HN user

EtherealMind

9 karma

25 year Enterprise IT survivor as a network architect/engineer. Now working as advisor/podcaster/writer/analyst. Generally known for strongly curated opinions on the future of data networking and security.

podcast: packetpushers.net

Posts0
Comments12
View on HN
No posts found.
Waterway Map 2 years ago

My 0.02p, it cost about £6000/yr to do it cheap. Goes up to £10k/yr with a full time mooring in a marina and outsourced services.

Boat pricing comes in a spectrum that very roughly looks like this:

3. £20-£40K Narrowboats are thirty or more years old, or are under 50ft. They have had many owners each of which will have done something to the boat. The engine fittings will be old eg. coolant hoses , the radiators might not work, the fireplace might need replacing, there is rust in important places needing welding and so on. There may be overplating on the hull to repair holes. In general, you can expect to perform regular/constant maintenance and repairs to maintain and keep them in working order. (some people enjoy this, you may not)

4. In the 40-60K range expect the boat to be about 20 years old. Generally modern and most things will be working but it might not have a good electrical system for modern lifestyles. It will have 20 years of wear and tear, and the interior might feel old and outdated.

5. In the £100k-£120 range you should see 5-10 year old boats. It probably will have a modern toilet/shower, modern electrical maybe a solar panel, a nicer kitchen and modern diesel engine/gearbox and propeller.

6. At £160K-180K you can get a new but simple/basic boat fitout probably no solar, no dinette, few cupboards. Or it’s a five year old custom build that has been fully fitted with many extras e.g washing machines, quality inverter/batteries

7. At £200K+ it a brand new boat, built to your specification. An all electric boutique boat is £220K-240K. I’ve heard of narrowboats up to £280K. Luxury wide beams over £350K do exist.

Waterway Map 2 years ago

I spend 8 months a year on my narrowboat moving around the canals as I hunt for pubs, relaxation and peace. In winter I hibernate in my house, pining for the canals and freedom.

Also, I work full-time from the boat.

Delivering this function is very costly, because of stateful inspection you must implement flow sticking which require buffering which then impacts performance

..... and so on and so on.

no, doesn't work.

A firewall doesn't prevent compromise. An attacker can always reach your Internet connected system, and attack through the firewall.

Firewall is useful for protecting servers that don't have well managed IPTables or similar.

Two things:

1. the number is more than 800. 2. NSX is being deployed primarily as a security tool for micro-segmentation. It is displacing firewalls in the data centre is substantly way. 3. Change in the data centre is slow. Infrastructure is commonly built on 10-15 year cycles so actual purchases are a lagging indicator.

There are some non-obvious issues:

1. Why not firewall in the operating system and distribute/scale the load evenly ? Centralising the firewall was done when OS provisioning was bad, now we have Puppet/Chef/Ansible, firewalls operations is simple enough.

2. Simple firewalling is effectively worthless when 99% of all traffic is HTTP/S and SSH. To add value you perform flow analysis combined with deep packet inspection to build a meta-data data to pass through a heuristics/pattern analysis to perform threat detection.

3. Passing through any device creates latency in the order of milliseconds, which is not acceptable in east/west traffic loads. Parallelisation, caching, flow cut-through will all incur a latency penalty.

HTH

greg

TLS in HTTP/2 11 years ago

Certain corporate companies formed a consortium to prevent encryption to ensure that monetisation of personal information would continue.

At the very last stage, the IETF appeared to be hijacked by very large telcos (e.g. ATT, Verizon, Ericsson, Comcast) to remove the mandatory requirement for TLS

As an outsider, this look likes a careful co-ordinated attack on the IETF standards process by a small number of "serial IETF professionals" who are paid by the big carriers to be inside the organisation and ensure that standards do the bidding of corporate masters. (some hyperbole there)

Waiting until the last phase restricted discussion, and used the existing momentum to complete HTTP2 standard while removing one of the fundamental reasons for HTTP2 to exist.

It is a very sad day that consumer rights have been compromised by big money. And as the Lenovo Superfish debacle showed, likely it will backfire in the long run.

Here is the consortium: http://www.atis.org/openweballiance/about.asp

Here is an summary I wrote about this topic: http://etherealmind.com/response-open-web-alliance-lobbies-i...