HN user

Snawoot

434 karma

[ my public key: https://keybase.io/yarmak; my proof: https://keybase.io/yarmak/sigs/B-6vurJWXuwCRjiwWwjhWFQYkm-IE_oNmPsr9czKvyo ]

Posts53
Comments150
View on HN
tlscookie.xx.kg 1mo ago

Tlscookie – hidden cookies in TLS tickets

Snawoot
2pts0
codeberg.org 3mo ago

Show HN: Weakmap – weak map for Go without use of finalizers

Snawoot
1pts0
snawoot.github.io 3mo ago

Making Services with Go Right Way

Snawoot
2pts0
github.com 5mo ago

Dumbproxy 1.42.0 released with TrustTunnel support

Snawoot
2pts1
github.com 6mo ago

HTTP-over-TLS proxy in a single command

Snawoot
2pts0
pkg.go.dev 7mo ago

Show HN: Secache – Sampling Eviction Cache

Snawoot
1pts0
snawoot.github.io 8mo ago

PPP-over-HTTP/2: Having Fun with dumbproxy and pppd

Snawoot
5pts0
github.com 9mo ago

Dumbproxy just got SOCKS5 support

Snawoot
3pts0
github.com 1y ago

Dumbproxy got Redis auth back end

Snawoot
1pts0
pkg.go.dev 1y ago

Show HN: Unicmp – fast universal ordering function for Go

Snawoot
3pts0
github.com 1y ago

Dumbproxy – simple, scriptable, secure forward proxy

Snawoot
7pts0
github.com 1y ago

Basic auth via HMAC signatures for Squid

Snawoot
2pts1
pkg.go.dev 1y ago

Generic Freelist Allocator for Go

Snawoot
10pts3
pkg.go.dev 1y ago

Show HN: Lock-free concurrent maps for Golang

Snawoot
5pts2
github.com 2y ago

Redundancy Group Announcement Protocol

Snawoot
2pts0
github.com 2y ago

Show HN: Dtlspipe – Like Stunnel, but for UDP

Snawoot
1pts0
github.com 3y ago

Self-hosted, fast and accurate connection speed test

Snawoot
2pts0
github.com 3y ago

Show HN: Terse – output randomly sampled lines

Snawoot
1pts0
twitter.com 3y ago

NthLink VPN tries to hide evidence of vulnerability

Snawoot
3pts0
github.com 3y ago

Show HN: Run secure proxy with LE certs in just one command

Snawoot
5pts1
snawoot.github.io 3y ago

Stripping NthLink VPN Encryption

Snawoot
6pts2
gist.github.com 3y ago

Poor Man's Global Traffic Manager

Snawoot
23pts12
twitter.com 3y ago

NthLink VPN found to be using same pre-shared keys for all users

Snawoot
18pts0
github.com 3y ago

Show HN: Dump Shadowsocks Credentials from NthLink

Snawoot
3pts0
habr.com 4y ago

Who Controls App Store: Martians or AI?

Snawoot
2pts0
github.com 5y ago

Show HN: Go implementation of Windscribe proxies client

Snawoot
1pts0
github.com 5y ago

Personal Shadowsocks server in 5 minutes with Heroku

Snawoot
10pts0
github.com 5y ago

Show HN: Reverse engineered Opera VPN client

Snawoot
8pts0
github.com 5y ago

Hola-proxy now works in Egypt

Snawoot
2pts0
www.ambitvpn.com 5y ago

Countdown to Quantum Decryption

Snawoot
2pts0
  Location: Ukraine
  Remote: yes
  Willing to relocate: no
  Technologies: Go, Python, JS, C, PostgreSQL, MySQL, MongoDB, Redis, Linux, Docker, kubernetes, ...
  Résumé/CV: https://www.linkedin.com/in/vladislav-yarmak/
  Email: vladislav-ex-hncv@vm-0.com
Software engineer with about 15 years of experience, former CTO, VPE, Systems Architect. My key skills are in backend development, infrastructure, computer networks.
  Location: Ukraine
  Remote: yes
  Willing to relocate: no
  Technologies: Go, Python, JS, C, PostgreSQL, MySQL, MongoDB, Redis, Linux, Docker, kubernetes, ...
  Résumé/CV: linked here https://snawoot.github.io/
  Email: specified here https://snawoot.github.io/
Most recent job was CTO at crypto/VPN startup and I was working on network and security stuff in general for about last 10 years. I'm open to other fields and roles, though.
Consistent hashing 10 months ago

I also double that rendezvous hashing suggestion. Article mentions that it has O(n) time where n is number of nodes. I made a library[1] which makes rendezvous hashing more practical for a larger number of nodes (or weight shares), making it O(1) amortized running time with a bit of tradeoff: distributed elements are pre-aggregated into clusters (slots) before passing them through HRW.

[1] https://pkg.go.dev/github.com/SenseUnit/ahrw

What ever happened to providing a good service?

I'm getting an impression it's just not profitable enough. For many years I get a feeling that business is considered sound only if it is superprofitable (not exactly the right term, but still) in order to cover all losses.

Probably it's because of market competition required to be at least noticed. Some companies' spendings for marketing are greater than for R&D, production and operations combined. Maybe we got ourselves into a situation where everywhere competing for low-hanging fruits or trying to make customer believe it's the service they need while all of it doesn't really overlap with real society needs.

Bloom Filters 1 year ago

Cuckoo filters are more efficient alternative. The algorithm of displacement is also very notable: how we can use random swaps to place data in cells optimally.

I had an attempt to improve performance of memory allocation with the use of arenas in Go and I chose freelist datastructure[1]

It almost doesn't use unsafe except one line to cast pointer types. I measured practical performance boost with "container/list" implementation hooked to my allocator. All in all it performs 2-5 times faster or up to 10 times faster if we can get rid[2] of any and allocations implied by the use of it.

All in all, heap allocations can be not that bad at all if you approach them from another angle.

[1] https://github.com/Snawoot/freelist

[2] https://github.com/Snawoot/list

2-6x faster than Redis (benchmark link below) yet disk persisted!

That's a false contradistinction: Redis is also disk persisted.

The benchmark you did mentions Redis benchmarking guide and this guide has following paragraph:

Redis is, mostly, a single-threaded server from the POV of commands execution (actually modern versions of Redis use threads for different things). It is not designed to benefit from multiple CPU cores. People are supposed to launch several Redis instances to scale out on several cores if needed. It is not really fair to compare one single Redis instance to a multi-threaded data store.

Did you just benchmarked against only single Redis instance and claimed performance win? Even if so, how do benchmarks compare against source-available competitor DragonflyDB?

Finally, documentation doesn't mention how persistence exactly works and what durability guarantees should we expect?

I have addresses like somename-ex-someservice@mydomain.com directed to my email, which I use to register myself in "someservice". This is how I know where email was leaked and needs to be disabled. I use Protonmail basic subscription to attach my domain. Before that I was using rewriting rules in Postfix.

That's great! I see you use `sync.Pool`, which is way safer alternative. However, I wasn't able to secure much of performance gains for linked list benchmark using sync.Pool. It's not even clear how much objects it will contain ready to go. On the other hand, sync.Pool docs suggest to implement own free list for small short-living objects. I wonder what do they mean and how it should look like?

Sure you can. Fingerprint of key is just a shorter and more convenient option to reference key everywhere, including manual verification. Article tells just that and it's commonly used in the industry.

And, by the way, signature in X.509 certificates ("TLS certificates") also hashes data to be signed - signed data input has to be smaller than sig size. Hence it also verifies pubkey indirectly.