลกระทบต่อการจ้างงานเด็กจบใหม่ในระดับอุตสาหกรรมรุนแรงกว่าที่ narrative "สกิลแค่เปลี่ยน" บอกไว้ ผู้ฟังที่เป็นผู้บริหารควรใช้บทสัมภาษณ์นี้เป็นจุดตั้งต้นที่ดี ไม่ใช่สูตรสำเร็จที่นำไปใช้ได้ทันทีโดยไม่ตรวจสอบบริบทองค์กรตัวเองเทียบกับข้อมูลอิสระเหล่านี้ก่อน&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;p&gt;[1] &lt;a href="https://www.youtube.com/watch?v=NL2Xmcy86s0" rel="noopener noreferrer"&gt;https://www.youtube.com/watch?v=NL2Xmcy86s0&lt;/a&gt; — The Secret Sauce EP.998: KBTG ชี้เป้า ทักษะแห่งอนาคตในยุค Agentic AI (สัมภาษณ์ วรนุช เดชะไกศยะ)&lt;br&gt;
[2] &lt;a href="https://techsauce.co/tech-and-biz/kbtg-2026-ai-business-value-trust-cyber-resilience" rel="noopener noreferrer"&gt;https://techsauce.co/tech-and-biz/kbtg-2026-ai-business-value-trust-cyber-resilience&lt;/a&gt; — ส่องกลยุทธ์ KBTG 2026 เมื่อ AI ต้องสร้าง Value จริง - Techsauce&lt;br&gt;
[3] &lt;a href="https://valtao.com/wp-content/uploads/2025/11/Rapport-MIT.pdf" rel="noopener noreferrer"&gt;https://valtao.com/wp-content/uploads/2025/11/Rapport-MIT.pdf&lt;/a&gt; — MIT NANDA: The GenAI Divide - State of AI in Business 2025&lt;br&gt;
[4] &lt;a href="https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study" rel="noopener noreferrer"&gt;https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study&lt;/a&gt; — METR: Measuring the Impact of Early-2025 AI on Experienced Open-Source Developer Productivity&lt;br&gt;
[5] &lt;a href="https://metr.org/blog/2026-02-24-uplift-update" rel="noopener noreferrer"&gt;https://metr.org/blog/2026-02-24-uplift-update&lt;/a&gt; — METR: We are Changing our Developer Productivity Experiment Design (Feb 2026 update)&lt;br&gt;
[6] &lt;a href="https://www.ivector.co/blog/ai-index-2026-junior-developer-hiring-drop" rel="noopener noreferrer"&gt;https://www.ivector.co/blog/ai-index-2026-junior-developer-hiring-drop&lt;/a&gt; — AI Index 2026: Why Junior Developer Hiring Fell 20% (citing Stanford HAI AI Index 2026)&lt;br&gt;
[7] &lt;a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027" rel="noopener noreferrer"&gt;https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027&lt;/a&gt; — Gartner: Over 40% of Agentic AI Projects Will Be Canceled by End of 2027&lt;br&gt;
[8] &lt;a href="https://www.brandbuffet.in.th/2026/04/krating-ruangroj-poonphol-leaves-kbtg" rel="noopener noreferrer"&gt;https://www.brandbuffet.in.th/2026/04/krating-ruangroj-poonphol-leaves-kbtg&lt;/a&gt; — เปลี่ยนแม่ทัพ กระทิง-เรืองโรจน์ พูนผล อำลา KBTG ส่งไม้ต่อ วรนุช เดชะไกศยะ&lt;/p&gt;

</description>
      <category>ai</category>
      <category>kbtg</category>
      <category>banking</category>
      <category>tech</category>
    </item>
    <item>
      <title>กล้ามเนื้อที่ชื่อว่า "ความคิด": Growth Mindset ในแบบที่ควรใช้จริง</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Sat, 26 Sep 2026 08:10:26 +0000</pubDate>
      <link>https://dev.to/supachai/klaamenuuethiichuuewaa-khwaamkhid-growth-mindset-ainaebbthiikhwraichcchring-2n6k</link>
      <guid>https://dev.to/supachai/klaamenuuethiichuuewaa-khwaamkhid-growth-mindset-ainaebbthiikhwraichcchring-2n6k</guid>
      <description>&lt;h1&gt;
  
  
  กล้ามเนื้อที่ชื่อว่า "ความคิด": Growth Mindset ในแบบที่ควรใช้จริง (ไม่ใช่แค่โปสเตอร์ติดผนัง)
&lt;/h1&gt;

&lt;p&gt;ลองนึกภาพนักยกน้ำหนักสองคนยืนอยู่หน้าบาร์เบล คนแรกมองแล้วคิดว่า "แรงของกูมีเท่านี้แหละ ยกได้แค่นี้ก็คือขีดสุดแล้ว" ส่วนอีกคนมองบาร์เบลแล้วคิดว่า "วันนี้ยกได้เท่านี้ พรุ่งนี้ฝึกต่อ เดี๋ยวก็ยกได้มากขึ้น" ความแตกต่างระหว่างสองคนนี้ไม่ใช่แค่ทัศนคติเท่ๆ แต่เป็นกรอบความคิดที่นักจิตวิทยา Carol Dweck แห่ง Stanford นิยามไว้ว่า &lt;strong&gt;fixed mindset&lt;/strong&gt; กับ &lt;strong&gt;growth mindset&lt;/strong&gt; — ความเชื่อที่ว่าความสามารถและสติปัญญาเป็นสิ่งตายตัว เทียบกับความเชื่อที่ว่ามันพัฒนาได้ผ่านความพยายาม กลยุทธ์ที่ถูกต้อง และการเรียนรู้จากความล้มเหลว[5]&lt;/p&gt;

&lt;h2&gt;
  
  
  จุดเริ่มต้น: คำชมที่ "ฆ่า" แรงจูงใจ
&lt;/h2&gt;

&lt;p&gt;งานวิจัยรากฐานที่ทำให้แนวคิดนี้ดังไปทั่วโลกคือการทดลองของ Mueller และ Dweck ในปี 1998 กับเด็กประถมปลายราว 400 คน พวกเขาให้เด็กทำโจทย์ปริศนา แล้วแบ่งคำชมออกเป็นสองแบบ: ชมที่ "ความฉลาด" ("เธอต้องฉลาดมากแน่ๆ") กับชมที่ "ความพยายาม" ("เธอต้องพยายามหนักมากแน่ๆ")&lt;/p&gt;

&lt;p&gt;ผลลัพธ์ชัดเจนมาก: เด็กที่ถูกชมว่าฉลาด พอเจอโจทย์ยากขึ้นและทำพลาด กลับเลือกงานที่ง่ายลงในรอบถัดไป ความอดทนต่องานลดลง ความสนุกในการทำโจทย์ลดลง และเวลาพลาดก็โทษว่า "ตัวเองไม่ฉลาดพอ" ส่วนเด็กที่ถูกชมว่าพยายาม กลับมีความอดทนสูงกว่า สนุกกับโจทย์มากกว่า และเมื่อพลาดก็ตีความว่า "ยังพยายามไม่พอ" ซึ่งเป็นกรอบคิดที่นำไปสู่การลงมือแก้ปัญหาต่อ ไม่ใช่การถอนตัว[1]&lt;/p&gt;

&lt;p&gt;นี่คือหัวใจของ growth mindset ในทางปฏิบัติ: &lt;strong&gt;วิธีที่เราตีความความล้มเหลวของตัวเอง กำหนดว่าเราจะลุกขึ้นสู้ต่อหรือถอดใจ&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  จากห้องทดลองสู่ห้องเรียนจริง
&lt;/h2&gt;

&lt;p&gt;ต่อมาในปี 2007 Blackwell, Trzesniewski และ Dweck ติดตามนักเรียนมัธยมต้นจริงเป็นเวลา 2 ปี พบว่านักเรียนที่เชื่อว่าสติปัญญาพัฒนาได้ (incremental theory) มีพัฒนาการเกรดคณิตศาสตร์ที่ชันกว่านักเรียนที่เชื่อว่าสติปัญญาตายตัว (entity theory) อย่างมีนัยสำคัญ[2] งานนี้เองที่ทำให้แนวคิด growth mindset ก้าวจากห้องแล็บสู่หลักสูตรโรงเรียนหลายพันแห่งทั่วสหรัฐฯ และกลายเป็นหนึ่งในกรอบคิดด้านการศึกษาที่มีอิทธิพลที่สุดในรอบ 20 ปีที่ผ่านมา[5]&lt;/p&gt;

&lt;h2&gt;
  
  
  แต่ความจริงมีมากกว่าโปสเตอร์แรงบันดาลใจ
&lt;/h2&gt;

&lt;p&gt;ในฐานะที่บทความนี้ต้องอ้างอิงหลักฐานอย่างตรงไปตรงมา — ต้องบอกด้วยว่า growth mindset ไม่ใช่ยาวิเศษ และงานวิจัยขนาดใหญ่ในช่วงหลังได้ปรับลดความคาดหวังลงมาอย่างมีนัยสำคัญ:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Sisk et al. (2018)&lt;/strong&gt; ทำ meta-analysis รวมข้อมูลจากนักเรียนเกือบ 365,000 คนใน 273 การศึกษา พบว่าความสัมพันธ์ระหว่างการมี growth mindset กับผลการเรียนอยู่ที่ r ≈ 0.10 เท่านั้น — อธิบายความแปรปรวนของผลการเรียนได้เพียงราว 1% และเมื่อดูเฉพาะการทดลองแบบแทรกแซง (intervention) 43 งานวิจัยกับนักเรียน ~57,000 คน ผลเฉลี่ยอยู่ที่ d ≈ 0.08 ซึ่งถือว่าเล็กมากในทางสถิติ พวกเขายังพบสัญญาณของ publication bias ด้วย คือมีแนวโน้มที่งานวิจัยที่ "ได้ผลดี" จะถูกตีพิมพ์มากกว่างานที่ไม่ได้ผล[3][6]&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Yeager et al. (2019)&lt;/strong&gt; ทำการทดลองแบบสุ่มระดับชาติ (National Study of Learning Mindsets) กับนักเรียน ม.ปลายปีที่ 1 จำนวน 12,490 คน ใน 65 โรงเรียนทั่วสหรัฐฯ ตีพิมพ์ใน Nature พบว่าโปรแกรมกระตุ้น growth mindset แบบสั้นๆ ทางออนไลน์ ช่วยเพิ่มเกรดเฉลี่ยได้จริง แต่เฉพาะในกลุ่มนักเรียนที่ผลการเรียนต่ำอยู่เดิม (ราว 0.10 แต้ม GPA) ส่วนนักเรียนที่เรียนดีอยู่แล้วแทบไม่ได้ผลต่าง[4][6]&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;(หมายเหตุความโปร่งใส: ตัวเลขสถิติสองรายการนี้ผู้เขียนอ่านผ่านบทวิเคราะห์สังเคราะห์ของ Atticus Li[6] ซึ่งสรุปจากรายงานต้นฉบับ[3][4] อีกที ยังไม่ได้ดึงข้อความเต็มจากตัวเปเปอร์ต้นฉบับโดยตรง — หากต้องการอ้างอิงระดับ peer-review เต็มรูปแบบ ควรตรวจสอบกับต้นฉบับใน Psychological Science และ Nature อีกครั้ง)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;สรุปคือ: ผลของ growth mindset &lt;strong&gt;มีจริง แต่เล็กกว่าที่ภาพลักษณ์ยอดนิยมทำให้เราเชื่อมาก&lt;/strong&gt; และมันไม่ใช่เวทมนตร์ที่ใช้ได้กับทุกคนในทุกบริบท — ได้ผลชัดสุดกับคนที่กำลังเจอกำแพงหรือขาดความมั่นใจ ไม่ใช่คนที่ทำได้ดีอยู่แล้ว&lt;/p&gt;

&lt;h2&gt;
  
  
  แล้วเราควรใช้แนวคิดนี้อย่างไรให้ "สร้างสรรค์และพัฒนา" จริง
&lt;/h2&gt;

&lt;p&gt;จากหลักฐานทั้งหมด นี่คือวิธีที่งานวิจัยสนับสนุนจริง ไม่ใช่แค่สโลแกน:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;ชมกระบวนการ ไม่ใช่ชมป้ายฉลาก&lt;/strong&gt; — พูดว่า "วิธีคิดนี้น่าสนใจ" หรือ "ความพยายามตรงนี้เห็นผล" แทนที่จะพูดว่า "เก่งมาก" หรือ "หัวไว" เพราะป้ายฉลาก ("ฉลาด") ผูกความมั่นใจไว้กับผลลัพธ์ครั้งเดียว พอพลาดทีก็สั่นคลอนทั้งระบบ[1]&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;ใช้คำว่า "ยัง" (yet)&lt;/strong&gt; — "ยังทำไม่ได้ตอนนี้" ต่างจาก "ทำไม่ได้" อย่างสิ้นเชิง คำเล็กๆ คำนี้เปลี่ยนกรอบจากการตัดสิน (judgment) เป็นสถานะชั่วคราว (state) ที่เปลี่ยนแปลงได้[5]&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;ตีความความล้มเหลวเป็นข้อมูล ไม่ใช่คำตัดสิน&lt;/strong&gt; — จุดที่ mastery-oriented mindset ต่างจาก helpless mindset ไม่ใช่ว่าใครเก่งกว่า แต่คือใครมองว่าความล้มเหลวคือ "สัญญาณให้ปรับกลยุทธ์" เทียบกับ "หลักฐานว่าไม่มีความสามารถ"[1]&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;อย่าคาดหวังปาฏิหาริย์ระดับองค์กรจากคำพูดให้กำลังใจอย่างเดียว&lt;/strong&gt; — ถ้าจะสร้างวัฒนธรรม growth mindset จริงจัง (ทีมงาน, นักเรียน, ลูกทีม) ต้องคู่กับระบบสนับสนุนจริง เช่น เวลาฝึกฝนเพิ่ม, โค้ชที่ดี, feedback loop ที่ไว — ไม่ใช่แค่เปลี่ยนคำพูดแล้วจบ เพราะหลักฐานชี้ว่าผลของ mindset เพียวๆ นั้นเล็ก เมื่อเทียบกับปัจจัยเชิงระบบอื่น[3][4]&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  สรุปแบบตรงไปตรงมา
&lt;/h2&gt;

