HN user

solaris2007

-17 karma

CTO of a medium sized company in Silicon Valley.

Going forward I'm just going to write whatever comes to my mind. If you actually thought I care about updoot good-boy points like you do I (along with everyone else who knows what a vagina looks like) view you with pity and contempt.

Alt account.

Posts0
Comments31
View on HN
No posts found.

But the moment two sites share the same address range, you have an ambiguity that IP routing cannot resolve.

Writing PF or nft rules to NAT these hyper-legacy subnets on the local side of the layer3 tunnel is actually super trivial, like 20 seconds of effort to reason about and write in a config manifest.

Like written the article, a device on the customer site is required. At that point you might as well deploy a router that has a supportable software stack and where possible sober IP instead of legacy IP.

.

I have been running IPv6-only networks since 2005 and have been deploying IPv6-only networks since 2009. When I encountered a small implementation gap in my favorite BSD, I wrote and submitted a patch.

Anyone who complained about their favorite open source OS having an IPv6 implementation gap or was using proprietary software (and then also dumb enough to complain about it), should be ashamed of themselves for doing so on any forum with "hacker" in the name. But we all know they aren't ashamed of themselves because the competency crisis is very real and the coddle culture let's such disease fester.

There is no excuse to not deploy at minimum a dual-stack network if not an IPv6-only network. If you deploy an IPv4-only network you are incompetent, you are shitting up the internet for everyone else, and it would be better for all of humanity if you kept any and all enthusiasm you have for computers entirely to yourself (not a single utterance).

This may come as a shock to someone stuck in a radical far left bubble but people who are not either a citizen of one of the several states or not a citizen of the federal government (nor both) are not parties to the agreement that is the constitution.

"concentration camp" isn't a root command line term to people with critical thinking skills.

Anyone who is neither a state citizen or federal citizen and does not have a valid VISA (or some equivalent) is an unlawful invader.

Again, this may come as a shock to someone stuck in a radical far left bubble, but most Americans' sentiment, the Americans who are busy raising their families, the ones who actually pay all the taxes that pay to house and feed all of these unlawful invaders stuck in limbo is: they are lucky we don't just kill them all.

I know it's shocking to those stuck in a radical far left bubble, but it's the reality. The state governments and federal governments were formed to protect what the founders wrote: "our posterity". Not every third world rando who shows up for the gibs Biden promised rather than fix their own country.

If you want to be effective in your activism, try to avoid "rhetorical correct" terms. Those terms only work on a particular lower class and only piss off the people with critical thinking skills because it comes across as trying to bullshit them in a malicious way (which it is).

edited: to add "(or some equivalent)"

The Sig P320 that an agent took off of him went off while it was in a federal cop's hand. This is the same Sig P320 that the US Army rejected and was mass recalled for going off on its own.

Unfortunately, when the shot went off he was still fighting with them, actively resisting and not complying. Fighting with federal cops like that is a good way to get killed. He played a stupid game and won a stupid prize.

Perfect. Now all they need to do is set up the redirect.

Every bot is doing something on behalf of a human. Now that LLMs can churn out half-assed bot scripts every "look I installed Arch Linux and ohmyzsh" script kiddie has bots too.

Bots aren't going anywhere.

"Use the web the way it was over 10 years ago plox" isn't going to do it.

Make the data available through bit-torrent and IPFS. Redirect IPs that make excessive requests to response only kilobytes in size "use the torrents and IPFS".

As an SRE, the only legitimate concern here could be the bandwidth costs. But QoS tuning should solve that too.

Supposedly technical people crying out for a journalist to help them is super lame. Everything about this looks super lame.

SmartOS 6 months ago

In 2014 and 2015 I was able to make some great things happen because of the people (mostly former Sun people) in the #smartos and #illumos IRC channels on Freenode. They were very helpful. Maybe this is because I put actual thought and effort into my questions and didn't waste their time with stupid questions (ones already answered in documentation or found in mailing lists).

  https://www.catb.org/esr/faqs/smart-questions.html
SmartOS 6 months ago

I am on a team that runs database services (mostly Postgres and DuckDB) on an internally maintained illumos branch that runs in VMs on the client's Oxide racks.

Dtrace, Zones, and an "untainted branch" of ZFS are the main reasons given when I asked why illumos and not Linux. I did later see the light (heh) with the Dtrace part for sure.

Are there any workloads (other than as a VM host) that run on SunOS derived OSes?

Pretty much any workload that runs on Linux or BSD. The exceptions that are notable are Ceph and "big network" applications like XDP/VPP/DPDK centric stuff like edge router or DDoS protection.

Zones provide full security isolation. A downstream user can have root in an illumos Zone and there isn't anything to worry about other than CPU side-channel flaws (which are or are not a problem depending on use case). FreeBSD's Jails, as shown by a 39C3 talk given this winter showed that the FreeBSD kernel is highly vulnerable to processes running as root within a Jail. Security isolation that can be relied on for untrusted workloads in Linux, in the form of containers at least, never really materialized.

