HN user

disambiguated

8 karma
Posts0
Comments4
View on HN
No posts found.

No, get an iPad and use the Kindle App - it's 1000x better than the hardware Kindle. Since the Kindle App became available for iPhone, my hardware Kindle has gathered dust - and now with the iPad, I can read on a large- or smaller-format device.

It's great for illustrations, too - all the drawbacks of the hardware-based Kindles disappear when you use the Kindle App on the iPad.

Firewalls aren't DDoS mitigation devices, they're staeful policy-enforcement devices. DDoS attacks are attacks against capacity and/or state - firewalls must be protected from DDoS just like hosts (even more so, in fact).

Implement iACLs, uRPF, and S/RTBH at your edges, and work with your SP on a reaponse plan.

And take your server out from behind the firewall. Stateful inspection makes no sense at all on a front-end server, where every connection is by definition unsolicited. Harden the OS, harden the apps/services, run a chrooted jail, use tcpwrappers and mod_security and mod_evasive, and use stateless ACLs in an ASIC-based router to enforce access policies.

By placing the server behind the firewall, you increase its vulnerability due to the potential for exhaustion of the connection table by an attacker. You can use firewalls between the tiers of a multi-tier setup, where you can control the number and types of inbound connections on a bidirectional basis, but no one who operates high-volume publicly-accessible servers puts the the front-end behind a firewall, because it does nothing to increase the security posture, and can actually be harmful.

Bangkok - great food, good connectivity, close air-wise to Singapore/HK, low cost-of-living, good overhead/underground trains, cheap taxis, tuk-tuks, and motorcycle-taxis.

Plus, it's easy for even totally unattractive social misfits to obtain intimate companionship, with no strings attached.

;>