&lt;p&gt;Growth mindset เป็นเครื่องมือที่มีหลักฐานรองรับจริง แต่เป็นเครื่องมือขนาดเล็กในกล่องเครื่องมือที่ใหญ่กว่า มันไม่ใช่สาเหตุเดียวที่ทำให้คนสำเร็จ และไม่ใช่คาถาที่ท่องแล้วเปลี่ยนชีวิต — แต่มันคือ &lt;strong&gt;มุมมองที่ทำให้เราลุกขึ้นได้เร็วกว่าเดิมหลังจากล้ม&lt;/strong&gt; และนั่นก็มีค่าพอที่จะฝึกฝนมันอย่างจริงจัง ไม่ใช่แค่แปะโปสเตอร์ไว้บนผนัง&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;p&gt;[1] &lt;a href="https://psycnet.apa.org/record/1998-04530-003" rel="noopener noreferrer"&gt;https://psycnet.apa.org/record/1998-04530-003&lt;/a&gt; — Mueller &amp;amp; Dweck (1998) Praise for Intelligence Can Undermine Children's Motivation and Performance, JPSP&lt;br&gt;
[2] &lt;a href="https://srcd.onlinelibrary.wiley.com/doi/10.1111/j.1467-8624.2007.00995.x" rel="noopener noreferrer"&gt;https://srcd.onlinelibrary.wiley.com/doi/10.1111/j.1467-8624.2007.00995.x&lt;/a&gt; — Blackwell, Trzesniewski &amp;amp; Dweck (2007) Implicit Theories of Intelligence Predict Achievement Across an Adolescent Transition, Child Development&lt;br&gt;
[3] &lt;a href="https://journals.sagepub.com/doi/10.1177/0956797617739704" rel="noopener noreferrer"&gt;https://journals.sagepub.com/doi/10.1177/0956797617739704&lt;/a&gt; — Sisk et al. (2018) To What Extent and Under Which Circumstances Are Growth Mind-Sets Important to Academic Achievement? Psychological Science&lt;br&gt;
[4] &lt;a href="https://www.nature.com/articles/s41586-019-1466-y" rel="noopener noreferrer"&gt;https://www.nature.com/articles/s41586-019-1466-y&lt;/a&gt; — Yeager et al. (2019) A national experiment reveals where a growth mindset improves achievement, Nature&lt;br&gt;
[5] &lt;a href="https://ctl.stanford.edu/students/growth-mindset" rel="noopener noreferrer"&gt;https://ctl.stanford.edu/students/growth-mindset&lt;/a&gt; — Stanford Center for Teaching and Learning - Growth Mindset&lt;br&gt;
[6] &lt;a href="https://atticusli.com/replication-crisis/growth-mindset" rel="noopener noreferrer"&gt;https://atticusli.com/replication-crisis/growth-mindset&lt;/a&gt; — Atticus Li - Growth Mindset: When the Effect Is Real But a Tenth the Size You Were Told&lt;/p&gt;

</description>
      <category>growthmindset</category>
      <category>psychology</category>
      <category>learning</category>
      <category>productivity</category>
    </item>
    <item>
      <title>Post-Quantum Cryptography: แยกเส้นตายที่แท้จริง ออกจากเส้นตายเชิงการตลาด</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Fri, 25 Sep 2026 12:25:52 +0000</pubDate>
      <link>https://dev.to/supachai/post-quantum-cryptography-aimaicheruueng-khywaakanthiihlang-singthiithamaihphmepliiynkhwaamkhid-5o3</link>
      <guid>https://dev.to/supachai/post-quantum-cryptography-aimaicheruueng-khywaakanthiihlang-singthiithamaihphmepliiynkhwaamkhid-5o3</guid>
      <description>&lt;h2&gt;
  
  
  Post-Quantum Cryptography: แยกเส้นตายที่แท้จริง ออกจากเส้นตายเชิงการตลาด
&lt;/h2&gt;

&lt;p&gt;ผมอ่าน e-book "Post-Quantum Cryptography (PQC) For Dummies" ของ Cisco [13] ด้วยความคาดหวังว่าจะได้ primer เชิงเทคนิคตรงไปตรงมา ซึ่งก็เป็นแบบนั้นจริง ในฐานะ primer ที่สปอนเซอร์โดยเวนเดอร์ก็ถือว่าทำได้ดี แต่พอกลับมาอ่านอีกครั้งด้วยมุมมองที่ตั้งคำถามมากขึ้น และตรวจสอบไขว้กับแหล่งข้อมูลอิสระ ก็พบช่องว่างสำคัญกว่าตัวหนังสือเอง: &lt;strong&gt;หนังสือเล่มนี้ปนกันระหว่าง "ควรพร้อมเมื่อไหร่" กับ "ภัยคุกคามจะเกิดขึ้นจริงเมื่อไหร่"&lt;/strong&gt; [13] ซึ่งเป็นตัวเลขคนละชุดที่มีระดับความแน่นอนต่างกันมาก&lt;/p&gt;

&lt;p&gt;บทความนี้คือการเขียนใหม่จากบทความก่อนหน้าที่ผมเผยแพร่ไปในหัวข้อเดียวกัน แต่เปลี่ยนมุมมอง จากเดิม "นี่คือสิ่งที่ทำให้ผมเชื่อ" มาเป็น "นี่คือสิ่งที่ผมจะโต้แย้งกลับ ถ้าเวนเดอร์เอาข้อมูลนี้มา pitch ในห้องประชุม"&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 1: "Harvest Now, Decrypt Later" — กลไกจริง แต่ความเร่งด่วนถูกขายเกินจริง
&lt;/h3&gt;

&lt;p&gt;กลไกทางเทคนิคไม่มีข้อโต้แย้ง ทีมงานด้าน cryptography ของ NIST เองยืนยันว่าความเสี่ยงเป็นเรื่องจริง: องค์กรต้องเริ่มเตรียมการย้ายระบบสู่ PQC เพราะข้อมูลที่เข้ารหัสไว้อาจกำลังเผชิญความเสี่ยงแบบ harvest-now-decrypt-later อยู่แล้ว [14] นี่คือข้อเท็จจริงเชิงเทคนิคที่ถูกต้อง ไม่ใช่การตลาด&lt;/p&gt;

&lt;p&gt;สิ่งที่ขาดหายไปจาก narrative ของเวนเดอร์ส่วนใหญ่ รวมถึงเล่มนี้ด้วย คือการคำนวณ cost-benefit ที่อยู่เบื้องหลัง การพูดคุยในชุมชนความปลอดภัยไซเบอร์แสดงปฏิกิริยาที่แบ่งเป็นสองฝั่งชัดเจน ทีมที่จัดการข้อมูลอ่อนไหวระยะยาว เช่น ความลับของรัฐหรือทรัพย์สินทางปัญญาที่ต้องเก็บเป็นความลับหลายสิบปี มองว่า HNDL เป็นเรื่องจริงจังและกำลังสร้าง crypto-asset inventory ส่วนทีมที่ไม่มีข้อมูลลักษณะนี้ระบุตรงๆ ว่าไม่ได้ให้ความสำคัญกับเรื่องนี้เป็นอันดับแรก เพราะพวกเขาไม่มีข้อมูลที่คุ้มค่าพอสำหรับการโจมตีแบบนี้ [15] HNDL เป็นโมเดลภัยคุกคามจริงสำหรับข้อมูลบางประเภทเท่านั้น ไม่ใช่ไฟไหม้ห้าดาวสำหรับทุกองค์กรเหมือนกันหมด หนังสือที่สร้างมาเพื่อขายสวิตช์ก็เข้าใจได้ที่จะข้ามความละเอียดอ่อนตรงนี้ไป&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 2: เส้นตายด้านการปฏิบัติตามข้อกำหนดชัดเจน — แต่ไทม์ไลน์ภัยคุกคามจริงไม่ชัดเจนเลย
&lt;/h3&gt;

&lt;p&gt;บทที่ 6 ของ Cisco ระบุวันที่ชัดเจน: 2027 สำหรับ milestone แรกของหลายประเทศ การเปลี่ยนผ่านเต็มรูปในช่วง 2030-2035 วันที่เหล่านี้เป็นเรื่องจริง มาจากข้อบังคับภาครัฐที่ประกาศแล้วจริง [13] สิ่งที่หนังสือไม่ได้บอกให้ชัดคือ ไม่มีใครรู้แน่ชัดว่าคอมพิวเตอร์ควอนตัมที่มีความเกี่ยวข้องเชิงการเข้ารหัส (CRQC) จะเกิดขึ้นจริงเมื่อไหร่ การประเมินจากผู้เชี่ยวชาญอิสระมีช่วงกว้างมาก ตั้งแต่มองโลกในแง่ดีที่ 2027-2030 ไปจนถึงระมัดระวังที่ 2035-2040 หรือมากกว่านั้น [3] อีกการประเมินหนึ่งวางความน่าจะเป็นสูงไว้เฉพาะช่วง 2030-2035 โดยไม่มีฉันทามติที่แคบกว่านั้น [4]&lt;/p&gt;

&lt;p&gt;นั่นคือความไม่แน่นอนกว่าทศวรรษบนตัวแปรเดียวที่กำหนดความเร่งด่วนจริงๆ มันเปลี่ยนวิธีที่เราควรอ่านเส้นตายด้านกำกับดูแล — ไม่ใช่ "ภัยคุกคามควอนตัมจะมาถึงในปี 2027" แต่เป็น "หน่วยงานกำกับดูแลต้องการให้คุณพร้อมก่อนเหตุการณ์ที่ไม่แน่นอน โดยมีระยะเผื่อความปลอดภัยกว้างพอ" นี่เป็นการตัดสินใจเชิงนโยบายที่มีเหตุผลรองรับ แต่เป็นเส้นตายเชิงการบริหารความเสี่ยง ไม่ใช่การพยากรณ์ทางวิทยาศาสตร์ — และเอกสารจากเวนเดอร์มักจะทำให้เส้นแบ่งนี้เบลอเพื่อสร้างความเร่งด่วน&lt;/p&gt;

&lt;p&gt;มีวิธีตรวจสอบความสมเหตุสมผลของเรื่องนี้ได้จากฝั่งฮาร์ดแวร์ควอนตัมเองด้วย Roadmap สาธารณะของ IBM — บริษัทที่สร้างเครื่องจริงๆ ไม่มีผลิตภัณฑ์ PQC ต้องขาย — ตั้งเป้าระบบ 200 logical qubits ("Starling") ไว้ปี 2029 และขยายเป็นระบบ 2,000 logical qubits ("Blue Jay") ภายในปี 2033 [18] ตัวเลขการแยกตัวประกอบของ Gidney-Ekerå ที่สไลด์เวนเดอร์ชอบยกมาอ้าง (ทำลาย RSA-2048 ใน 8 ชั่วโมง) ต้องใช้ noisy physical qubits ประมาณ 20 ล้านตัว [16] — เป็นหน่วยวัดคนละแบบกับจำนวน logical qubits ของ IBM และสับสนกันได้ง่ายถ้ากราฟวางสองตัวเลขนี้ไว้ใกล้กันโดยไม่บอกให้ชัด การประเมินจำนวน logical qubits ที่อัลกอริทึมของ Shor ต้องการจริงอยู่ในช่วงประมาณ 2,000-4,000 ตัว ถ้าเป็นจริงตามนี้ วิถีฮาร์ดแวร์ของ IBM เองจะยังไม่ข้ามเกณฑ์นี้จนกว่าจะถึงประมาณปี 2033 เป็นอย่างเร็วที่สุด — ตรงกับฝั่งระมัดระวังของการประเมิน CRQC อิสระข้างต้น ไม่ใช่ฝั่งมองโลกในแง่ดี และมาจากคนที่มีแรงจูงใจน้อยที่สุดในการขยายไทม์ไลน์ให้ดูเร่งด่วน&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 2b: มุมมองประเทศไทย — หน่วยงานกำกับดูแลและอุตสาหกรรมเริ่มขยับแล้ว ไม่ขึ้นกับหนังสือของเวนเดอร์รายใดรายหนึ่ง
&lt;/h3&gt;

&lt;p&gt;ประเทศไทยก็ไม่ได้รอฉันทามติระดับโลกเรื่องเวลาที่ CRQC จะมาถึงเหมือนกัน สำนักงานคณะกรรมการการรักษาความมั่นคงปลอดภัยไซเบอร์แห่งชาติ (สกมช./NCSA) ประกาศนโยบาย "Quantum-Ready 2030" เป็นเสาหลักระดับชาติต่อสาธารณะแล้ว [19][23] และรายงานข่าวจากเดือนมีนาคม 2026 แสดงว่า NCSA และธนาคารแห่งประเทศไทย (BOT) ร่วมกันเร่งให้ภาคธนาคารเตรียมพร้อมสำหรับสิ่งที่เรียกว่ายุค "Y2Q" โดยวางกรอบให้เป็นเส้นตายเชิงปฏิบัติการแบบ Y2K มากกว่าจะเป็นปัญหาวิจัยที่ยังไกลตัว [21] สมาคมธนาคารไทย (Thai Bankers' Association) จัดบรรทึกสรุปเรื่องการย้ายระบบ PQC ให้กับภาคธนาคารโดยเฉพาะในเดือนกรกฎาคม 2026 [22]&lt;/p&gt;

&lt;p&gt;นี่คือการยืนยันที่เป็นอิสระ จากหน่วยงานกำกับดูแลและสมาคมอุตสาหกรรมที่ไม่มีความเกี่ยวข้องกับเวนเดอร์รายใด ว่าท่าที "เริ่มตอนนี้ ย้ายระบบเป็นเฟส" ไม่ใช่แค่กลยุทธ์การขายของ Cisco เท่านั้น แต่เป็นสมมติฐานการทำงานจริงของสถาบันที่กำหนดความคาดหวังด้านการปฏิบัติตามข้อกำหนดในตลาดนี้ สิ่งที่ควรสังเกตสำหรับการประเมินเชิงเทคนิคที่ทำเพื่อองค์กรไทย: นาฬิกากำกับดูแลตรงนี้เดินตามเครื่องหมายปี 2030 เดียวกับที่ใช้ทั่วโลก แต่มาถึงผ่านแนวทางเฉพาะภาคส่วน (ธนาคารก่อน) มากกว่าข้อบังคับครอบคลุมทั้งหมดในครั้งเดียว — ควรวางแผนขั้นตอนสำรวจสินทรัพย์เข้ารหัสให้สอดคล้องกัน โดยเริ่มจากหน่วยงานกำกับดูแลหรือสมาคมอุตสาหกรรมที่ดูแลภาคส่วนของคุณจริงๆ&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 3: กรอบคิด "แค่เปิด ML-KEM" ข้ามต้นทุนทางวิศวกรรมจริง
&lt;/h3&gt;

&lt;p&gt;หนังสือนำเสนอการผสาน PQC ของ Cisco — ML-KEM ใน IKEv2/IPsec, TLS 1.3, SSH, EAP-TLS/MACsec — ราวกับเป็นแค่การเปิดสวิตช์ตั้งค่า [13] NIST กำหนดมาตรฐานพื้นฐานนี้เสร็จสมบูรณ์แล้วคือ FIPS 203 (ML-KEM) ตั้งแต่สิงหาคม 2024 [1][2] ดังนั้นตัวการเข้ารหัสเองก็เป็นมาตรฐานที่สมบูรณ์แล้ว แต่ต้นทุนการนำไปใช้งานจริงไม่ได้เป็นศูนย์:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ML-KEM-768 มี overhead ที่วัดได้จริงประมาณ 150 ไมโครวินาทีต่อ handshake เทียบกับ X25519 แบบคลาสสิก — เล็กน้อยต่อการเชื่อมต่อหนึ่งครั้ง แต่สะสมเพิ่มขึ้นเมื่อระบบมีอัตราการเชื่อมต่อสูง [11]&lt;/li&gt;
&lt;li&gt;การตั้งค่าแบบ Hybrid KEM ซึ่งเป็นสิ่งที่องค์กรส่วนใหญ่จะใช้จริงระหว่างช่วงเปลี่ยนผ่าน เพื่อความเข้ากันได้ย้อนหลังกับอุปกรณ์รุ่นเก่า มี handshake latency และ bandwidth overhead สูงกว่าทั้งโหมดคลาสสิกล้วนและ post-quantum ล้วน [12]&lt;/li&gt;
&lt;li&gt;บนแพลตฟอร์มที่ไม่มี hardware acceleration สำหรับการคำนวณแบบ lattice-based การประมวลผล PQC อาจเพิ่ม CPU overhead ที่วัดได้บน management plane เมื่อ scale ขึ้น ไม่ใช่แค่ data plane เท่านั้น [8]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;ทั้งหมดนี้ไม่ได้แปลว่าการย้ายระบบสู่ PQC เป็นความคิดที่แย่ แต่มันหมายความว่า "เปิดใช้แล้วเดินหน้าต่อ" ไม่ใช่คำอธิบายที่ถูกต้องของงานจริง การวางแผนขีดความสามารถและการทดสอบประสิทธิภาพในโหมด hybrid เป็นรายการงานจริงที่ต้องทำ และการประเมินเชิงเทคนิคที่เป็นธรรมควรพูดถึงเรื่องนี้&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 4: "Cisco เป็นเจ้าแรก" ต้องการบริบทตลาดที่หนังสือไม่ได้ให้ไว้
&lt;/h3&gt;

