HN user

jauer

2,163 karma

SRE working at the intersection of Network and Security infra at one of the FAANG.

Former SysAdmin at a small dialup/wireless/fiber/colo ISP in the US Midwest. Full stack where the stack went from datacenter power and cooling, fiber in the ground, to BGP, database perf tuning, and dev on backoffice/accounting/billing systems.

https://jade.wtf / https://github.com/jda/ / jade@jade.wtf

[ my public key: https://keybase.io/jda; my proof: https://keybase.io/jda/sigs/-MAdRvws8lprdF6WKGMur4GHTbctlG5hOtJvctF_rWg ]

Posts4
Comments461
View on HN

Information is default low-trust unless you have reason to extend trust to the source and that's been the case for thousands of years, if not the entirety of human existence.

We now have the tools to increase trust in specific information, for example: by signing images that need high trust for things like news reporting using camera hardware root of trust with time and geo stamping. If signatures are removed, that's back to a default low-trust state.

and the xAI data centers are uniquely dirty and polluting because they don't have sufficient grid connectivity and are running on generator 24x7.

This isn't a problem for the vast majority of datacenters, and won't become a larger problem unless the anti-civilization mindset blocks infrastructure investment that's eventually needed even if the datacenter isn't built.

Unlike enterprise datacenters, systems inside these datacenters are tightly coupled to compute system design to eke out PUE, so network cabling, electrical, and cooling to a lesser degree gets reworked every 3-5 years. On a campus with several data halls this means that there’s work for those trades well beyond initial construction. Sure, you don’t have the steel and concrete work happening that went into the shell, but it’s more than a handful of operations people.

From the 00s to mid 2010s I did fiber splicing in factories from Kenosha to Beaver Dam and even then they were fairly well-automated to the extent that I’d see just a few people on the factory floor moving carts of metal between machines or handling shipping and receiving.

I've worked in various teams on the infrastructure side of a FAANG from early career/L4 to sr staff eng/L7 and have always been encouraged and rewarded for asking questions, even when those questions have led to unexpected multimillion dollar costs and in one case a loss of ~1% of fleetwide compute capacity.

I think this comes down to how you go about asking. You have to take the time to understand what is and how it's seen by others by being curious, reading docs, etc instead of rolling in making assertions disguised as questions to assert authority like so many are wont to do.

I suppose it's possible that I'm the designated court jester and that's why I can get away with questioning, but I don't think that's the case :)

at the same time you have endless stories of people losing family and friends to cancer because a doctor dismissed complaints as anxiety or needing to exercise more leading to cancer not being discovered until it was too late to treat.

The answer can't be to put our collective heads in the sand.

IPv4 continues to be available to entities that have a need that fits a particular policy shape, just most people don't. Specifically, you can get IPv4 /24s for IPv6 transition purposes. This includes anycast DNS, MX, etc for legacy clients on other networks, v4-side of CGNAT, etc.

E.g. I was able to get a /24 in the ARIN region in 2021 and could justify 2 more for a _logical_ network topology similar to what NK presents to the world.

APNIC similarly has a pool available for IPv4 allocations: https://www.apnic.net/manage-ip/ipv4-exhaustion/#the-situati...

Trivially on their (and qnap's) amd64 systems at least. There are some quirks where they are more similar to an embedded system than a PC, but it's not a big deal. Things like console over UART (unless you add a UART) and fan control not working out of the box, so you set it to full speed in bios or mess with config.

Debian has docs on installing on at least one model of their arm boxes: https://wiki.debian.org/InstallingDebianOn/Synology

I run Debian on a few different models of qnap because their hardware occupies a niche of compact enclosure, low noise, and many drives.

There’s secret from an adversary and then there’s internal compartmentalization.

You could have 100s of people who have a business need to look at syslog from a router, but approximately nobody who should have access to login creds of administrative users and maybe 10s of people with access to automation role account creds.

TFA asserts that Git LFS is bad for several reasons including because proprietary with vendor lock-in which I don't think is fair to claim. GitHub provided an open client and server which negates that.

LFS does break disconnected/offline/sneakernet operations which wasn't mentioned and is not awesome, but those are niche workflows. It sounds like that would also be broken with promisors.

The `git partial clone` examples are cool!

The description of Large Object Promisors makes it sound like they take the client-side complexity in LFS, move it server-side, and then increases the complexity? Instead of the client uploading to a git server and to a LFS server it uploads to a git server which in turn uploads to an object store, but the client will download directly from the object store? Obviously different tradeoffs there. I'm curious how often people will get bit by uploading to public git servers which upload to hidden promisor remotes.

Reuters builds software for a variety of fields and maintains datasets that would be useful in identifying if, say, an email with an invoice purporting to be from a specific company aligns with the invoicing practices of that company.

It would be more accurate to compare that side of Reuters to LexisNexus, Wolters Kluwer, or perhaps Bloomberg.

