5 ms·
Normally you need to know ahead of time what your server is going to be used for and write the code in advance. But with Erlang, you can have a distributed net
by brokencode 3y ago
Normally you need to know ahead of time what your server is going to be used for and write the code in advance.
But with Erlang, you can have a distributed network of Erlang servers where the server is a generic computing resource that can do anything the client wants.
The code actually comes from the client. No need to get your system administrators to install some binary on all the machines. You simply pass the function along and the remote machine calls it.
- refactorworks 3y agoThanks! I get it — no need to install binaries of specific servers.
- rramadass 3y agohttps://news.ycombinator.com/item?id=37415159 https://news.ycombinator.com/item?id=37415159
- nesarkvechnep 3y agoDouble check whether you think of the correct abstraction level. The BEAM is more like the JVM than Kubernetes.
- zbentley 3y agoOne of the most interesting characteristics of the BEAM, in my opinion, is that it's similar to both. As a memory-managed bytecode runtime it's similar to the JVM, and as a distributed process orchestrator+discovery and RPC system, it's similar to Kubernetes. I often wonder what would have happened if the "BEAM renaissance" (driven largely by the birth of Elixir and associated tools) had happened a decade earlier, before Kubernetes became the de-facto standard for ad-hoc distributed computing in web software.
- zaphirplane 3y agoA few people here are liking the idea, isn’t this the exact definition of arbitrary code execution (exploit) It’s possible people are showing the capability of BEAM thou
- coldtea 3y agoIt's the definition of any distributed system (or even single server) where you can deploy code, whether it's Erlang or a kubernetes cluster you setup. Is pushing new code for your server to run "arbitrary code execution"? I guess we can call it that. Is it an exploit? Depends if the code comes from some random person on the internet from mechanisms that you don't intend for pushing new code to run (e.g. through a buffer overflow on your server or XSS), or if it comes from yourself through your official mechanisms.
- jerf 3y ago"Arbitrary code execution", yes, "exploit", no. You need to be "inside" the BEAM cluster and a member of the BEAM cluster to do this. That is not something you hand off to end users, just as you do not normally hand end users direct access to your database socket or other such resources. In Raymond Chen's terminology [1], if you're sending Erlang terms to the BEAM cluster, you're already on the privileged side of the airtight hatchway. [1]: https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31283 https://devblogs.microsoft.com/oldnewthing/20060508-22/?p=31...
- brokencode 3y agoOnly if you allow untrusted clients to join to the cluster. To really make use of something like this, you’d have to control the clients rather than opening it up to anybody on the public internet.