&lt;p&gt;Release note ของ Cisco สำหรับ IOS-XE 26.1.1 อธิบายการนำ PQC มาใช้บน C9000 Smart Switch ว่าเป็น "การนำ post-quantum cryptography มาใช้แบบ full-stack เป็นรายแรกในอุตสาหกรรม" [7] นี่คือคำอธิบายของ Cisco เกี่ยวกับผลิตภัณฑ์ของตัวเอง ไม่ใช่ผลการเปรียบเทียบจากบุคคลที่สามที่เป็นอิสระ คู่แข่งก็กำลังเดินหน้าความพยายามคู่ขนานตามไทม์ไลน์ของตัวเอง — Palo Alto Networks เผยแพร่เอกสารการรองรับฟีเจอร์ PQC และการย้ายระบบของตัวเอง [9] และ Fortinet ก็เผยแพร่ roadmap การเตรียม PQC ของตัวเองเช่นกัน [10] ทั้งสองอยู่ในระยะเริ่มต้นใกล้เคียงกับ Cisco การอ้าง "เป็นเจ้าแรก" ของเวนเดอร์เกี่ยวกับฮาร์ดแวร์ของตัวเอง ควรถูกอ่านในฐานะเนื้อหาการตลาด จนกว่าจะมีบุคคลที่สามอิสระมายืนยันการเปรียบเทียบนั้น ไม่ควรเชื่อตามที่กล่าวอ้างทันที&lt;/p&gt;

&lt;h3&gt;
  
  
  ข้ออ้าง 5: สิ่งเดียวที่นักเข้ารหัสอิสระและเอกสารของเวนเดอร์เห็นตรงกันจริงๆ
&lt;/h3&gt;

&lt;p&gt;Bruce Schneier — ไม่มีความเกี่ยวข้องกับ Cisco ไม่มีผลิตภัณฑ์ต้องขาย — พูดประเด็นที่รอดจากตัวกรองการตลาดได้อย่างสมบูรณ์ ความตื่นตระหนกในปัจจุบันเรื่องคอมพิวเตอร์ควอนตัมจะ "ทำลายทุกอย่าง" ส่วนใหญ่มาจากคนที่ไม่เข้าใจ cryptography [5] แต่ข้อสรุปที่นำไปปฏิบัติได้จริงที่ซ่อนอยู่ใต้คำเตือนนั้นยังคงเป็นจริง — ต้องสร้าง cryptoagility เพราะไม่ว่า NIST จะกำหนดมาตรฐานอะไรตอนนี้ มันมีแนวโน้มจะถูกทำลายหรือถูกแทนที่เร็วกว่าที่ทุกคนต้องการ ระบบจึงต้องสามารถสลับอัลกอริทึมได้โดยไม่ต้องออกแบบใหม่ทั้งหมด [6] นี่คือข้ออ้างเดียวในหนังสือของ Cisco ที่ผมจะยังคงเชื่อไว้แบบไม่มีข้อสงวน ไม่ใช่เพราะ Cisco พูด แต่เพราะมันยืนหยัดได้ด้วยตัวเองไม่ว่าใครจะเป็นคนพูด&lt;/p&gt;

&lt;h3&gt;
  
  
  สรุปสิ่งที่ผมจะทำจริงในฐานะการประเมินเชิงเทคนิค
&lt;/h3&gt;

&lt;p&gt;ถ้าคุณกำลังวางแผนสถาปัตยกรรมแบบไม่ผูกติดเวนเดอร์ นี่คือเวอร์ชันของเรื่องนี้ที่ผมจะลงมือทำจริง:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;สำรวจสินทรัพย์เข้ารหัสตามความอ่อนไหวของข้อมูลและอายุการใช้งาน&lt;/strong&gt; — ข้อนี้ใช้ได้เสมอไม่ว่าไทม์ไลน์ CRQC จะแม่นยำแค่ไหน [3][4] เพราะระยะเวลาการย้ายระบบเอง — หลายปีสำหรับสิ่งที่ฝังอยู่ในฮาร์ดแวร์/เฟิร์มแวร์ — คือข้อจำกัดจริง ไม่ใช่วันที่ภัยคุกคามควอนตัมจะมาถึง&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;มองข้ออ้าง "เราเป็นเจ้าแรก" ของเวนเดอร์เป็นเรื่องที่ยังไม่ได้รับการยืนยัน จนกว่าจะมี benchmark อิสระ&lt;/strong&gt; — Cisco [7], Palo Alto [9], Fortinet [10] ต่างวิ่งไปสู่เส้นชัยเดียวกันที่ NIST กำหนดไว้ ไม่มีใครมีสิทธิ์ตรวจการบ้านของตัวเอง&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;จัดงบประมาณสำหรับทดสอบประสิทธิภาพโหมด hybrid ไม่ใช่แค่เปิด feature flag&lt;/strong&gt; — ตัวเลข overhead ข้างต้นดูเล็กน้อยเมื่อแยกดู แต่สะสมเมื่อ scale การเชื่อมต่อขึ้น [11][12] และโหมด hybrid ซึ่งการย้ายระบบส่วนใหญ่จะใช้ไปอีกหลายปี มีภาระหนักกว่าทั้งสองโหมดล้วนอย่างวัดผลได้&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ใช้เส้นตายภาครัฐเป็นจุดยึดในการวางแผน ไม่ใช่การพยากรณ์ความเสี่ยง&lt;/strong&gt; — มันบอกว่าคุณต้องพร้อมเมื่อไหร่ ไม่ใช่ภัยคุกคามจะมาถึงเมื่อไหร่ [13][14] การปนกันสองอย่างนี้คือสิ่งที่เปลี่ยนโครงการโครงสร้างพื้นฐานหลายปีที่มีเหตุผลรองรับ ให้กลายเป็นการซื้อของเพราะตื่นตระหนกโดยไม่จำเป็น&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;บทวิเคราะห์ กรอบคิด และการวิจารณ์เป็นความเห็นของผู้เขียนเอง รายการแหล่งอ้างอิงทั้งหมดอยู่ด้านล่าง&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;p&gt;[1] &lt;a href="https://csrc.nist.gov/pubs/fips/203/final" rel="noopener noreferrer"&gt;https://csrc.nist.gov/pubs/fips/203/final&lt;/a&gt; — NIST FIPS 203 (ML-KEM) ฉบับสมบูรณ์&lt;br&gt;
[2] &lt;a href="https://quantumsecuritydefence.com/insights/nist-fips-standards/" rel="noopener noreferrer"&gt;https://quantumsecuritydefence.com/insights/nist-fips-standards/&lt;/a&gt; — NIST FIPS 203/204/205 เสร็จสมบูรณ์เดือนสิงหาคม 2024&lt;br&gt;
[3] &lt;a href="https://qramm.org/learn/quantum-threat-timeline.html" rel="noopener noreferrer"&gt;https://qramm.org/learn/quantum-threat-timeline.html&lt;/a&gt; — ไทม์ไลน์ CRQC: การประเมินของผู้เชี่ยวชาญ 2030-2040&lt;br&gt;
[4] &lt;a href="https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/" rel="noopener noreferrer"&gt;https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/&lt;/a&gt; — ไทม์ไลน์ CRQC ช่วง 2030-2035&lt;br&gt;
[5] &lt;a href="https://www.schneier.com/news/archives/2025/01/have-a-good-bullshit-detector-advises-computer-security-expert-bruce-schneier.html" rel="noopener noreferrer"&gt;https://www.schneier.com/news/archives/2025/01/have-a-good-bullshit-detector-advises-computer-security-expert-bruce-schneier.html&lt;/a&gt; — Schneier: ความตื่นตระหนกเรื่องควอนตัมคริปโตถูกขยายเกินจริง&lt;br&gt;
[6] &lt;a href="https://www.schneier.com/blog/archives/2023/08/you-cant-rush-post-quantum-computing-standards.html" rel="noopener noreferrer"&gt;https://www.schneier.com/blog/archives/2023/08/you-cant-rush-post-quantum-computing-standards.html&lt;/a&gt; — Schneier: cryptoagility คือสิ่งที่จำเป็นจริง&lt;br&gt;
[7] &lt;a href="https://community.cisco.com/t5/networking-knowledge-base/ios-xe-26-1-1-what-s-new-for-cisco-switching/ta-p/5545263" rel="noopener noreferrer"&gt;https://community.cisco.com/t5/networking-knowledge-base/ios-xe-26-1-1-what-s-new-for-cisco-switching/ta-p/5545263&lt;/a&gt; — Cisco IOS XE 26.1.1 PQC บน C9000 (ข้ออ้าง "เจ้าแรกในอุตสาหกรรม")&lt;br&gt;
[8] &lt;a href="https://www.pinglabz.com/post-quantum-crypto-in-cisco-campus-networks-what-operators-need-to-know/" rel="noopener noreferrer"&gt;https://www.pinglabz.com/post-quantum-crypto-in-cisco-campus-networks-what-operators-need-to-know/&lt;/a&gt; — PingLabz: การวิเคราะห์ compute overhead ของ PQC บน Cisco Campus&lt;br&gt;
[9] &lt;a href="https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/support-for-quantum-features" rel="noopener noreferrer"&gt;https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/support-for-quantum-features&lt;/a&gt; — เอกสาร PQC support ของ Palo Alto Networks&lt;br&gt;
[10] &lt;a href="https://www.fortinet.com/resources/articles/post-quantum-cryptography-preparation" rel="noopener noreferrer"&gt;https://www.fortinet.com/resources/articles/post-quantum-cryptography-preparation&lt;/a&gt; — Roadmap การเตรียม PQC ของ Fortinet&lt;br&gt;
[11] &lt;a href="https://dev.to/abraham_arellanotavara_7/choosing-between-ml-kem-and-ml-dsa-for-your-post-quantum-migration-part-2-4dip"&gt;https://dev.to/abraham_arellanotavara_7/choosing-between-ml-kem-and-ml-dsa-for-your-post-quantum-migration-part-2-4dip&lt;/a&gt; — ข้อมูล overhead ของ ML-KEM/ML-DSA จากการย้ายระบบจริง&lt;br&gt;
[12] &lt;a href="https://www.sciencedirect.com/science/article/pii/S1389128625009223" rel="noopener noreferrer"&gt;https://www.sciencedirect.com/science/article/pii/S1389128625009223&lt;/a&gt; — งานวิจัยเปรียบเทียบประสิทธิภาพ handshake แบบ post-quantum&lt;br&gt;
[13] &lt;a href="https://www.cisco.com/c/dam/en_us/solutions/networking/pqc/post-quantum-cryptography-for-dummies.pdf" rel="noopener noreferrer"&gt;https://www.cisco.com/c/dam/en_us/solutions/networking/pqc/post-quantum-cryptography-for-dummies.pdf&lt;/a&gt; — Cisco, "Post-Quantum Cryptography (PQC) For Dummies, Cisco Special Edition," Lawrence Miller, John Wiley &amp;amp; Sons, Inc., © 2026 (แหล่งต้นฉบับ)&lt;br&gt;
[14] &lt;a href="https://thequantuminsider.com/2026/07/30/nist-andrew-regenscheid-post-quantum-cryptography-transition/" rel="noopener noreferrer"&gt;https://thequantuminsider.com/2026/07/30/nist-andrew-regenscheid-post-quantum-cryptography-transition/&lt;/a&gt; — Andrew Regenscheid จาก NIST พูดถึงความเสี่ยง HNDL&lt;br&gt;
[15] &lt;a href="https://www.reddit.com/r/cybersecurity/comments/1sfushf/quantum_cryptography_and_the_harvest_now_decrypt/" rel="noopener noreferrer"&gt;https://www.reddit.com/r/cybersecurity/comments/1sfushf/quantum_cryptography_and_the_harvest_now_decrypt/&lt;/a&gt; — r/cybersecurity: ปฏิกิริยาต่อ cost-benefit ของ HNDL&lt;br&gt;
[16] &lt;a href="https://arxiv.org/abs/1905.09749" rel="noopener noreferrer"&gt;https://arxiv.org/abs/1905.09749&lt;/a&gt; — Gidney &amp;amp; Ekerå (2019), "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits"&lt;br&gt;
[18] &lt;a href="https://www.ibm.com/roadmaps/quantum/" rel="noopener noreferrer"&gt;https://www.ibm.com/roadmaps/quantum/&lt;/a&gt; — IBM Quantum Roadmap: Starling (2029, 200 logical qubits), Blue Jay (2033, 2,000 logical qubits)&lt;br&gt;
[19] &lt;a href="https://cybreplus.ncsa.or.th/news/detail/19042569" rel="noopener noreferrer"&gt;https://cybreplus.ncsa.or.th/news/detail/19042569&lt;/a&gt; — สกมช. (NCSA): นโยบาย "Quantum-Ready 2030"&lt;br&gt;
[21] &lt;a href="https://thailandedition.com/i/y2k-y2q-ncsa-urges-banks-prep-quantum-crypto-00a569bb28d0c723646eb753" rel="noopener noreferrer"&gt;https://thailandedition.com/i/y2k-y2q-ncsa-urges-banks-prep-quantum-crypto-00a569bb28d0c723646eb753&lt;/a&gt; — NCSA + ธนาคารแห่งประเทศไทย เร่งภาคธนาคารเตรียมพร้อมยุค "Y2Q"&lt;br&gt;
[22] &lt;a href="https://www.exequantum.com/insights/preparing-for-post-quantum-cryptography-migration-in-banking-four-recommendations-from-our-thai-bankers-association-presentation" rel="noopener noreferrer"&gt;https://www.exequantum.com/insights/preparing-for-post-quantum-cryptography-migration-in-banking-four-recommendations-from-our-thai-bankers-association-presentation&lt;/a&gt; — บรรทึกสรุป PQC migration ของสมาคมธนาคารไทย กรกฎาคม 2026&lt;br&gt;
[23] &lt;a href="https://siamrath.co.th/economy/technology/155933" rel="noopener noreferrer"&gt;https://siamrath.co.th/economy/technology/155933&lt;/a&gt; — วิสัยทัศน์ 5 ปี สกมช. ย้ำ "Quantum-Ready 2030"&lt;/p&gt;