SmartOS 6 months ago

SmartOS was Joyent's distribution of illumos, like how RedHat Linux is a distribution of Linux. Oxide's rack-scale compute is powered by Oxide's illumos build named Helios.

  https://rfd.shared.oxide.computer/rfd/0026

  https://github.com/oxidecomputer/helios

Rights can be extended through contracts. A lawyer at Spotify might think to put in: "we distribute the music for you, your right to enforce copyright or otherwise litigate on behalf of that music is also extended to us as if we also own it".

The legal language would be different, that's a dumbed down version.

Think of the gravity that Instagram/Facebook has today, or maybe things are different today, so had for millennials. Try to take away a young adult's phone today, you'll risk being eliminated. We had some neat handhelds with PCMCIA slots that OpenBSD ran on in those days but it was only the kids in "rich" neighborhoods that also had them and I was a year behind in getting those. The critical mass of the network effect at that time was on desktops and iBooks.

super hot girls

Yeah a San Francisco 7 was like an 8 in Los Angeles and easily a 10 in most towns (in those days).

They were prowling MySpace just as much as anyone else. You know what they're up to.

That is a priggish statement

A cursory glance at the definition of "prig" shows that what I wrote there is categorically not. You should at least try to look up that word and if you look it up and still don't get it then what you have is a reading comprehension issue.

Typescript is what I choose for most tasks these days.

So you're smart on this, at least. Cantrill said it really well, Typescript brought "fresh water" to Javascript.

haven’t noticed any real difference between my past C#, C++, C, Java, Ruby, etc programming peers and my current JavaScript ones.

You might still be on their level. I see that you didn't mention Rust or at least GoLang. Given the totality of your responses, you're certainly not writing any safe C (not ever).

A long time ago the power supply blew out in the machine I played Counter Strike: Source on and I was a teenager just barely 16 with no money so I couldn't replace it.

I was able to keep in touch with my drug dealers and my girlfriend's friends (who were also all super hot) which was very important to me at that age, in an environment where you really needed a car or people who had cars to do anything with anyone worth doing anything with.

I got OpenSolaris booted on a Pentium II box that had 384mb of RAM then ran Openbox and a communications suite of SILC, IRC, Pidgin, Finch (a text frontend to libpurple), and some XMPP+OTR clients -- all in Solaris Zones to not get my shit wrecked by the same RCE exploits I was using against other Pidgin users (which seemed to be as numerous as exploits for the official AIM client). This was before Facebook.

Solaris Zones gave me that feeling of power over software that Qubes enthusiasts like to talk about, similar dopamine+endorphin flow to being a military dictator of a 3rd world country. Shit was so cash.

Thanks to Unix' elegance, I still had a life until moved enough herb to assemble another box I could run Counter Strike: Source (on FreeBSD, Cedega for the win) on.

If you can't figure out how to store dependencies locally you shouldn't be operating a network so everything kind of balances itself out.

This interview the day after the "cancelling" debacle sheds full light on the whole thing.

  Hotep Jesus' podcast - Scott Adams Interview
  https://rumble.com/v2axwg2-scott-adams-interview-its-okay-to-be-white.html

That we see someone on Hacker News (of all places) repeating this smear validates Adams' repeated statements on his video podcast that he had a valid defamation claim against the hate group that pushed this smear.

The man just died and random people are repeating smear campaigns against him that are directly contrary to what his actual beliefs were.

This is horrible and pretty fucked up.

If a situation where production vxlan is going over Wireguard arises, then someone in leadership failed to plan and the underlying Wireguard tunnel is coping with that failure. No doubt, OP already knows this and all too well.

The problem is no doubt a people problem. I have learned to overcome these people problems by adhering to specific kinds of communication patterns (familiar to Staff Engineers and SVPs).

There is no reason that Wireguard over vxlan over Wireguard can't work, even with another layer (TLS) on top of Wireguard. Nonetheless it is very suboptimal and proprietary implementations of vxlan tend to behave poorly in unexpected conditions.

We should remember that vxlan is next-get vlan.

The type of Wireguard traffic encapsulated within the vxlan that comes to mind first is Kubernetes intra/inter-cluster pod-to-pod traffic. But this Wireguard traffic could be between two legacy style VMs.

If I were the operator told "you need to securely tunnel this vxlan traffic between two sites" I would reach for IPsec instead of Wireguard in an attempt to not lower the MTU of encapsulated packets too much. Wireguard is a layer 4 (udp) protocol intended to encapsulate layer 3 (ipv6 and legacy ip) packets.

If I were the owner of the application I would bake mutual TLS authentication on QUIC with "encrypted hello" (both elliptic and PQ redundant) into the application. The applications would be implemented in Rust, or if not practicable to implement the application in Rust I would write into the Helm chart a sidecar that does such a mutual TLS auth part (in Rust of course).

I would also aggressively "ping" in some manner through the innermost encapsulation layer. If I had tenancy on a classic VM doing Wireguard over the vxlan I would have "ping -i 2 $remote_inside_tunnel_ipv6" running indefinitely.

AWS designs and implements their foundational services holistically. I can understand that the services "higher up the stack" may not feel this way to AWS customers sometimes. However, the foundation of VPCs, EC2, EBS and S3, are very strong.

If the word "production" is suppose to really mean something to you, move your workload to Google Cloud, or move it to AWS, or on https://cast.ai

Disclaimer: I have no commercial affiliation with Cast AI.