HN user

M_bara

149 karma
Posts1
Comments73
View on HN

(like reading env vars and sending them to an external server) it'd not be able to send credentials or fetch a malware remotely at all due to the DNS queries being intercepted by eBPF and being sent to a CoreDNS proxy.

Wouldn’t the exploit then just use ip addresses directly?

That is why i insist on 1. Streaming replication whether from RDS or my own DB 2. Db dumps shipped to s3 using write only creds or something like rsync.

Streaming gets you PIT recovery while DB dumps give me daily snapshots stored daily for 14 days.

An aside: 15 or so years ago, a work colleague made a mistake and dropped the entire business critical DB - at a critical internet related company - think of continent wide ip issues. I had just joined as a dba and the first thing I’d done was MySQL bin logging. That thing saved our bacon - the drop db statement had been replicated to slaves so we ended up restoring our nightly backup and replaying the binlogs using sed and awk to extract DML queries. Epic 30 minute save. Moral of the story, have a backup of your backup so you can recover when the recovery fails;)

It’s all about the resources - the gold, the minerals and the farmland. Different groups want to control it from East African proxies for the Middle East. It’s really sad and has the potential to destabilise the region.

If you think this is bad, then the chemicals used in rocketry - read the book ignition [1] - will have you whimpering in a corner. As with any system, risks can be identified and controlled and operationalised - Gasoline has its risks, so does Chlorine trifluoride [2]. Yet both are wildly different and are used in day to day operations.

1. https://library.sciencemadness.org/library/books/ignition.pd... 2. https://en.wikipedia.org/wiki/Chlorine_trifluoride

Precisely,Safaricom also alleged that they would allow for illegal connections… perhaps they meant connections that we can’t easily wiretap on behalf of the government. Interestingly, during the protests a few months ago, the government severely throttled all external connections by putting a few interfaces down at the fibre sea landing points. Only Starlink users were getting good connectivity. A lot of folks migrated at that point.

Same thing in Kenya. A 150km radius around Nairobi is maxed out. I have a fishy kit that can’t join due to capacity issues. In fact, the advent of Starlink - which had acquired 0.5% of the entire market - has rattled the existing players so much that, 1. They’ve doubled available bandwidth for residential plans without increasing cost. Safaricom went way overboard and 5x-ed plans. So if you were on 40mbit for $40 USD, you’d get 200mbit for the same cost. 2. They are all writing letters to the fcc equivalent crying about GSM spectrum interference (duh…) and predatory pricing [1]. I’m all for more competition! I’m only considering moving to Starlink due to frequent fibre cuts.

1. https://www.businessdailyafrica.com/bd/corporate/technology/...

We had something similar about 10 years ago where I worked. Customer instances were backed via loopback devices to local disks. We didn’t think of this - face palm - on the loop back devices. What we ended up doing was writing a small daemon to posix fadvise the kernel to skip the page cache… your solution is way simpler and more elegant… hats off to you

This is something life changing for some of us. I grew up in an area where water has a lot of fluoride and we didn’t get to know until I was 16.. side effect is I have very brittle teeth.. I’ve shattered a couple due to bad rice (had a small stone in it), lentils, sliver of bone … Now, the kicker is Colgate et al have been marketing fluoride toothpaste to the same region to people facing fluorosis knowingly - profits above all else. so if this treatment comes through, I’ll be lining up!

About 9 years ago, I consulted for a company that had a bad internal hack - disgruntled cofounder. Basically, a dead man’s switch was left that copied out the first 20mb of every disk to some bucket and then zeroed out. To recover the data we had to use test disk to rebuilt the partition table… but before doing that we didn’t want to touch the corrupted disks so we ended up copying out about 40tb using rescue flash disks, nectat and drive (some of the servers had a physical raid with all slots occupied so you couldn’t use some free had slots). Something along the lines of dd if=/dev/sdc bs=xxx | gzip | nc -l -p 8888 and the reverse on the other side. It actually worked surprisingly well. One thing of note,try combinations of dd bs to match with sector size - proper sizing had a large impact on dd throughput

Back in the day ~23 years ago. A telco that had just launched started providing voice mail service. Normal outgoing call rates were about .5 usd per minute. The newly launched voice mail service was free. So university students found a new trick to call their friends, flash your friend (single ring signal to say that they don’t pick up their phone), hang up and call again, let it ring till it goes to voicemail, leave a long message, hang up and wait for the reply. Obviously it’s not full duplex and latency was high but what the e heck it’s free. The telco killed it within 2 days… and then we started having fun with all those smsc Center numbers from all over the world…