</description>
      <category>security</category>
      <category>networking</category>
      <category>cisco</category>
    </item>
    <item>
      <title>Post-Quantum Cryptography: Separating the Real Deadline from the Marketing Deadline</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Fri, 25 Sep 2026 12:25:18 +0000</pubDate>
      <link>https://dev.to/supachai/post-quantum-cryptography-isnt-a-someday-problem-heres-what-changed-my-mind-5e74</link>
      <guid>https://dev.to/supachai/post-quantum-cryptography-isnt-a-someday-problem-heres-what-changed-my-mind-5e74</guid>
      <description>&lt;h2&gt;
  
  
  Post-Quantum Cryptography: Separating the Real Deadline from the Marketing Deadline
&lt;/h2&gt;

&lt;p&gt;I read Cisco's "Post-Quantum Cryptography (PQC) For Dummies" e-book [13] expecting a straightforward technical primer. It's a decent one, as far as vendor-sponsored primers go. But re-reading it with a more adversarial eye — and cross-checking its claims against independent sources — exposed a gap that matters more than the book itself. The book conflates "when should you be ready" with "when will the threat materialize." [13] Those are two very different numbers with very different levels of certainty.&lt;/p&gt;

&lt;p&gt;This is a rewrite of an earlier, more uncritical take I published on the same topic. Same subject, different lens: less "here's what convinced me," more "here's what I'd push back on if a vendor pitched me this in a meeting."&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 1: "Harvest Now, Decrypt Later" — real mechanism, oversold urgency
&lt;/h3&gt;

&lt;p&gt;The mechanics are not in dispute. NIST's own cryptography staff confirm the risk is real: organizations need to begin preparing for PQC migration because encrypted data may already face harvest-now-decrypt-later exposure [14]. That's a legitimate technical fact, not marketing spin.&lt;/p&gt;

&lt;p&gt;What's missing from most vendor narratives, including this one, is the cost-benefit calculus underneath it. Practitioner discussion in security communities shows a split reaction. Teams handling long-lived sensitive data — state secrets, IP with decades of shelf life — take HNDL seriously and are building crypto-asset inventories. Teams without that kind of data explicitly say they are not prioritizing it, because in their own words they do not hold data worth the effort of this kind of attack [15]. HNDL is a genuine threat model for a specific class of data, not a universal five-alarm fire for every organization. A book built to sell switches understandably skips that nuance.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 2: The compliance deadlines are firm — the underlying threat timeline is not
&lt;/h3&gt;

&lt;p&gt;Cisco's chapter 6 lists hard dates: 2027 for several countries' first milestones, full transitions running 2030–2035. Those dates are real; they come from published government mandates [13]. What the book does not say clearly is that nobody knows when a cryptographically relevant quantum computer (CRQC) will actually exist. Independent estimates for CRQC arrival span from an optimistic 2027–2030 to a conservative 2035–2040 or beyond [3]. A separate estimate places significant probability specifically in the 2030–2035 window, with no consensus tighter than that [4].&lt;/p&gt;

&lt;p&gt;That's a decade-plus of uncertainty on the one variable that actually determines urgency. It changes how you should read the regulatory deadlines: they are not "the quantum threat arrives in 2027." They are "regulators want you ready before an uncertain event, with a wide margin of safety." That's a defensible policy choice, but it's a risk-management deadline, not a scientific prediction — and vendor material tends to blur that distinction to manufacture urgency.&lt;/p&gt;

&lt;p&gt;There's a useful sanity check on this from the quantum hardware side itself. IBM's own public roadmap — the company actually building the machines, with no PQC product to sell — targets a 200-logical-qubit system ("Starling") for 2029, scaling to a 2,000-logical-qubit system ("Blue Jay") by 2033 [18]. The Gidney–Ekerå factoring estimate that vendor slides love to cite (breaking RSA-2048 in 8 hours) calls for roughly 20 million &lt;em&gt;noisy physical&lt;/em&gt; qubits [16] — a different unit than IBM's logical-qubit count, and easy to conflate if a chart puts both numbers side by side without saying so. Various estimates for how many &lt;em&gt;logical&lt;/em&gt; qubits Shor's algorithm actually needs cluster in the 2,000–4,000 range. If that holds, IBM's own hardware trajectory doesn't cross that threshold until around 2033 at the earliest — which lines up with the conservative end of the independent CRQC estimates above, not the optimistic end, and comes from the people with the least incentive to hype the timeline.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 2b: The Thailand angle — regulators and industry are already moving, independent of any single vendor's book
&lt;/h3&gt;

&lt;p&gt;Thailand isn't waiting for global consensus on CRQC timing either. Thailand's National Cyber Security Agency (NCSA, สกมช.) has publicly set "Quantum-Ready 2030" as a national policy pillar [19][23], and reporting from March 2026 shows the NCSA and the Bank of Thailand jointly urging the banking sector to prepare for what they're calling the "Y2Q" transition, framing it explicitly as a Y2K-style operational deadline rather than a distant research problem [21]. The Thai Bankers' Association followed up with a dedicated PQC migration briefing for the sector in July 2026 [22].&lt;/p&gt;

&lt;p&gt;That's independent corroboration, from a regulator and an industry association with no vendor affiliation, that the "start now, migrate in phases" posture isn't just Cisco's sales pitch — it's the working assumption of the institutions actually setting compliance expectations in this market. Worth noting for any technical evaluation done for a Thai enterprise audience: the regulatory clock here runs on the same 2030 marker used elsewhere globally, but it's arriving via sector-specific guidance (banking first) rather than a single blanket mandate — plan the crypto-asset inventory step accordingly, starting with whichever regulator or industry body actually governs your sector.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 3: The "just enable ML-KEM" framing skips real engineering cost
&lt;/h3&gt;

&lt;p&gt;The book presents Cisco's PQC integration — ML-KEM in IKEv2/IPsec, TLS 1.3, SSH, EAP-TLS/MACsec — as essentially a configuration toggle [13]. NIST finalized the underlying standard, FIPS 203 (ML-KEM), in August 2024 [1][2], so the cryptography itself is mature. The deployment cost is not zero, though:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ML-KEM-768 measured overhead is roughly 150 microseconds per handshake versus classical X25519 — small per connection, but it compounds at scale on high-connection-rate systems [11].&lt;/li&gt;
&lt;li&gt;Hybrid KEM configurations, which most organizations will actually run during the transition period for backward compatibility with legacy peers, incur higher handshake latency and bandwidth overhead than either pure classical or pure post-quantum KEMs alone [12].&lt;/li&gt;
&lt;li&gt;On platforms without hardware acceleration for lattice-based math, PQC operations can add measurable CPU overhead on management-plane operations at scale, not just the data plane [8].&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of this makes PQC migration a bad idea. It does mean "enable it and move on" is not an accurate description of the work. Capacity planning and hybrid-mode performance testing are real line items, and a fair technical evaluation should say so.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 4: "Cisco is first" needs a market context the book doesn't provide
&lt;/h3&gt;

&lt;p&gt;Cisco's own release notes for IOS-XE 26.1.1 describe the C9000 Smart Switch PQC implementation as an "industry-first full-stack implementation of post-quantum cryptography" [7]. That is Cisco's characterization of its own product, not an independent benchmark. Competitors are running parallel efforts on their own timelines: Palo Alto Networks publishes its own PQC feature support and migration documentation [9], and Fortinet has published its own PQC preparation roadmap [10]. Both are at a comparably early stage to Cisco's rollout. A vendor's "first" claim about its own hardware should be read as marketing copy until an independent third party validates the comparison, not taken at face value.&lt;/p&gt;

&lt;h3&gt;
  
  
  Claim 5: The one thing independent cryptographers and the vendor material actually agree on
&lt;/h3&gt;

&lt;p&gt;Bruce Schneier — no Cisco affiliation, no product to sell — makes a point that survives the marketing filter intact. Today's panic about quantum computers "breaking everything" mostly comes from people who don't understand cryptography [5]. But the actionable takeaway underneath that pushback is still real: build cryptoagility, because whatever NIST standardizes now will likely get broken or superseded sooner than anyone wants, so systems need to be able to swap algorithms without a redesign [6]. That is the one claim in the Cisco book I would keep without reservation, not because Cisco said it, but because it holds up independently of who's saying it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where that leaves a technical evaluation
&lt;/h3&gt;

&lt;p&gt;If you're doing vendor-neutral architecture planning, here's the version of this story I'd actually act on:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Inventory crypto assets by data sensitivity and shelf-life.&lt;/strong&gt; This holds regardless of CRQC timeline uncertainty [3][4], because the migration lead time itself — multi-year for anything embedded in hardware or firmware — is the real constraint, not the quantum threat's arrival date.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Treat vendor "we're first" claims as unverified until independently benchmarked.&lt;/strong&gt; Cisco [7], Palo Alto [9], and Fortinet [10] are all racing toward the same NIST-defined finish line; none of them gets to grade its own homework.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Budget for hybrid-mode performance testing, not just a feature-flag flip.&lt;/strong&gt; The overhead numbers above are individually small but compound at connection scale [11][12], and hybrid mode — which most migrations will run for years — is measurably heavier than either pure mode.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Use government deadlines as planning anchors, not risk predictions.&lt;/strong&gt; They tell you when to be ready, not when the threat arrives [13][14]. Conflating the two is exactly the move that turns a legitimate multi-year infrastructure project into unnecessary panic-buying.&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;Analysis, framing, and critique are the author's own. Full source list below.&lt;/em&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Sources
&lt;/h2&gt;

&lt;p&gt;[1] &lt;a href="https://csrc.nist.gov/pubs/fips/203/final" rel="noopener noreferrer"&gt;https://csrc.nist.gov/pubs/fips/203/final&lt;/a&gt; — NIST FIPS 203 (ML-KEM) Final&lt;br&gt;
[2] &lt;a href="https://quantumsecuritydefence.com/insights/nist-fips-standards/" rel="noopener noreferrer"&gt;https://quantumsecuritydefence.com/insights/nist-fips-standards/&lt;/a&gt; — NIST FIPS 203/204/205 finalized August 2024&lt;br&gt;
[3] &lt;a href="https://qramm.org/learn/quantum-threat-timeline.html" rel="noopener noreferrer"&gt;https://qramm.org/learn/quantum-threat-timeline.html&lt;/a&gt; — CRQC timeline: expert estimates 2030–2040&lt;br&gt;
[4] &lt;a href="https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/" rel="noopener noreferrer"&gt;https://www.encryptionconsulting.com/education-center/crqc-timelines-quantum-threat-landscape/&lt;/a&gt; — CRQC Timelines: 2030–2035 range&lt;br&gt;
[5] &lt;a href="https://www.schneier.com/news/archives/2025/01/have-a-good-bullshit-detector-advises-computer-security-expert-bruce-schneier.html" rel="noopener noreferrer"&gt;https://www.schneier.com/news/archives/2025/01/have-a-good-bullshit-detector-advises-computer-security-expert-bruce-schneier.html&lt;/a&gt; — Schneier: panic over quantum crypto is overblown&lt;br&gt;
[6] &lt;a href="https://www.schneier.com/blog/archives/2023/08/you-cant-rush-post-quantum-computing-standards.html" rel="noopener noreferrer"&gt;https://www.schneier.com/blog/archives/2023/08/you-cant-rush-post-quantum-computing-standards.html&lt;/a&gt; — Schneier: cryptoagility is the real requirement&lt;br&gt;
[7] &lt;a href="https://community.cisco.com/t5/networking-knowledge-base/ios-xe-26-1-1-what-s-new-for-cisco-switching/ta-p/5545263" rel="noopener noreferrer"&gt;https://community.cisco.com/t5/networking-knowledge-base/ios-xe-26-1-1-what-s-new-for-cisco-switching/ta-p/5545263&lt;/a&gt; — Cisco IOS XE 26.1.1 PQC on C9000 (industry-first claim)&lt;br&gt;
[8] &lt;a href="https://www.pinglabz.com/post-quantum-crypto-in-cisco-campus-networks-what-operators-need-to-know/" rel="noopener noreferrer"&gt;https://www.pinglabz.com/post-quantum-crypto-in-cisco-campus-networks-what-operators-need-to-know/&lt;/a&gt; — PingLabz: PQC compute overhead on Cisco Campus&lt;br&gt;
[9] &lt;a href="https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/support-for-quantum-features" rel="noopener noreferrer"&gt;https://docs.paloaltonetworks.com/network-security/quantum-security/administration/quantum-security-concepts/support-for-quantum-features&lt;/a&gt; — Palo Alto Networks PQC support docs&lt;br&gt;
[10] &lt;a href="https://www.fortinet.com/resources/articles/post-quantum-cryptography-preparation" rel="noopener noreferrer"&gt;https://www.fortinet.com/resources/articles/post-quantum-cryptography-preparation&lt;/a&gt; — Fortinet PQC preparation roadmap&lt;br&gt;
[11] &lt;a href="https://dev.to/abraham_arellanotavara_7/choosing-between-ml-kem-and-ml-dsa-for-your-post-quantum-migration-part-2-4dip"&gt;https://dev.to/abraham_arellanotavara_7/choosing-between-ml-kem-and-ml-dsa-for-your-post-quantum-migration-part-2-4dip&lt;/a&gt; — ML-KEM-768 overhead: ~150 microseconds/handshake&lt;br&gt;
[12] &lt;a href="https://www.sciencedirect.com/science/article/pii/S1389128625009223" rel="noopener noreferrer"&gt;https://www.sciencedirect.com/science/article/pii/S1389128625009223&lt;/a&gt; — Hybrid KEMs incur highest handshake latency/bandwidth overhead&lt;br&gt;
[13] &lt;a href="https://www.cisco.com/c/dam/en_us/solutions/networking/pqc/post-quantum-cryptography-for-dummies.pdf" rel="noopener noreferrer"&gt;https://www.cisco.com/c/dam/en_us/solutions/networking/pqc/post-quantum-cryptography-for-dummies.pdf&lt;/a&gt; — Cisco, "Post-Quantum Cryptography (PQC) For Dummies, Cisco Special Edition," Lawrence Miller, John Wiley &amp;amp; Sons, Inc., © 2026 (original source)&lt;br&gt;
[14] &lt;a href="https://thequantuminsider.com/2026/07/30/nist-andrew-regenscheid-post-quantum-cryptography-transition/" rel="noopener noreferrer"&gt;https://thequantuminsider.com/2026/07/30/nist-andrew-regenscheid-post-quantum-cryptography-transition/&lt;/a&gt; — NIST's Andrew Regenscheid on HNDL risk&lt;br&gt;
[15] &lt;a href="https://www.reddit.com/r/cybersecurity/comments/1sfushf/quantum_cryptography_and_the_harvest_now_decrypt/" rel="noopener noreferrer"&gt;https://www.reddit.com/r/cybersecurity/comments/1sfushf/quantum_cryptography_and_the_harvest_now_decrypt/&lt;/a&gt; — r/cybersecurity: HNDL cost-benefit reactions&lt;br&gt;
[16] &lt;a href="https://arxiv.org/abs/1905.09749" rel="noopener noreferrer"&gt;https://arxiv.org/abs/1905.09749&lt;/a&gt; — Gidney &amp;amp; Ekerå (2019), "How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits"&lt;br&gt;
[18] &lt;a href="https://www.ibm.com/roadmaps/quantum/" rel="noopener noreferrer"&gt;https://www.ibm.com/roadmaps/quantum/&lt;/a&gt; — IBM Quantum Roadmap: Starling (2029, 200 logical qubits), Blue Jay (2033, 2,000 logical qubits)&lt;br&gt;
[19] &lt;a href="https://cybreplus.ncsa.or.th/news/detail/19042569" rel="noopener noreferrer"&gt;https://cybreplus.ncsa.or.th/news/detail/19042569&lt;/a&gt; — Thailand NCSA (สกมช.): "Quantum-Ready 2030" policy&lt;br&gt;
[21] &lt;a href="https://thailandedition.com/i/y2k-y2q-ncsa-urges-banks-prep-quantum-crypto-00a569bb28d0c723646eb753" rel="noopener noreferrer"&gt;https://thailandedition.com/i/y2k-y2q-ncsa-urges-banks-prep-quantum-crypto-00a569bb28d0c723646eb753&lt;/a&gt; — Thailand NCSA + Bank of Thailand urge banking sector to prepare for the "Y2Q" era&lt;br&gt;
[22] &lt;a href="https://www.exequantum.com/insights/preparing-for-post-quantum-cryptography-migration-in-banking-four-recommendations-from-our-thai-bankers-association-presentation" rel="noopener noreferrer"&gt;https://www.exequantum.com/insights/preparing-for-post-quantum-cryptography-migration-in-banking-four-recommendations-from-our-thai-bankers-association-presentation&lt;/a&gt; — Thai Bankers' Association PQC migration briefing, July 2026&lt;br&gt;
[23] &lt;a href="https://siamrath.co.th/economy/technology/155933" rel="noopener noreferrer"&gt;https://siamrath.co.th/economy/technology/155933&lt;/a&gt; — NCSA 5-year vision reiterating "Quantum-Ready 2030"&lt;/p&gt;

