HN user

growse

3,174 karma

@growse@hachyderm.io

Posts16
Comments1,135
View on HN

Summary: it's not DNSSEC itself, it's DNS providers like Cloudflare returning incorrect data to make responses shorter and avoid switching to TCP.

I feel like we need the angry goose meme here.

"But why are those providers returning incorrect data?"

No one.

I thought everyone was "trying so hard to re-invent PGP".

we do need a single key that can be used for all those things

We do? This is not obvious. Why does my disk encryption key need to be the same that I use to sign binaries that I release?

I do similar, but frame it in terms of dependencies.

The database can live without the web server, but the web server doesn't work without the database.

Therefore webserver ---> database.

Key thing in that these deployment / context / container diagrams don't have a temporal axis. If you want to represent a flow, then you want a diagram where time has directionality, like a sequence diagram.

If I accidentally yank the power cable out of my load balancer, I can plug it back in and I'm back up and running.

If I cock up my DNSSEC config, nobody can resolve any records under my org's domain (goodbye internal email!) and you've got to twiddle your thumbs for a period of time waiting for various timeouts to pass (go ask Slack how it went for them).

These things are not the same.

As if DNS isn't a major contributing to A LOT of downtime. That doesn't mean it's not worth doing not investing in making deployment more seamless and less error prone.

Ah yes. Let's take something that's prone to causing service issues and strap more footguns to it.

It's not worth it, because the cost is extremely quantifiable and visible, whereas the benefits struggle to be coherent.

That entire post is that you should enable DNSSEC because it's "more secure", and there are no reasons not to.

"More secure" begs the question "against what?", which the blog post doesn't seem to want to go into. Maybe it's secure from hidden tigers.

My favourite DNSSEC "lolwut" is about how people argue that it's something "NIST recommends", whilst at the same time the most recent major DNSSEC outage was......... time.nist.gov! (https://ianix.com/pub/dnssec-outages.html)

If you're in (for example) a CI context and do a git checkout @tag, there's no guarantee that you'll get the same content as the last time you fetched that tag.

Tags are not immutable.

Why is entitlement to others labor the moral position, instead of the immoral position?

You seem to be mistaking me for someone arguing that anyone is entitled to others' labour?

CABF started imposing restrictions on the public CA operators regarding the issuance of non-HTTPS certificates.

The restriction is on signing non web certificates with the same root/intermediate as is part of the WebPKI.

There's no rule (that I'm aware of?) that says the CAs can't have different signing roots for whatever use-case that are then trusted by people who need that use case.

if we could of built it much closer to the WCML

Knocking down half the towns that the WCML runs through to build more tracks carrying trains that aren't going to stop there would be neither easier nor cheaper than HS2.

But you write it as if it's in contradiction with my point, which I'm not seeing.

My point was that a community is members + values + practices + other stuff. In the case where one member who wants to upend the values and practices of an existing community, "just fork it" is an entirely reasonable response.

I rarely see good faith engagements being immediately shut down with "just fork it" (you'd never accept issues / MRs!). Instead it's usually used as a last resort when the "exploiter" doesn't get their way and starts whining about it.

If a change is proposed that's completely counter to a community's stated values, then I guess "fork it" is a more appropriate immediate response, because it's hard to see how such a clash could be resolved without fundamental change.

Edit

Every community is the sum of its members

A community is much more than the sum of it's members.

The subtext here is that there's a difference between someone saying "I don't like this community, I'm going to make my own" and "I don't like this community, I'm going to change it".

Building communities is hard. It's not obvious why someone who wants a community on their terms gets to piggyback on an existing community rather than putting the effort in to make their own.

The point of "just fork it" is that if your ideas are popular, then sustainability shouldn't be a problem.

I don't remember if this is in the original text, but is there a time constraints on distributing the source on request?

If a user asks for the source, and the distributor says "sure" and then delivers it 12 months later, have they violated the license?

Love your customers 7 months ago

I have generally told that story with the ISV anonymized -- but you clearly found an example where I named them.

It was on one of the OaF podcasts about dtrace. I worked for Reuters at the time and contempt for their customers was definitely a thread that ran through some parts of that org, even as it made a bunch of us feel very icky.

(I still have a side quest to find / talk to some of the people involved on 'our' side of the fence about this!)

There's a bus factor equivalent with the cloud, too. The power to severely disrupt your service (either accidentally, or on purpose) rests with a single org (and often, a single compliance department within that org).

Ironically, this becomes more of a concern the larger the supplier. AWS can live with firing any one of their customers - a smaller outfit probably couldn't.

Using LLMs at Oxide 8 months ago

The value is in how clear the final output is.

Clarity is useless if it's inaccurate.

Excel is deterministic. ChatGPT isn't.

Did anyone use AFS (Andrew File System)?

Glances round to see if there's any alumni from a certain Large Investment Bank also present...