3 ms·
Great that they respond so clearly and quickly. One question - does anyone else feel that having NGINX as the only link in the summary kind of suggests that it
by deckiedan 10y ago
Great that they respond so clearly and quickly.
One question - does anyone else feel that having NGINX as the only link in the summary kind of suggests that it's an nginx problem? I could imagine my previous boss reading the article, and 3 months later saying, "Wait what, we're using nginx??? Isn't that that shit that made cloudbleed happen?"
- zzzcpan 10y agoWhile they are not being precise in their response, you cannot consider nginx more secure. Nginx is still part of the problem, it had many CVEs too, even very similar memory disclosure vulnerabilities.
- Filligree 10y agoIt's written in C, which is part of the problem. I'd be very interested in a similarly-featured webserver (reverse proxy, mostly) which is written in a memory-safe language.
- atmosx 10y agoCaddy[1] is written in Go and has a nicer, simpler syntax. I'm sure NGINX has many more features though. [1] https://github.com/mholt/caddy https://github.com/mholt/caddy
- fortytw2 10y agoCaddy has less than half the performance of Nginx - not really a viable replacement at any sort of scale. https://hackernoon.com/caddy-a-modern-web-server-vs-nginx-e9e4abc443e#.wps7udz6x https://hackernoon.com/caddy-a-modern-web-server-vs-nginx-e9...
- Filligree 10y agoDepends on what you're doing. If it's fronting an expensive web-app, then the couple hundred CPU-microseconds needed to proxy a request isn't going to be noticeable... Caddy can serve 5,000 requests per second per core. I would flip your statement on its head, and say that a minority of people need anything close to that. The few companies that do, can probably afford to keep on top of CVEs for their frontends as well.
- shawabawa3 10y agoThat's misleading at best. Empty request benchmarks are indicative of nothing in the real world. For any reasonable workload, even serving static sites of a few kilobytes they will be effectively the same. Caddy's sane default settings (enforcing SSL, and with correct settings to get an A+ on SSL labs) make it the right choice for a lot of deployments
- rnhmjoj 10y agoIronically as I was considering Caddy as an NGINX alternative I found about a security issue that is very reminiscent of what happened at cloudflare: https://github.com/mholt/caddy/issues/1204#issuecomment-278193792 https://github.com/mholt/caddy/issues/1204#issuecomment-2781...
- Klathmon 10y agoWell, as nice as that sounds on paper, there's a reason we use reverse-proxies in the first place. It's because it turns out that opening anything up to the web is a whole can of worms of exploits, malformed requests, differently complying useragents, tons of standard, nonstandard, and "crazy off the wall bullshit" headers, and a LOT more. Greenfield writing a new safe reverse proxy that works within a magnitude of performance of something like nginx is a monumental effort. Not to mention the chicken-and-egg problem of how nobody will trust it until it has significant usage which it won't get until some people trust it.
- jbergstroem 10y ago> nginx hacked This caught my eye as well. Not sure what to do about it other than link/read the cloudflare blog post/incident report. FUD, etc.
- atmosx 10y agoHahahaha, you're spot-on actually, but that's why they're paying you, right? So you'll take 2 weeks worth of explanations on why NGINX has nothing to do with this! BUT... The moment you passed your argument through a severe vulnerability related to NGINX (doesn't even have to be directly related, mind you!) will be disclosed and you're boss will jump-in screaming "I KNEW IT, NGINX IS BEHIND ALL THIS!" (he'll be spelling it correctly by then :-P )
- jln 10y agoI think you're right: including NGINX in the summary is a distraction, and highlighting it as a link makes the wrong implication. I'm a developer at Monzo, so I've tweaked the blog post to remove the reference. Thanks!