</description>
      <category>security</category>
      <category>networking</category>
      <category>cisco</category>
      <category>cryptography</category>
    </item>
    <item>
      <title>Debugging a 6-Second JVM Death Loop: เรื่องราวการ Decompile Bytecode เพื่อหา Root Cause (ฉบับภาษาไทย)</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Thu, 24 Sep 2026 11:37:12 +0000</pubDate>
      <link>https://dev.to/supachai/debugging-a-6-second-jvm-death-loop-eruuengraawkaar-decompile-bytecode-ephuuehaa-root-cause-27o3</link>
      <guid>https://dev.to/supachai/debugging-a-6-second-jvm-death-loop-eruuengraawkaar-decompile-bytecode-ephuuehaa-root-cause-27o3</guid>
      <description>&lt;h2&gt;
  
  
  อาการที่พบ
&lt;/h2&gt;

&lt;p&gt;Secondary server ใน High Availability (HA) failover cluster ตายซ้ำๆ ไม่ใช่แบบ crash เสียงดัง แต่ตาย &lt;em&gt;เงียบๆ&lt;/em&gt; ทุกครั้งหลัง startup ประมาณ 6-7 วินาที พร้อม log message ที่ไม่บอกอะไรเลย:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;System going to Shutdown --- received process interrupt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;ไม่มี stack trace ไม่มี exception ไม่มีเบาะแสว่า &lt;em&gt;ทำไม&lt;/em&gt; แค่... หายไป&lt;/p&gt;

&lt;p&gt;นี่คือเรื่องราวว่าผม trace ข้อความนี้ลึกลงไปจนเจอ PostgreSQL configuration parameter ตัวเดียว — ด้วยการ decompile Java bytecode ของ vendor เอง หลังจากเอกสาร, log, และ community forum ทั้งหมดไม่มีคำตอบให้เลย&lt;/p&gt;

&lt;h2&gt;
  
  
  จุดเริ่มต้น
&lt;/h2&gt;

&lt;p&gt;ผมกำลังสร้าง proof-of-concept สำหรับฟีเจอร์ HA failover ของ network monitoring product เชิงพาณิชย์ตัวหนึ่ง ทดสอบโครงสร้างแบบ 3-VM ที่เบากว่ามาตรฐาน 4-VM ที่ vendor แนะนำ:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;VM 1&lt;/strong&gt;: Primary application server&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;VM 2&lt;/strong&gt;: Secondary application server (ตัวที่ตายซ้ำๆ)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;VM 3&lt;/strong&gt;: PostgreSQL database + shared filesystem host รวมเครื่องเดียวกัน&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;ไม่มีอะไรแปลกใหม่ เป็น failover pattern มาตรฐาน เอกสารของ vendor ไม่ได้ห้ามการรวม role DB กับ shared-folder ไว้เครื่องเดียวกันอย่างชัดเจน ผมเลยสร้างแบบนี้เพื่อลด deployment footprint&lt;/p&gt;

&lt;p&gt;Primary server ทำงานสมบูรณ์แบบ แต่ Secondary ไม่ยอมอยู่รอด&lt;/p&gt;

&lt;h2&gt;
  
  
  รอบที่ 1: ผู้ต้องสงสัยที่ชัดเจน (ผิดหมด)
&lt;/h2&gt;

&lt;p&gt;ผมไล่ตรวจ hypothesis ระดับ config ทุกตัวที่นึกออก และเจอ &lt;em&gt;สิ่งที่พังจริงๆ 4 อย่าง&lt;/em&gt; ระหว่างทาง — ไม่มีตัวไหนเป็นสาเหตุจริงเลย:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;โฟลเดอร์ config หายไป&lt;/strong&gt; (&lt;code&gt;pgsql/ext_conf/&lt;/code&gt;) ที่ถูก exclude จากการ replication ระหว่างเซิร์ฟเวอร์อย่างเงียบๆ ทำให้เกิด &lt;code&gt;FileOutputStream&lt;/code&gt; error ลึกใน startup utility class&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Database superuser ไม่มี password ตั้งไว้&lt;/strong&gt; ขณะที่ encrypted credential file คาดหวังว่ามี — เป็นความคลาดเคลื่อนคลาสสิกระหว่าง "config บอกว่ายังไง" กับ "database มีจริงอะไร"&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;แถวหายไปในตาราง server-status tracking&lt;/strong&gt; — secondary node ไม่เคยลงทะเบียนตัวเอง ทำให้ internal health check หาอะไรมารายงานไม่ได้เลย&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ลำดับ startup script ผิด&lt;/strong&gt; — script "prerequisite verification" ถูกใช้เสมือนว่ามัน &lt;em&gt;ทำการ activate&lt;/em&gt; ทั้งที่จริงๆ ต้องรัน &lt;em&gt;ก่อน&lt;/em&gt; main service launcher ไม่ใช่รันแทน&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;ผมแก้ครบทั้ง 4 จุด Secondary ยังคงตายที่จุด 6-7 วินาทีเหมือนเดิม ทุกครั้ง&lt;/p&gt;

&lt;h2&gt;
  
  
  รอบที่ 2: อินเทอร์เน็ตไม่มีคำตอบ
&lt;/h2&gt;

&lt;p&gt;ถึงจุดนี้ผมทำสิ่งที่ engineer ที่มีเหตุผลควรทำ — ไปหา prior art Community forum ของ vendor, เอกสาร HA/failover ทางการ, แม้แต่เอกสารของ product พี่น้องที่สร้างบน framework เดียวกัน&lt;/p&gt;

&lt;p&gt;ยืนยันได้ 1 อย่างที่มีประโยชน์: "received process interrupt" เป็น &lt;strong&gt;ข้อความ generic จาก Java Service Wrapper&lt;/strong&gt; (ตัว process supervisor ที่ห่อ JVM ไว้) — มันจะขึ้นทุกครั้งที่ JVM exit ไม่ว่าจะเป็นจากการเรียก &lt;code&gt;System.exit()&lt;/code&gt; แบบ clean หรือจาก uncaught exception มันไม่ใช่ error code เฉพาะของ product เปรียบเทียบง่ายๆ คือมันเหมือนการยักไหล่ของซอฟต์แวร์&lt;/p&gt;

&lt;p&gt;ไม่พบ precedent สำหรับ symptom ชุดนี้เลย ถึงเวลาต้องลึกกว่า log แล้ว&lt;/p&gt;

&lt;h2&gt;
  
  
  รอบที่ 3: ตาราง Database ผิดตัว
&lt;/h2&gt;

&lt;p&gt;ผมขยายการตรวจสอบ database ให้กว้างกว่าตารางที่ error message พูดถึง และเจอ 2 ตารางที่ startup code อ่านจริงๆ ซึ่งไม่เคยพิจารณามาก่อน:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;ตารางหนึ่งเก็บ &lt;strong&gt;สถานะการลงทะเบียน node&lt;/strong&gt; — มี 0 แถวสำหรับ secondary หมายความว่ามันไม่เคยบอก cluster สำเร็จว่า "ฉันมีอยู่จริง"&lt;/li&gt;
&lt;li&gt;อีกตารางเก็บ &lt;strong&gt;path configuration ของ shared folder&lt;/strong&gt; — ยังชี้ไปค่าเก่าจากโครงสร้างทดสอบก่อนหน้า ไม่เคยอัปเดตแม้จะแก้ config file ไปหลายรอบแล้ว&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;ผมแก้ทั้งสองตรงในฐานข้อมูลเลย Secondary ตายที่จุด 6-7 วินาทีเดิมเป๊ะ ข้อความเดิม ไม่เปลี่ยนแปลงอะไรเลย&lt;/p&gt;

&lt;p&gt;ตอนนั้นเองที่ผมรู้ว่ากำลัง debug ผิด layer ไปทั้งหมด&lt;/p&gt;

&lt;h2&gt;
  
  
  รอบที่ 4: Decompile โค้ดของ Vendor เอง
&lt;/h2&gt;

&lt;p&gt;เมื่อ error output ของ vendor ไม่บอกอะไรเลย และเอกสารสาธารณะก็ไม่มีคำตอบ เหลือที่เดียวที่มีคำตอบจริง: ตัว compiled code เอง&lt;/p&gt;

&lt;p&gt;ผมดาวน์โหลด &lt;a href="https://github.com/leibnitz27/cfr" rel="noopener noreferrer"&gt;CFR&lt;/a&gt; ซึ่งเป็น open-source Java decompiler ที่ใช้งานได้ดี มาลงตรงบน VM แล้วชี้มันไปที่ JAR file ของ product เองโดยใช้ JRE ที่ bundle มาด้วย:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;java &lt;span class="nt"&gt;-jar&lt;/span&gt; cfr.jar SomeVendorClasses.jar &lt;span class="nt"&gt;--outputdir&lt;/span&gt; /tmp/decompiled
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;จากนั้นเริ่ม trace call chain ของ startup จริงๆ ด้วยการอ่าน source code จริง แทนที่จะเดาจาก log:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;StartupHooks.preStartServer()
  → StartupCheckHandler.doPreCheck()
  → Preprocessor.initialize(coldStart)
      → moduleInit()          [ตัดออก — log marker ไม่เคยปรากฏเลย]
      → StartupCheckHandler.doDBMemoryCheck()
          → sqlChecks()       [ตัดออก — return true ทันทีสำหรับ DB type นี้]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;ผม trace ผ่าน 5 class แยกกันใน 3 JAR ที่ต่างกัน ทุก code path ที่เกี่ยวกับ Failover ที่ผมหาเจอ &lt;strong&gt;ไม่มี log evidence ว่าเคยรันเลยสักครั้ง&lt;/strong&gt; บน secondary ที่ล้มเหลว ไม่ใช่ "รันแล้วล้มเหลว" แต่ &lt;em&gt;ไม่เคยถูกรันเลย&lt;/em&gt; ซึ่งหมายความว่า JVM ตายก่อนที่จะไปถึง HA-specific logic ใดๆ ที่ผมใช้เวลาหลายวันไล่ตามเลย&lt;/p&gt;

&lt;p&gt;นั่นทำให้ผมหันไปมองอะไรที่พื้นฐานกว่ามาก: การ bootstrap connection pool&lt;/p&gt;

&lt;h2&gt;
  
  
  สาเหตุที่แท้จริง
&lt;/h2&gt;

&lt;p&gt;การอ่าน raw stderr log แบบเต็ม (ไม่ใช่ application-level log ที่เคยเช็ค) เจอสิ่งนี้:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Could not instantiate RelationalAPI in NmsUtil. Server quitting
Check for the NmsStorageException :
CreateConnectionException
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;การ grep decompiled source หา string นี้ตรงๆ พาผมไปเจอ method ที่รับผิดชอบทันที: &lt;code&gt;catch&lt;/code&gt; block ที่ห่อรอบการสร้าง database connection pool ซึ่ง — เมื่อล้มเหลว — จะ log ข้อความ generic นี้แล้วเรียก &lt;code&gt;System.exit(1)&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Secondary กำลังตายระหว่างการทำงานพื้นฐานที่สุดเท่าที่จะเป็นไปได้: การพยายามเปิด database connection pool ของตัวเอง&lt;/strong&gt; ก่อน failover logic ใดๆ ก่อนการลงทะเบียน node ใดๆ ก่อนทุกอย่างที่ผมใช้เวลา debug มา 4 รอบ&lt;/p&gt;

&lt;p&gt;แล้วทำไม connection pool creation ถึงล้มเหลว?&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SHOW&lt;/span&gt; &lt;span class="n"&gt;max_connections&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="c1"&gt;-- 100&lt;/span&gt;

&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;pg_stat_activity&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="c1"&gt;-- 57 (ทั้งหมดมาจาก primary server)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Connection pool ของ secondary ถูกตั้งค่าให้ขอ &lt;strong&gt;50 connections&lt;/strong&gt; ตอน startup — เท่ากับ primary Primary ใช้ไปแล้ว 57 &lt;code&gt;57 + 50 = 107&lt;/code&gt; เทียบกับเพดานที่ 100&lt;/p&gt;

&lt;p&gt;Connection pool creation ของ secondary ล้มเหลว exception handler แบบ generic จับมันไว้ log ข้อความที่ไม่ให้เบาะแสอะไรเลยเกี่ยวกับสาเหตุจริง แล้วฆ่า JVM ตัว process supervisor รายงานสิ่งนี้เป็น "received process interrupt" — ข้อความที่ generic มากจนพาผมหลงทางไปหลายวัน&lt;/p&gt;

&lt;h2&gt;
  
  
  วิธีแก้
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo sed&lt;/span&gt; &lt;span class="nt"&gt;-i&lt;/span&gt; &lt;span class="s1"&gt;'s/max_connections = 100/max_connections = 250/'&lt;/span&gt; /etc/postgresql/17/main/postgresql.conf
&lt;span class="nb"&gt;sudo &lt;/span&gt;systemctl restart postgresql
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Secondary start สำเร็จตั้งแต่ครั้งแรกหลังจากนี้ ยืนยันผ่าน audit log ของ application เอง:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;The service is now in standby mode.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;4 รอบของการแก้ไขที่ถูกต้องแต่ผิดจุด และสาเหตุจริงคือค่า configuration default ตัวเดียวที่ไม่เคย scale เกินกว่า connection pool เดียว&lt;/p&gt;

&lt;h2&gt;
  
  
  ทำไมถึงใช้เวลานานขนาดนี้
&lt;/h2&gt;