I'm curious how well this article resonates with people outside a particular bubble (vs. being puzzling if you are inside a different bubble.)

The statement that Anduril sponsoring a NixOS conference was inherently damaging as opposed to the reaction causing the damage, "When did defense work stop being taboo" etc.

I've worked in the US Midwest->SFBay->US West and defense work never seemed particularly taboo in my circles, moreso that the work was boring and constricting.

Traditionally cautious sectors adopting a particular technology seems like a sign that a technology is viewed as having a particular level of dependability. That's a good thing.

Tailscale intentionally overrides your device's routing table to force traffic between hosts in the same subnet to go over a Wireguard tunnel instead of bypassing it. They do this because they believe that the presumption that a local subnet is trustworthy is false.

It works for me? That's normal behavior if you aren't signed into Twitter :(

Summary of thread: Society doesn't handle 2nd order consequences well. NK cryptolocker attack on healthcare-involved systems in British hospitals disrupted treatment to the extent that hundreds of people died who probably wouldn't have.

Expanding on that: Organized crime groups located in and sometimes tasked by RU SVR & GRU (not to mention NK state groups) have caused sufficient disruption to US healthcare systems to have indirectly caused more US Citizen deaths than the Sept 11 attacks. Right now cyber that does not directly cause destruction such as making buildings blow up or poisoning water supply is treated as just an annoying white collar crime.

I don't think anyone wants the US Government to be in a position where their options are to admit powerlessness or get proportional against nuclear armed states.

Somewhat related: https://blogs.icrc.org/law-and-policy/2023/10/04/8-rules-civ...

She was one of the people who literally built the technical foundation of the world we know. That alone justifies all the upvotes.

The fact that she did that on top of basically starting life over at 30 due to the constraints around transition at that time? That's winning a marathon with a cinder block chained to your ankle.

As far as the concentration of trans people in computing, AFAIK there are two predominant theories: First, survivorship bias involving careers that are often non-customer-facing and well-paying. Second, that there's common cause or comorbidity with other developmental differences (like ASD or 2SD+ IQ) that are unusually common among people who end up in computing.

I'm normally on a very minimal dose. I have, prior to getting timer tops and forgetting that I'd already taken med, taken >100mg of dextroamphetamine without feeling high and without titrating up. Instead, I got very focused and methodical to an uncomfortable degree, but there's absolutely zero high or euphoria.

Across ~4 doctors (1 PCP, 3 pysch), none have titrated up. They've ballparked and said things like "let me know and we'll reduce if you can't sleep and increase if it doesn't work. If you want, try doubling up or cut it in half (for non-XR)".

Given the variation in dosage visible in the literature (such as this case report of megadosing: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3407707/ ) I'd suggest that there are multiple underlying physical causes for the condition described as ADHD to the extent that sweeping statements like that aren't accurate. E.g. my (very different) experience and your experience being different indicates that we probably have different underlying causes, not that one is a myth or misperception and the other is the real take.

I have several CO2 monitors including some from AirThings, Aranet4, and a industrial sensor in the form of a Vaisala GMP252 CO2 probe. They all track closely enough that I don't worry about it. The Vaisala is rated to +/- 40PPM which is accurate enough for living space environmentals.

Automation is all very well once the network link is up and working so you can reach the automation

With properly constructed automation and modern* hardware, you don’t need to do any manual config on-box for automation to be reachable. Zero-Touch Provisioning is a wonder to behold.

Modern being relative. I saw this work on routers terminating telco circuits nearly 20 years ago and had servers netboot and install the OS with basic config before that (though automation was far more tedious back then)

I’m a NetEng for a large (>1M servers, >100 POPs) network that is IPv6-only internally.

It’s not hard to remember IPv6 addresses for DNS servers assuming your addressing plan reserved the right subnets for anycasted services.

Remembering IP addresses stops being a thing pretty quickly. If anything the challenge shifts to remembering airport codes.

If you are typing them by hand that often even in IPv4 networks I'd be worried about typos and insufficient automation.

I think it’s more that small and medium organizations just don’t have any incentive to change (and plenty of incentive to not take the risk of change) leading to the numbers we see at https://ipv6-in-real.life/

Lee McKnight, associate professor at Syracuse University in New York, said the widespread nature appears to be 'a massive Distributed Denial of Service (DDOS) attack on core Internet infrastructure.'

Really curious how _the quoted expert_ got "DDOS on core internet infrastructure" from this.

eNodeB or gNodeBs not broadcasting their networks would indicate a fault in the 4G/5G core (networks unique to each telco, not internet infra), which should be sufficiently isolated from the internet to not be DDoSable by random IoT devices.

This kind of fault would be more indicative of a configuration error, targeted attack, or external dependency. If the latter, I'm very curious who all of the major US telcos are depending on in that way...