HN user

samplonius

122 karma
Posts0
Comments74
View on HN
No posts found.

Anything that uses clear-text passwords has been removed. That is a very clear red-line. Also, anything that uses weak encryption, like P2PTP has also been removed, but a few versions ago. And the ssh defaults are tightened up almost every point release. As soon as a cipher becomes known as "weak", Apple pulls it.

I don't get why Houston wants to spend $400M on a reservoir. Sure they need a reservoir, but they need all of the other stuff too. Perhaps if they had $4B budget, they could actually fix everything that needs to be fixed.

Houston needs to get to the point that they can handle 60+ inches of rain in a 24 hour period. Token efforts might keep their budget balanced and the voters appeased until the next election, but they're getting 100 year storms so frequently now, they'll have to stop calling them that.

Climate change is great and all, but even if you sharply cut carbon emissions today, it would take a years before 100 years storms went back to their previous frequency.

I'm not aware of any routers that can forward IPv4 in hardware, but pass IPv6 to the control plane.

Even the discontinued Catalyst 6500, which was used (and still is) by a lot of ISPs with the SUP720 supervisor, can do native IPv6.

I think you are completely wrong about this. Routers with native IPv6 were available 15 years ago, and are already getting pulled out to be replaced by the new stuff.

The reality is that, that ISP tier 1s use either Juniper MX or Cisco ASR9000 routers. These routers have good IPv6 performance.

That is generally the opposite of reality. IPv6 is generally faster than IPv4.

I don't know what "a couple of years ago" is, but all tier-1 ISPs have IPv6 backbones. There should be no reason for your access ISP to have to tunnel anything to get to a tier-1.

Your statement "Most ISPs (including mine) are using 6rd gateways to get their customers onto the IPv6 backbone" is kind of a red flag. If ISPs aren't connected to a backbone, can you even call them an ISP?

Except for DLC. A AAA title will need to ship at least 4 x DLCs over a 12 to 18 month period. And no doubt the DLC development will expose serious bugs along the way, so the DLC will have to contain patches as well.

The lifespan of AAA titles is longer now that most are purchased digitally.

I think it is important to note that Rackspace got into AWS and Azure services, because the dedicated physical servers business was dead man walking. While Rackspace did introduce virtualization and other services running on their own hardware, they would never be able to touch Amazon's industry sized scale.

There is a probably a consumer device that has a GRE listener running, and it is possible to send it a small packet, and it will return back some sort of error response. So classic amplification.

Thought given the moderate amount of traffic, maybe it isn't a hugely effective DDoS method.

Even if a consumer device doesn't use GRE, it doesn't mean it isn't there. GRE is often included in Linux kernels.

So "space" is some magical place where measurement error does not exist?

Low earth orbit isn't perfect either. You still have micro gravity. And the experiment requires a lot of power, and very sensitive instruments to measure the phenomenon. How do you get sensitive instruments which are expected to be operating near their error threshold into orbit without damaging them?

Orbital experiments will have to be smaller, and use less power, so the effects will even be smaller. But the instruments will have to be tough enough to withstand 5G. And the apparatus could still be introducing other errors, like coolant momentum, which also isn't magically eliminated by being in space.

Yes, but they can be flooded as well. Every system is going to have a finite capacity. And if the capacity is exceeded, the system will slow. If the capacity is significantly exceeded, it will become unreachable itself.

So if the capacity of your system is X Gbps, then it will start to have problems if the attacker sends X + 1 Gbps. And will probably be completely unreachable if the attacker sends X * 2 Gbps.

There is an incentive: it is the cost of transit. However, there usually are not a lot of zombies per single ISP for the access level ISP to even see any abnormal traffic.

The best thing is that access ISPs need to implement BCP38 (https://tools.ietf.org/html/bcp38). And shutdown all open recursive DNS servers. It would be great if Microsoft didn't ship such a retarded DNS server too. I would say that most ISPs do not do this.

NTP really should be replaced with something better. There are still large numbers of NTP amplification attacks going on. The big issue with NTP today, is that by default ntpd in daemon mode, is also a NTP server and responds to NTP requests. And so many of the two bit home routers run ntpd.

But the reality is, that no one is even reporting DDoSes right now. I work at an ISP, and I haven't seen a DDoS report in the past year. We pro-actively scan for open DNS and open NTP services. But many DDoS attacks just use regular HTTP/HTTPS, are hard to detect at the individual network connection level. Do you think Akamai sent out a single notice to any ISPs, saying "The following X IPs are sending excessive traffic to site Y, and are suspected to be part of a botnet"?

You are not the first to come up with this idea. This same thought has been posted every year for the past 20 or so years in mailing lists, forums or Usenet (thought lately, not too often to Usenet).

I think prevention should be emphasized. If there wasn't so much garbage plugged into the Internet, there wouldn't be huge botnets to send DDoSes. There are few groups that scan the Internet for vulnerable systems, and rather than compromise them, send notices to the ISPs. In Canada, the CCIRC does this. But they only check IP blocks assigned to Canadian ISPs and enterprises.

Plus, why do so many ISPs still allow spoofing of IPs? It isn't 1999 anymore.

We should start a grass roots group to talk to everyone they meet, and get people to update their OSes, devices, and get rid of crap.

He doesn't get to "keep every penny". There is such a thing as personal income tax, and in Canada is going to be over 50%.

Hopefully, the deal was structured with some stock, or paid to a corporate entity. Because if he received a cheque made out for $575M, most of that money went to tax. If it was made out to his personal corporation, he'd just have to pay corporate tax on it, which is about half as much. But would still be over $100M.

Please laws over ride TOS?

Can you add a item to the ToS that says: Vendor is allowed to kill customer at any time during contract term?

Maybe that is a bad example, since assisted suicide is basically that.

It is not that Netflix is being access, but what on Netflix is being accessed.

Netflix does not publish viewership information. But a large ISP could run DPI on Netflix traffic to determine what content is being viewed. And since many ISPs have their own TV product, they would be really interested in that information themselves.

But if Netflix streams at TLSed, then good luck figuring out Archer from The Lust of the Dead.

It also assumes the future people will be even dumber than the present population?

But also isn't it a treasure trove? Nuclear waste can be reprocessed into fresh fuel. The waste has a large amount of useful energy left.

The plan in the US was to enrich waste in breeder reactors, mix in some fresh fuel, and re-use it. It was the nuclear fuel cycle. Lots of resources on the technology.

There were two problems. The use of breeder reactors had some proliferation concerns: they can be used to make warheads. Not a big deal in the US, as the US can already make warheads, but harder if you want to export nuclear waste reprocessing to other countries.

Transporting the waste was deemed risky. More so after 9/11, as fresh waste is so radioactively hot, it needs to be kept in water, or it will overheat. If you crash a plane into a transport vehicle, or a re-processing plant, it will create quite a mess.

So there is no way the nuclear waste will stay in the ground for 10,000 years. I suspect it will be less than a hundred years before someone digs it up, and reprocesses it.

Burying nuclear waste is itself waste.

I debate whether multicast has any use case in gaming.

When online gaming started, it was fairly common to send the entire world state to all clients. Multicast helps when you are sending the same data to everyone. but online gaming started, worlds were small (think Quake I level). However, this type of model does not scale as the world size increases, and eventually the world is too big to send everything to every client.

Plus, cheating. Sending the entire world state to every client, opens up cheating vectors. The trend has been for the game server to send only state that the particular client can actually see or needs. This limits the damage of what a compromised client can do. Plus, it allows the world size to scale up.