&lt;p&gt;มีหลายอย่างที่ซ้อนกันทำให้เรื่องนี้ยากผิดปกติ:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Error message ไม่มีข้อมูลการวินิจฉัยเลย&lt;/strong&gt; ข้อความระดับ wrapper แบบ generic บดบัง exception ระดับ application ซึ่งบดบัง exception ระดับ database ซึ่งบดบังสาเหตุจริง&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log ทั้งหมดที่มีอยู่เป็น downstream ของความล้มเหลวจริง&lt;/strong&gt; มันไม่ได้พัง — มันแค่เป็น log ของ code ที่ไม่เคยมีโอกาสรันเลย&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Message field ของ exception เองว่างเปล่า&lt;/strong&gt; มีแค่ &lt;em&gt;ชื่อ class ของ exception&lt;/em&gt; ในบรรทัด log ถัดไปที่ให้เบาะแสที่ใช้ได้ — ที่เหลือคือความเงียบ&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;บั๊กนี้ขึ้นอยู่กับ topology ไม่ใช่ product defect&lt;/strong&gt; Deployment แบบ single-server หรือ deployment ที่ size ถูกต้องตั้งแต่วันแรก จะไม่มีทางเจอสิ่งนี้เลย มันจะปรากฏก็ต่อเมื่อมีการเพิ่ม connection pool ขนาดเต็มตัวที่สองเข้าไปกับ database ที่ capacity ไม่เคยถูกวางแผนใหม่สำหรับ consumer 2 ตัว&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  บทเรียนที่ใหญ่กว่า
&lt;/h2&gt;

&lt;p&gt;ถ้าคุณกำลังรัน HA/failover setup ใดๆ กับ PostgreSQL และ &lt;code&gt;max_connections&lt;/code&gt; ของ database ถูกปล่อยไว้ที่ default 100 ให้คำนวณเลขก่อนเพิ่ม node ตัวที่สอง:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;required = (primary pool size) + (secondary pool size) + headroom
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Connection pool ของ application ส่วนใหญ่ default อยู่ในช่วง 20-50 เซิร์ฟเวอร์สองตัวที่ชี้ไปยัง database เดียวกันสามารถเผาผลาญ default ของ PostgreSQL ได้เร็วอย่างน่าอาย — และรูปแบบความล้มเหลวที่คุณจะเห็นแทบไม่เคยพูดถึง &lt;code&gt;max_connections&lt;/code&gt; ตรงๆ เลย&lt;/p&gt;

&lt;p&gt;และในภาพกว้างกว่านั้น: เมื่อ error output ของ vendor ไม่มีข้อมูลจริงๆ และการค้นหาสาธารณะไม่พบอะไรเลย การ decompile compiled classes ของ vendor เอง (เพื่อวัตถุประสงค์ diagnostic ไม่ใช่การหลีกเลี่ยง license) เป็นทางเลือก escalation ที่ legitimate มันพาผมจาก "4 การแก้ไขที่ดูเป็นไปได้แต่ผิด ไม่มีทางออก" ไปสู่ "สาเหตุที่แท้จริง วัดผลได้ แก้สำเร็จตั้งแต่ retry ครั้งแรก" — เร็วกว่าการรอ support ticket แม้ว่า vendor support ยังคงเป็นทางเลือกที่ถูกต้องเมื่อคุณไม่มีเวลาหรือเครื่องมือที่จะลึกขนาดนี้&lt;/p&gt;




&lt;h2&gt;
  
  
  Diagram: เส้นทางการสืบสวน (Investigation Funnel)
&lt;/h2&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TD
    A["🔴 อาการ: JVM ตายทุก 6-7 วินาที&amp;lt;br/&amp;gt;'received process interrupt'"] --&amp;gt; B["รอบ 1: Config-level fixes&amp;lt;br/&amp;gt;4 บั๊กจริง แก้หมดแล้ว"]
    B --&amp;gt;|"ยังตายเหมือนเดิม"| C["รอบ 2: Deep research สาธารณะ&amp;lt;br/&amp;gt;ยืนยัน: เป็น generic wrapper message"]
    C --&amp;gt;|"ไม่พบ precedent"| D["รอบ 3: DB tables ที่ถูกต้อง&amp;lt;br/&amp;gt;fosnodedetails, fosparams"]
    D --&amp;gt;|"ยังตายเหมือนเดิม"| E["รอบ 4: Decompile bytecode ด้วย CFR&amp;lt;br/&amp;gt;Trace call chain จริง 5 classes"]
    E --&amp;gt; F["🎯 พบ: JVM ตายก่อนถึง&amp;lt;br/&amp;gt;Failover logic ใดๆ เลย"]
    F --&amp;gt; G["อ่าน raw stderr log แบบเต็ม"]
    G --&amp;gt; H["🎯 Root Cause: CreateConnectionException&amp;lt;br/&amp;gt;PostgreSQL max_connections หมด"]
    H --&amp;gt; I["✅ Fix: max_connections 100→250&amp;lt;br/&amp;gt;Secondary start สำเร็จทันที"]

    style A fill:#ff6b6b,color:#fff
    style H fill:#51cf66,color:#fff
    style I fill:#51cf66,color:#fff&lt;/code&gt;&lt;/pre&gt;



&lt;h2&gt;
  
  
  Diagram: Call Chain ที่ Trace ได้จากการ Decompile
&lt;/h2&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart LR
    A[StartupHooks&amp;lt;br/&amp;gt;preStartServer] --&amp;gt; B[StartupCheckHandler&amp;lt;br/&amp;gt;doPreCheck]
    B --&amp;gt; C[Preprocessor&amp;lt;br/&amp;gt;initialize coldStart]
    C --&amp;gt; D["moduleInit()&amp;lt;br/&amp;gt;❌ ตัดออก - log ไม่ปรากฏ"]
    C --&amp;gt; E[StartupCheckHandler&amp;lt;br/&amp;gt;doDBMemoryCheck]
    E --&amp;gt; F["sqlChecks()&amp;lt;br/&amp;gt;❌ ตัดออก - return true ทันที"]
    C -.-&amp;gt;|"JVM ตายก่อนถึงจุดนี้"| G["Connection Pool&amp;lt;br/&amp;gt;Bootstrap"]
    G --&amp;gt; H["🎯 CreateConnectionException&amp;lt;br/&amp;gt;max_connections หมด"]

    style D fill:#868e96,color:#fff
    style F fill:#868e96,color:#fff
    style G fill:#ffd43b,color:#000
    style H fill:#ff6b6b,color:#fff&lt;/code&gt;&lt;/pre&gt;






&lt;p&gt;&lt;em&gt;เครื่องมือที่ใช้: &lt;a href="https://github.com/leibnitz27/cfr" rel="noopener noreferrer"&gt;CFR decompiler&lt;/a&gt; v0.152, PostgreSQL 17, Linux server tooling มาตรฐาน ไม่มีชื่อ vendor เฉพาะเจาะจงในบทความนี้โดยตั้งใจ — pattern นี้ generalize ได้กับ Java-based HA product ใดๆ ที่ใช้ PostgreSQL เป็น backend&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;บทความนี้เป็นฉบับแปลไทยของ &lt;a href="https://dev.to/supachai/debugging-a-6-second-jvm-death-loop-a-bytecode-decompilation-story-5dfo"&gt;Debugging a 6-Second JVM Death Loop: A Bytecode Decompilation Story&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>postgres</category>
      <category>java</category>
      <category>debugging</category>
      <category>thai</category>
    </item>
    <item>
      <title>Debugging a 6-Second JVM Death Loop: A Bytecode Decompilation Story</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Thu, 24 Sep 2026 04:01:50 +0000</pubDate>
      <link>https://dev.to/supachai/debugging-a-6-second-jvm-death-loop-a-bytecode-decompilation-story-5dfo</link>
      <guid>https://dev.to/supachai/debugging-a-6-second-jvm-death-loop-a-bytecode-decompilation-story-5dfo</guid>
      <description>&lt;h2&gt;
  
  
  The Symptom
&lt;/h2&gt;

&lt;p&gt;A secondary server in a High Availability (HA) failover cluster kept dying. Not crashing loudly — dying &lt;em&gt;quietly&lt;/em&gt;, exactly 6-7 seconds after every startup attempt, with a log message that told me absolutely nothing:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;System going to Shutdown --- received process interrupt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;No stack trace. No exception. No hint about &lt;em&gt;why&lt;/em&gt;. Just... gone.&lt;/p&gt;

&lt;p&gt;This is the story of how I traced that message all the way down to a single PostgreSQL configuration parameter — by decompiling the vendor's own Java bytecode when documentation, logs, and community forums all came up empty.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Setup
&lt;/h2&gt;

&lt;p&gt;I was building a proof-of-concept for a commercial network monitoring product's HA failover feature, testing a leaner 3-VM topology instead of the vendor's standard 4-VM recommendation:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;VM 1&lt;/strong&gt;: Primary application server&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;VM 2&lt;/strong&gt;: Secondary application server (the one that kept dying)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;VM 3&lt;/strong&gt;: Combined PostgreSQL database + shared filesystem host&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Nothing exotic. Standard failover pattern. The vendor's docs didn't explicitly forbid combining the DB and shared-folder roles on one VM, so I built it that way to reduce the deployment footprint.&lt;/p&gt;

&lt;p&gt;The primary server worked flawlessly. The secondary would not stay alive.&lt;/p&gt;

&lt;h2&gt;
  
  
  Round 1: The Obvious Suspects (all wrong)
&lt;/h2&gt;

&lt;p&gt;I worked through every config-level hypothesis I could think of, and found four &lt;em&gt;genuinely broken things&lt;/em&gt; along the way — none of which were the actual problem:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;A missing config directory&lt;/strong&gt; (&lt;code&gt;pgsql/ext_conf/&lt;/code&gt;) that got silently excluded from server-to-server replication, causing a &lt;code&gt;FileOutputStream&lt;/code&gt; error deep in a startup utility class.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A database superuser with no password set&lt;/strong&gt;, while the encrypted credential file expected one — classic drift between "what the config says" and "what the database actually has."&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A missing row in a server-status tracking table&lt;/strong&gt; — the secondary node had never registered itself, so an internal health check found literally nothing to report on.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Wrong startup script order&lt;/strong&gt; — a "prerequisite verification" script was being treated as if it &lt;em&gt;performed&lt;/em&gt; activation, when it was actually meant to run &lt;em&gt;before&lt;/em&gt; the main service launcher, not instead of it.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;I fixed all four. The secondary still died at the 6-7 second mark, every single time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Round 2: The Internet Has Nothing
&lt;/h2&gt;

&lt;p&gt;At this point I did what any reasonable engineer does — I went looking for prior art. Vendor community forums, official HA/failover documentation, even documentation for a sibling product built on the same underlying framework.&lt;/p&gt;

&lt;p&gt;I confirmed one useful thing: "received process interrupt" is a &lt;strong&gt;generic message from the Java Service Wrapper&lt;/strong&gt; (the process supervisor wrapping the JVM) — it fires on &lt;em&gt;any&lt;/em&gt; JVM exit, whether from a clean &lt;code&gt;System.exit()&lt;/code&gt; call or an uncaught exception. It's not a product-specific error code. It's the software equivalent of a shrug.&lt;/p&gt;

&lt;p&gt;I found zero precedent for my exact combination of symptoms. Time to go deeper than logs.&lt;/p&gt;

&lt;h2&gt;
  
  
  Round 3: Wrong Database Tables
&lt;/h2&gt;

&lt;p&gt;I widened my database inspection beyond the tables mentioned in visible error messages, and found two tables the startup code actually reads that I hadn't considered:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;One tracking &lt;strong&gt;node registration status&lt;/strong&gt; — had zero rows for the secondary, meaning it had never successfully told the cluster "I exist."&lt;/li&gt;
&lt;li&gt;One holding the &lt;strong&gt;shared folder path configuration&lt;/strong&gt; — still pointing at a stale value from an earlier test topology, never updated despite multiple rounds of config-file fixes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I fixed both directly in the database. The secondary died at the exact same 6-7 second mark. Same message. No change whatsoever.&lt;/p&gt;

&lt;p&gt;That's when I knew I was debugging the wrong layer entirely.&lt;/p&gt;

&lt;h2&gt;
  
  
  Round 4: Decompiling the Vendor's Own Code
&lt;/h2&gt;

&lt;p&gt;When a vendor's error output tells you nothing, and public documentation has nothing, there's one place left with the actual answer: the compiled code itself.&lt;/p&gt;

&lt;p&gt;I downloaded &lt;a href="https://github.com/leibnitz27/cfr" rel="noopener noreferrer"&gt;CFR&lt;/a&gt;, a solid open-source Java decompiler, straight onto the VM, and pointed it at the product's own JAR files using its bundled JRE:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;java &lt;span class="nt"&gt;-jar&lt;/span&gt; cfr.jar SomeVendorClasses.jar &lt;span class="nt"&gt;--outputdir&lt;/span&gt; /tmp/decompiled
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then I started tracing the actual startup call chain by reading real source code instead of guessing from logs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;StartupHooks.preStartServer()
  → StartupCheckHandler.doPreCheck()
  → Preprocessor.initialize(coldStart)
      → moduleInit()          [ruled out — its log markers never appeared]
      → StartupCheckHandler.doDBMemoryCheck()
          → sqlChecks()       [ruled out — returns true immediately for this DB type]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;I traced through five separate classes across three different JARs. Every single Failover-specific code path I could find had &lt;strong&gt;zero log evidence of ever running&lt;/strong&gt; on the failing secondary. Not "ran and failed" — &lt;em&gt;never executed at all&lt;/em&gt;. Which meant the JVM was dying before it ever reached any of the HA-specific logic I'd spent days chasing.&lt;/p&gt;

&lt;p&gt;That redirected me somewhere much more basic: connection pool bootstrap.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Actual Root Cause
&lt;/h2&gt;

&lt;p&gt;A full read of the raw stderr log (not the application-level logs I'd been checking) turned up this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Could not instantiate RelationalAPI in NmsUtil. Server quitting
Check for the NmsStorageException :
CreateConnectionException
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Grepping the decompiled source for that exact string led me straight to the responsible method: a &lt;code&gt;catch&lt;/code&gt; block wrapped around database connection pool creation, which — on failure — logs this generic message and calls &lt;code&gt;System.exit(1)&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The secondary was dying during the most basic operation possible: trying to open its own database connection pool.&lt;/strong&gt; Before any failover logic. Before any node registration. Before anything I'd spent four rounds of debugging on.&lt;/p&gt;

&lt;p&gt;So why would connection pool creation fail?&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SHOW&lt;/span&gt; &lt;span class="n"&gt;max_connections&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="c1"&gt;-- 100&lt;/span&gt;

&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;count&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;pg_stat_activity&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="c1"&gt;-- 57 (all from the primary server)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The secondary's connection pool was configured to request &lt;strong&gt;50 connections&lt;/strong&gt; on startup — same as the primary. The primary was already using 57. &lt;code&gt;57 + 50 = 107&lt;/code&gt;, against a ceiling of 100.&lt;/p&gt;

&lt;p&gt;The secondary's connection pool creation failed. The generic exception handler caught it, logged a message that gave no hint of the actual cause, and killed the JVM. The process supervisor reported this as "received process interrupt" — a message so generic it actively pointed me in the wrong direction for days.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Fix
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo sed&lt;/span&gt; &lt;span class="nt"&gt;-i&lt;/span&gt; &lt;span class="s1"&gt;'s/max_connections = 100/max_connections = 250/'&lt;/span&gt; /etc/postgresql/17/main/postgresql.conf
&lt;span class="nb"&gt;sudo &lt;/span&gt;systemctl restart postgresql
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The secondary started on the first attempt after this. Verified through the application's own audit log:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;The service is now in standby mode.
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Four rounds of legitimate-but-wrong fixes, and the actual cause was a single default configuration value that never scales past one connection pool.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why This Took So Long
&lt;/h2&gt;

&lt;p&gt;A few things stacked up to make this unusually hard:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;The error message carried zero diagnostic information.&lt;/strong&gt; A generic wrapper-level message masked an application-level exception, which masked a database-level exception, which masked the real cause.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;All my available logs were downstream of the actual failure.&lt;/strong&gt; They weren't broken — they were just logs for code that never got a chance to run.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The exception's own message field was empty.&lt;/strong&gt; Only the &lt;em&gt;exception class name&lt;/em&gt; in the following log line gave a usable clue — everything else was silence.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The bug is topology-dependent, not a product defect.&lt;/strong&gt; A single-server deployment, or a properly-sized deployment from day one, would never hit this. It only surfaces the moment a second full-size connection pool gets added against a database whose capacity was never re-planned for two consumers.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  The Bigger Lesson
&lt;/h2&gt;

&lt;p&gt;If you're running &lt;em&gt;any&lt;/em&gt; HA/failover setup against PostgreSQL, and your database's &lt;code&gt;max_connections&lt;/code&gt; was left at the default 100, do the arithmetic before you add that second node:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;required = (primary pool size) + (secondary pool size) + headroom
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Most application connection pools default to something in the 20-50 range. Two servers pointed at one database can burn through the PostgreSQL default embarrassingly fast — and the failure mode you'll see almost never mentions &lt;code&gt;max_connections&lt;/code&gt; directly.&lt;/p&gt;

&lt;p&gt;And more generally: when a vendor's error output is genuinely uninformative, and public search turns up nothing, decompiling the vendor's own compiled classes (for diagnostic purposes, not license circumvention) is a legitimate escalation path. It took me from "four plausible-but-wrong fixes and no resolution" to "exact root cause, quantified, fixed on the first retry" — faster than waiting on a support ticket, though vendor support is still the right call when you don't have the time or tooling to go this deep.&lt;/p&gt;







&lt;h2&gt;
  
  
  Diagram: The Investigation Funnel
&lt;/h2&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart TD
    A["🔴 Symptom: JVM dies every 6-7 seconds&amp;lt;br/&amp;gt;'received process interrupt'"] --&amp;gt; B["Round 1: Config-level fixes&amp;lt;br/&amp;gt;4 real bugs found and fixed"]
    B --&amp;gt;|"Still dies the same way"| C["Round 2: Deep public research&amp;lt;br/&amp;gt;Confirmed: generic wrapper message"]
    C --&amp;gt;|"No precedent found"| D["Round 3: Correct DB tables&amp;lt;br/&amp;gt;fosnodedetails, fosparams"]
    D --&amp;gt;|"Still dies the same way"| E["Round 4: Decompile bytecode with CFR&amp;lt;br/&amp;gt;Trace real call chain across 5 classes"]
    E --&amp;gt; F["🎯 Found: JVM dies before reaching&amp;lt;br/&amp;gt;any Failover-specific logic"]
    F --&amp;gt; G["Read the raw stderr log in full"]
    G --&amp;gt; H["🎯 Root Cause: CreateConnectionException&amp;lt;br/&amp;gt;PostgreSQL max_connections exhausted"]
    H --&amp;gt; I["✅ Fix: max_connections 100→250&amp;lt;br/&amp;gt;Secondary starts on first retry"]

    style A fill:#ff6b6b,color:#fff
    style H fill:#51cf66,color:#fff
    style I fill:#51cf66,color:#fff&lt;/code&gt;&lt;/pre&gt;



&lt;h2&gt;
  
  
  Diagram: The Call Chain Traced From Decompiled Source
&lt;/h2&gt;



&lt;pre data-lang="mermaid"&gt;&lt;code&gt;flowchart LR
    A[StartupHooks&amp;lt;br/&amp;gt;preStartServer] --&amp;gt; B[StartupCheckHandler&amp;lt;br/&amp;gt;doPreCheck]
    B --&amp;gt; C[Preprocessor&amp;lt;br/&amp;gt;initialize coldStart]
    C --&amp;gt; D["moduleInit()&amp;lt;br/&amp;gt;❌ Ruled out - log never appeared"]
    C --&amp;gt; E[StartupCheckHandler&amp;lt;br/&amp;gt;doDBMemoryCheck]
    E --&amp;gt; F["sqlChecks()&amp;lt;br/&amp;gt;❌ Ruled out - returns true immediately"]
    C -.-&amp;gt;|"JVM dies before reaching this point"| G["Connection Pool&amp;lt;br/&amp;gt;Bootstrap"]
    G --&amp;gt; H["🎯 CreateConnectionException&amp;lt;br/&amp;gt;max_connections exhausted"]

    style D fill:#868e96,color:#fff
    style F fill:#868e96,color:#fff
    style G fill:#ffd43b,color:#000
    style H fill:#ff6b6b,color:#fff&lt;/code&gt;&lt;/pre&gt;



&lt;p&gt;&lt;em&gt;Tools used: &lt;a href="https://github.com/leibnitz27/cfr" rel="noopener noreferrer"&gt;CFR decompiler&lt;/a&gt; v0.152, PostgreSQL 17, standard Linux server tooling. No proprietary vendor names in this writeup by design — the pattern generalizes to any Java-based HA product backed by PostgreSQL.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>postgres</category>
      <category>java</category>
      <category>debugging</category>
      <category>sysadmin</category>
    </item>
    <item>
      <title>[AI-100.EP1] - Introduction to AI.</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Sat, 06 Jan 2024 15:25:55 +0000</pubDate>
      <link>https://dev.to/supachai/ai-100ep1-introduction-to-ai-l31</link>
      <guid>https://dev.to/supachai/ai-100ep1-introduction-to-ai-l31</guid>
      <description>&lt;h2&gt;
  
  
  Introduction to AI (Artificial Intelligence)
&lt;/h2&gt;

&lt;p&gt;การมาของ Artificial Intelligence (AI) นั้น ช่วยให้เราสร้างโปรแกรมหรือซอฟต์แวร์ที่น่าสนใจและไม่คิดว่าจะสามารถทำได้ เช่น การปรับปรุงการดูแลสุขภาพ, ช่วยให้ผู้คนเอาชนะความด้อยโอกาสทางกายภาพ, เสริมสร้างโครงสร้างพื้นฐาน(Infrastcture) ที่ฉลาดขึ้น, สร้างประสบการณ์ใหม่ๆ ด้านความบันเทิงต่างๆ และแม้แต่ช่วยโลกของเรา!&lt;/p&gt;

&lt;h3&gt;
  
  
  AI คืออะไร ?
&lt;/h3&gt;

&lt;p&gt;ให้เข้าใจง่ายๆ, AI คือ โปรแกรมหรือซอฟแวร์ที่เลียนแบบพฤติกรรมและความสามารถต่างๆ ของมนุษย์ &lt;/p&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--fEwAKBmU--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/od6ccx3osxttyk6j1quq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--fEwAKBmU--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/od6ccx3osxttyk6j1quq.png" alt="Robot and Baby" width="800" height="457"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ปัญญาประดิษฐ์ (Artificial Intelligence, AI)&lt;/strong&gt; คือสาขาวิชาในด้านวิทยาการคอมพิวเตอร์ที่เน้นการพัฒนาคอมพิวเตอร์หรือเครื่องมือคอมพิวเตอร์ให้สามารถทำงานหรือปฏิบัติการที่ต้องการความคิดและความสามารถคล้ายมนุษย์ได้ โดยคอมพิวเตอร์ในระบบ AI จะถูกออกแบบและโปรแกรมให้สามารถประมวลผลข้อมูล, ตัดสินใจ, แก้ปัญหา, และเรียนรู้จากข้อมูลด้วยตัวเองโดยอัตโนมัติ โดยไม่ต้องมีคำสั่งทางโปรแกรมเฉพาะหรือกฎระเบียบที่กำหนดไว้ล่วงหน้า. AI มีการนำไปใช้ในหลายด้านของชีวิตประจำวันและอุตสาหกรรมต่าง ๆ เช่น ระบบค้นหาบนเว็บ, รถยนต์ขับเอง, การแก้ปัญหาทางการแพทย์, การทำงานในสายงานการเงิน, การวิเคราะห์ข้อมูลธุรกิจ, และอื่น ๆ โดยมีศักยภาพในการเปลี่ยนแปลงและเป้าหมายในการพัฒนาเพิ่มเติมในอนาคต.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.microsoft.com/en-us/videoplayer/embed/RE4vyDl?postJsllMsg=true"&gt;ลองดู VDO เกี่ยวกับประโยชน์ของ AI&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  Keywords of AI  :
&lt;/h3&gt;

&lt;h4&gt;
  
  
  1. Machine learning
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;This is often the foundation for an AI system, and is the way we "teach" a computer model to make predictions and draw conclusions from data.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--HQW4-Uqr--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/t46k6pxtlsz6vg0t12o5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--HQW4-Uqr--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/t46k6pxtlsz6vg0t12o5.png" alt="machine_learning_concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Machine learning&lt;/strong&gt; (การเรียนรู้ของเครื่อง) คือสาขาหนึ่งของปัญญาประดิษฐ์ที่เน้นการพัฒนาโมเดลคอมพิวเตอร์ให้สามารถเรียนรู้และปรับตัวเองจากข้อมูล โดยไม่ต้องโปรแกรมโดยตรงให้คำสั่งเฉพาะหรือกำหนดกฎระเบียบให้กับคอมพิวเตอร์. การเรียนรู้ของเครื่องใช้วิธีการทางคณิตศาสตร์และสถิติในการวิเคราะห์และเรียนรู้จากข้อมูลเพื่อให้เครื่องมีความสามารถในการทำงานหรือการตัดสินใจโดยอาศัยข้อมูลที่มีอยู่เป็นหลัก. Machine learning สามารถนำไปใช้ในหลายด้านของการประยุกต์ใช้ เช่น:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;&lt;em&gt;การจำแนกและการจัดกลุ่มข้อมูล&lt;/em&gt;&lt;/strong&gt;: การแยกประเภทของข้อมูลออกเป็นกลุ่มหรือหมวดหมู่ต่าง ๆ เช่นการจำแนกอีเมลของลูกค้าเป็นสแปมและไม่ใช่สแปม.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การทำนาย&lt;/strong&gt;&lt;/em&gt;: การใช้โมเดลเรียนรู้ของเครื่องเพื่อทำนายผลลัพธ์หรือเหตุการณ์ในอนาคต เช่นการทำนายราคาหุ้นหรืออากาศในวันพรุ่งนี้.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การค้นหาข้อมูล&lt;/strong&gt;&lt;/em&gt;: การใช้เรนเดอร์และการจัดเรียงข้อมูลเพื่อค้นหาข้อมูลที่เกี่ยวข้องหรือสรุปข้อมูลจากข้อมูลมหาศาล.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การปรับปรุงการตัดสินใจ&lt;/strong&gt;&lt;/em&gt;: การใช้ระบบเรียนรู้ของเครื่องในการช่วยในการตัดสินใจทางธุรกิจหรือการวางแผน.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;โดยที่ Machine learning มีหลายวิธีการและอัลกอริทึมต่าง ๆ ซึ่งรวมถึงการเรียนรู้แบบแม่นยำ (supervised learning), การเรียนรู้แบบไม่มีผู้สอน (unsupervised learning), การเรียนรู้แบบเสริมกัน (reinforcement learning), และอื่น ๆ อีกมาก. การนำเสนอข้อมูลและการเลือกโมเดลที่เหมาะสมกับงานที่ต้องการเป็นความสำคัญในการประสบความสำเร็จในการใช้เทคโนโลยีนี้ในงานแต่ละประเภท. &lt;/p&gt;

&lt;h4&gt;
  
  
  2. Computer vision
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;Capabilities within AI to interpret the world visually through cameras, video, and images.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--YXQyyFlF--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/faweebii5eb9apd1v6to.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--YXQyyFlF--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/faweebii5eb9apd1v6to.png" alt="Computer vision Concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Computer vision&lt;/strong&gt; คอมพิวเตอร์วิชัน (Computer Vision) เป็นสาขาหนึ่งของปัญญาประดิษฐ์ที่เน้นการให้คอมพิวเตอร์รู้จักและเข้าใจภาพและวิดีโอแบบอัตโนมัติ โดยใช้การประมวลผลข้อมูลทางภาพและวิดีโอ โดยมีวัตถุประสงค์ที่จะให้คอมพิวเตอร์มีความสามารถในการเห็นและเข้าใจโลกต่าง ๆ เหมือนมนุษย์. การทำคอมพิวเตอร์วิชันมีประโยชน์ในหลายงานและสถานการณ์ เช่น &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;ระบบรู้จักใบหน้า (Facial Recognition)&lt;/strong&gt;&lt;/em&gt;: ใช้ในการรู้จักและจดจำใบหน้าของบุคคล เช่นในการปลดล็อกสมาร์ทโฟนหรือการควบคุมการเข้าถึงอาคาร. &lt;/li&gt;
&lt;li&gt;การตรวจสอบคุณภาพผลิตภัณฑ์ (Quality Inspection): ใช้ในอุตสาหกรรมผลิตเพื่อตรวจสอบความเสมอของผลิตภัณฑ์และความผิดพลาด. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;รถยนต์แบบขับเอง (Autonomous Vehicles)&lt;/strong&gt;&lt;/em&gt;: ช่วยให้รถยนต์แบบขับเองสามารถรู้จักและตรวจจับสิ่งของรอบตัว เช่นการจดจำสัญลักษณ์จราจรและรถยนต์อื่น ๆ บนถนน. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การวิเคราะห์ภาพการแพทย์ (Medical Image Analysis)&lt;/strong&gt;&lt;/em&gt;: ช่วยในการวิเคราะห์รูปภาพการสแกน CT, MRI, และรังสีอื่น ๆ เพื่อวินิจฉัยโรคและปัญหาทางการแพทย์.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การจดจำและวิเคราะห์วัตถุ (Object Recognition and Analysis)&lt;/strong&gt;&lt;/em&gt;: ใช้ในการตรวจจับวัตถุที่เป็นรูปร่างและข้อมูลที่มีอยู่ในภาพหรือวิดีโอ เช่นการจดจำสินค้าในร้านค้าออนไลน์.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;การทำคอมพิวเตอร์วิชันเกี่ยวข้องกับการใช้เทคโนโลยีการเรียนรู้ของเครื่อง (Machine Learning) เพื่อสร้างโมเดลที่สามารถรู้จักและวิเคราะห์ข้อมูลทางภาพและวิดีโอได้ และมักใช้งานร่วมกับเทคโนโลยีการประมวลผลภาพ (Image Processing) เพื่อดำเนินการกับข้อมูลทางภาพต่าง ๆ ให้เหมาะสมกับงานและการแยกแยะวัตถุต่าง ๆ ในภาพหรือวิดีโอ.&lt;/p&gt;

&lt;h4&gt;
  
  
  3. Natural Language Processing(NLP)
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;Capabilities within AI for a computer to interpret written or spoken language, and respond in kind.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--d7GKP3ap--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/dxt1llxi1vs7wx43o1ka.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--d7GKP3ap--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/dxt1llxi1vs7wx43o1ka.png" alt="NLP Concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Natural Language Processing(NLP)&lt;/strong&gt; คือสาขาหนึ่งของปัญญาประดิษฐ์ที่เน้นการประมวลผลและเข้าใจภาษาธรรมชาติโดยอัตโนมัติโดยใช้คอมพิวเตอร์และเทคโนโลยี การทำ NLP มุ่งเน้นให้คอมพิวเตอร์สามารถอ่านและเข้าใจข้อความและภาษาพูดแบบมนุษย์ รวมถึงสามารถตอบสนองตามความหมายของข้อมูลทางภาษาธรรมชาติด้วยวิธีการทางคณิตศาสตร์และการเรียนรู้ของเครื่อง. NLP มีประโยชน์ในหลายด้านของการประยุกต์ใช้ เช่น &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การแปลภาษา (Language Translation)&lt;/strong&gt;&lt;/em&gt;: การแปลข้อความหรือภาษาจากภาษาหนึ่งไปยังอีกภาษาหนึ่ง เช่นการแปลจากภาษาอังกฤษเป็นภาษาสเปน. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การวิเคราะห์สื่อสังคม (Social Media Analysis)&lt;/strong&gt;&lt;/em&gt;: ใช้ในการวิเคราะห์และเข้าใจความรู้สึกและทัศนคติของบุคคลหรือสังคมจากข้อมูลที่โพสต์บนสื่อสังคมออนไลน์. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การจดจำเสียง (Speech Recognition)&lt;/strong&gt;&lt;/em&gt;: การรับรู้และแปลงเสียงพูดให้อยู่ในรูปของข้อความ เช่นระบบควบคุมเสียงในอุปกรณ์สมาร์ท. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การตอบสนองของระบบอัตโนมัติ (Chatbots)&lt;/strong&gt;&lt;/em&gt;: การสร้างโปรแกรมคอมพิวเตอร์ที่สามารถสนทนาและตอบคำถามของผู้ใช้อย่างเป็นธรรมชาติ. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การค้นหาข้อมูล (Information Retrieval)&lt;/strong&gt;&lt;/em&gt;: การช่วยในการค้นหาข้อมูลที่เกี่ยวข้องจากฐานข้อมูลขนาดใหญ่โดยใช้คำค้นหาหรือคำถาม. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;NLP มีความซับซ้อนมากเนื่องจากภาษามนุษย์มีความหลากหลายและความเชิงบรรยายที่ซับซ้อน และความหมายของคำและประโยคมักมีบทบาทที่ขึ้นอยู่กับบริบท ทำให้การใช้เทคโนโลยี NLP ค่อนข้างท้าทาย แต่มันเป็นสาขาที่มีการพัฒนาและใช้งานอย่างกว้างขวางในหลายด้านของชีวิตประจำวันและธุรกิจ.&lt;/p&gt;

&lt;h4&gt;
  
  
  4. Document intelligence
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;Capabilities within AI that deal with managing, processing, and using high volumes of data found in forms and documents.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--XcND5h1u--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/0tv0srhwzy3qlpjzl5z8.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--XcND5h1u--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/0tv0srhwzy3qlpjzl5z8.png" alt="Document intelligence Concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Document intelligence&lt;/strong&gt; (ความรู้เกี่ยวกับเอกสาร)เป็นสาขาใหม่ในด้านการปัญญาประดิษฐ์และเทคโนโลยีสารสนเทศที่เน้นการใช้เทคโนโลยีเพื่อการประมวลผลเอกสารและข้อมูลที่อยู่ในรูปแบบของเอกสารอิเล็กทรอนิกส์ โดยเฉพาะเอกสารที่มีลักษณะที่ซับซ้อน เช่นเอกสารทางธุรกิจ, แบบฟอร์ม, เอกสารทางการแพทย์, และเอกสารทางกฎหมาย เพื่อให้คอมพิวเตอร์สามารถเข้าใจเนื้อหาและแปลงเป็นข้อมูลที่มีความหมายได้. Document intelligence รวมถึงการใช้เทคโนโลยีการเรียนรู้ของเครื่อง (Machine Learning) เพื่อทำการแยกแยะและสกัดข้อมูลจากเอกสาร ตัวอย่างการประยุกต์ใช้ document intelligence ได้แก่: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Optical Character Recognition (OCR)&lt;/strong&gt;&lt;/em&gt;: การแปลงข้อความที่ถูกพิมพ์หรือลายมือเป็นข้อมูลที่คอมพิวเตอร์สามารถเข้าใจได้ โดยใช้การสแกนหรือถ่ายภาพเอกสาร. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การจดจำและการแยกแยะเอกสาร (Document Classification)&lt;/strong&gt;&lt;/em&gt;: การแยกประเภทเอกสารต่าง ๆ เช่นใบสมัครงาน, ใบแจ้งหนี้, หรือสัญญา. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การสกัดข้อมูล (Data Extraction)&lt;/strong&gt;&lt;/em&gt;: การสกัดข้อมูลที่สำคัญออกจากเอกสาร เช่นชื่อลูกค้า, ที่อยู่, วันที่, หมายเลขบัญชี, หรือข้อมูลอื่น ๆ ที่เกี่ยวข้อง. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การค้นหาข้อมูล (Information Retrieval)&lt;/strong&gt;&lt;/em&gt;: การค้นหาข้อมูลที่ต้องการจากเอกสารในฐานข้อมูลขนาดใหญ่. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;การวิเคราะห์ข้อมูล (Data Analysis)&lt;/strong&gt;&lt;/em&gt;: การนำข้อมูลที่ถูกสกัดออกมาจากเอกสารมาวิเคราะห์เพื่อให้สามารถทำการตัดสินใจหรือการวางแผนในธุรกิจได้. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Document intelligence ช่วยลดการกระทำของมนุษย์ในการประมวลผลเอกสารและเพิ่มความแม่นยำในการจัดการข้อมูล ซึ่งมีประโยชน์ในหลายอุตสาหกรรม เช่น การเงิน, การขาย, การบริหารจัดการ, และการดูแลสุขภาพ.&lt;/p&gt;

&lt;h4&gt;
  
  
  5. Knowledge mining
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;Capabilities within AI to extract information from large volumes of often unstructured data to create a searchable knowledge store&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--K1EKhSKG--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/owjt5pcq9rsn4yg9255q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--K1EKhSKG--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/owjt5pcq9rsn4yg9255q.png" alt="Knowledge mining Concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Knowledge mining&lt;/strong&gt; (การขุดความรู้) เป็นกระบวนการในการค้นหา, สกัด, และนำเอาข้อมูลและความรู้ที่ซ่อนอยู่ในข้อมูลที่มีอยู่ในรูปแบบที่ไม่โครงสร้างมาใช้ประโยชน์ โดยใช้เทคโนโลยีและเครื่องมือการประมวลผลข้อมูลต่าง ๆ รวมถึงการใช้ปัญญาประดิษฐ์ เพื่ออ่าน, วิเคราะห์, และเข้าใจข้อมูลที่มีโครงสร้างที่ไม่เป็นมาตรฐานหรือมีความซับซ้อน.&lt;/p&gt;

&lt;p&gt;กระบวนการ Knowledge mining มักเกี่ยวข้องกับข้อมูลที่อยู่ในรูปแบบของข้อความ, เอกสาร, บันทึกการประชุม, หรือข้อมูลที่ไม่มีโครงสร้างแน่นอน เช่นข้อมูลทางเศรษฐศาสตร์, ข้อมูลการสนทนา, หรือข้อมูลทางการแพทย์. กระบวนการนี้มักใช้เทคโนโลยีการประมวลผลภาษาธรรมชาติ (Natural Language Processing, NLP), การเรียนรู้ของเครื่อง (Machine Learning), และเครื่องมือที่ช่วยในการสกัดข้อมูลที่มีความหมายและความรู้ออกมาจากข้อมูลที่ไม่มีโครงสร้างเหล่านี้.&lt;/p&gt;

&lt;p&gt;เช่นหากคุณมีฐานข้อมูลเอกสารที่มีข้อความเกี่ยวกับความรู้ทางการแพทย์ การใช้ Knowledge mining สามารถช่วยในการค้นพบความรู้ทางการแพทย์ที่ซ่อนอยู่ในข้อมูลเหล่านี้ เช่นการค้นหาข้อมูลที่เกี่ยวกับโรคร้ายแรงหรือการค้นหาข้อมูลที่เกี่ยวกับการวิจัยทางการแพทย์ใหม่ ๆ ที่อาจมีประโยชน์ในการรักษาโรคหรือป้องกันโรคในอนาคต.&lt;/p&gt;

&lt;p&gt;ดังนั้น Knowledge mining มีความสำคัญในการแปรรู้และนำความรู้ที่มีอยู่ในข้อมูลให้เป็นประโยชน์ในงานวิจัย, ธุรกิจ, และอุตสาหกรรมต่าง ๆ โดยช่วยให้เราทราบเกี่ยวกับความรู้ที่อาจมีค่าและไม่เคยรู้มาก่อน.&lt;/p&gt;

&lt;h4&gt;
  
  
  6. Generative AI
&lt;/h4&gt;

&lt;blockquote&gt;
&lt;p&gt;Capabilities within AI that create original content in a variety of formats including natural language, image, code, and more.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://res.cloudinary.com/practicaldev/image/fetch/s--jrYlU_SF--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/4dsb3nudvll3f6dozh3q.png" class="article-body-image-wrapper"&gt;&lt;img src="https://res.cloudinary.com/practicaldev/image/fetch/s--jrYlU_SF--/c_limit%2Cf_auto%2Cfl_progressive%2Cq_auto%2Cw_800/https://dev-to-uploads.s3.amazonaws.com/uploads/articles/4dsb3nudvll3f6dozh3q.png" alt="Generative AI Concept" width="800" height="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Generative AI&lt;/strong&gt; Generative AI (Artificial Intelligence สร้างสรรค์) คือแบบจำลองของปัญญาประดิษฐ์ที่ถูกออกแบบเพื่อสร้างข้อมูลหรือเนื้อหาใหม่ๆ ที่ดูเหมือนมนุษย์สร้างขึ้น โดยไม่จำเป็นต้องมีข้อมูลต้นฉบับที่เป็นตัวอย่าง หรือมีการคัดลอกโครงสร้างจากข้อมูลที่มีอยู่ แต่เครื่องมือ Generative AI สามารถสร้างสิ่งต่าง ๆ ออกมาด้วยตัวเอง ซึ่งประกอบด้วยหลายๆ แนวทางและเทคโนโลยีต่าง ๆ อย่างไรก็ตาม เหตุการณ์ที่มีชื่อเสียงมากของ Generative AI คือการใช้การเรียนรู้ของเครื่อง (Machine Learning) แบบเรียนรู้เชิงลึก (Deep Learning) และโมเดลการเรียนรู้เชิงเส้น (Linear Learning) เพื่อสร้างข้อมูลเสมือนมนุษย์เช่น ข้อความ, ภาพ, เสียง, และวิดีโอ. Generative AI สามารถประยุกต์ใช้ในหลายด้านและสาขา เช่น: &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Natural Language Generation (NLG)&lt;/strong&gt;&lt;/em&gt;: สร้างข้อความที่มีความหมายและอ่านได้เพื่อใช้ในการสร้างเนื้อหาบนเว็บไซต์, บทความข่าว, และรายงาน. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Image Generation&lt;/strong&gt;&lt;/em&gt;: สร้างภาพที่มีความคล้ายคลึงกับภาพจริง ๆ เช่นสร้างภาพของมนุษย์,สัตว์,หรือภาพสร้างสรรค์อื่น ๆ. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Music Composition&lt;/strong&gt;&lt;/em&gt;: สร้างเสียงเพลงหรือเนื้อร้องเพลงใหม่ ๆ ที่มีความสมจริงในการดนตรี. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Art Generation&lt;/strong&gt;&lt;/em&gt;: สร้างผลงานศิลปะและภาพวาดที่สร้างสรรค์จากคอมพิวเตอร์. &lt;/li&gt;
&lt;li&gt;
&lt;em&gt;&lt;strong&gt;Video Synthesis&lt;/strong&gt;&lt;/em&gt;: สร้างวิดีโอและอนิเมชันใหม่ ๆ ที่มีความหมายและความคล้ายคลึงกับวิดีโอจริง. &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Generative AI มีศักยภาพในการสร้างเนื้อหาและสร้างสรรค์สิ่งต่าง ๆ โดยอัตโนมัติ แต่ก็มีความท้าทายในด้านความแม่นยำและความคุณภาพ และมีความคำนึงถึงปัญหาทางจริยธรรมและความปลอดภัยเมื่อมีการใช้งานในประเด็นต่าง ๆ ที่มีผลต่อสังคมและวัฒนธรรม.&lt;/p&gt;

&lt;p&gt;อ้างอิงจาก:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/training/modules/get-started-ai-fundamentals/1-introduction"&gt;Microsoft Fundamental AI Concepts: Introduction to AI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;สรุปเนื้อหาจาก ChatGPT และรูปภาพจาก DALL-E
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>fundamentals</category>
      <category>learning</category>
    </item>
    <item>
      <title>Simple Remove or Change HTTP Server header in NGINX Plus.</title>
      <dc:creator>supachai jaturaprom</dc:creator>
      <pubDate>Thu, 18 Nov 2021 11:40:34 +0000</pubDate>
      <link>https://dev.to/supachai/simple-remove-or-change-http-server-header-in-nginx-plus-5658</link>
      <guid>https://dev.to/supachai/simple-remove-or-change-http-server-header-in-nginx-plus-5658</guid>
      <description>&lt;p&gt;&lt;code&gt;First written&lt;/code&gt;, I must have remove or change strings value &lt;strong&gt;HTTP Server header&lt;/strong&gt; in NGINX. Excellet, The &lt;strong&gt;NGINX Plus&lt;/strong&gt; have Core functional (Build-in) &lt;strong&gt;without third-party dynamic module&lt;/strong&gt; for solution this case, detial as like below.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Official Document:&lt;/strong&gt; &lt;a href="https://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens" rel="noopener noreferrer"&gt;https://nginx.org/en/docs/http/ngx_http_core_module.html#server_tokens&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnlosvpaj58asdmk2qzo3.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fnlosvpaj58asdmk2qzo3.png" alt="nginx server_tokens"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Example Configuration for nginx.conf&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;http { 
....
#server_tokens off; 
#server_tokens "Microsoft-IIS/8.5"; 
#server_tokens none; 
server_tokens ""; 
...
 } 
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Noted: Uncomment &lt;code&gt;server_tokens&lt;/code&gt; lines for each testing case.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Capture Screen of Testing&lt;/strong&gt;&lt;br&gt;
&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F30ntkxsk3hcw9evkvy5n.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F30ntkxsk3hcw9evkvy5n.png" alt="testing server_tokens"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Thanks for reading my written, Good luck.&lt;/p&gt;

</description>
      <category>nginx</category>
      <category>linux</category>
      <category>security</category>
      <category>nginxplus</category>
    </item>
  </channel>
</rss>
