Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
imbriaco
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
Counterfactual Thinking, Rules, and The Knight Capital Accident
(kitchensoap.com)
4 points
by
imbriaco
13y ago
|
0 comments
62.
▲
by
imbriaco
13y ago
Very few resolvers break DNS TTLs in that way anymore. Google certainly honors TTLs down to at least 30 seconds. I'm not aware of any major ISPs that get this wrong anymore either. This hasn't been a significant problem in years.
63.
▲
by
imbriaco
13y ago
It turns out they are actually big problems. You can't dream them away. What would have actually happened is Microsoft would have had a customer revolt on their hands and not sold any Xbox One consoles -- I think they have enough probl
64.
▲
by
imbriaco
13y ago
You are incorrect. The usual process in cases where the government subpoenas data from service providers is for the service providers to gather the data and supply it to the government. Doing anything else is nearly nonsensical since the go
65.
▲
by
imbriaco
13y ago
It's not their fault, we were in the middle of provisioning and service validation with them but it wasn't completed. We're had to work through some issues on the fly that we were trying to do non-disruptively, but they'
66.
▲
by
imbriaco
13y ago
Nope, we're on 1.9. We were briefly on 2.0 (last week) but had some minor performance regressions that we need to understand before we go back.
67.
▲
by
imbriaco
13y ago
The "huge swaths of the internet" part is poorly phrased in the article. What they're basically saying is that there are a large number of DNS servers on the Internet that allow anyone to query them. Attackers query those ser
68.
▲
by
imbriaco
13y ago
Indeed, and you can almost certainly buy a server for the cost of the reservation. Don't get me wrong, EC2 is an amazingly useful platform and it has been a game changer for our industry in a lot of ways. Improved hosting economics isn
69.
▲
by
imbriaco
13y ago
If it's just three servers, I'd be astonished if any meaningful amount of time was spent maintaining the hardware after the initial installation. You have to maintain the operating system in either case, so this is a clear win for
70.
▲
by
imbriaco
13y ago
You should also point out that's a 20 year old Cessna 150.
71.
▲
by
imbriaco
13y ago
Google and Facebook are not intelligence agencies.
72.
▲
by
imbriaco
13y ago
Before you decide to be condescending, you should probably freshen up yourself. The vast majority of merchants fall into PCI-DSS Level 2-4. Those merchants complete a self-assessment questionnaire (SAQ), in other words, self-reporting. They
73.
▲
by
imbriaco
13y ago
It doesn't really matter. A phisher could write an entirely different message with a link in it just as easily.
74.
▲
by
imbriaco
14y ago
Nope. This was a pretty standard DoS attack.
75.
▲
by
imbriaco
14y ago
It's pretty clear that it was a failure of CloudFlare's profiler in generating an obviously impossible rule, the engineer who attempted to apply that rule, and Juniper for allowing it. There's no one place to lay blame, nor is it relevant.
76.
▲
by
imbriaco
14y ago
I'm really confused where people are coming up with the idea that the word "intelligent" is somehow a synonym for "queueing". That doesn't make any sense to me. The intelligent part of it is that it knows which servers and ports your applic
77.
▲
by
imbriaco
14y ago
For the record, it's unlikely that the outages were caused due to differences between the versions so much as they were caused by the changing load patterns on the cluster and the old Java version.
78.
▲
by
imbriaco
14y ago
You should check out iperf as well.
79.
▲
by
imbriaco
14y ago
Good work from Amazon putting together the post-mortem. Whether you agree or not with their remediation plans, they hit the important parts of a public post-mortem very well: 1. Demonstrate understanding of the event. 2. Communicate what st
80.
▲
by
imbriaco
14y ago
You're right on all counts. We have a great many plans with regard to how we want our network to operate that are underway.
81.
▲
by
imbriaco
14y ago
Thanks, I really appreciate that. For me, the motivation for transparency came from too many frustrating instances of being kept in the dark after things had gone wrong. The worst thing both during and after an outage is poor communication,
82.
▲
by
imbriaco
14y ago
We have significantly more than 33 servers.
83.
▲
by
imbriaco
14y ago
I appreciate your point of view but respectfully disagree. The post-mortem would have absolutely been less accurate if we had delivered it sooner since we did not have the details about why the MLAG failover did not happen as expected until
84.
▲
by
imbriaco
14y ago
I would have been less offended if your initial comment wasn't as presumptuous. You most certainly have a right to participate in the conversation, but there was no useful content in the post. It came across in exactly the same was as the e
85.
▲
by
imbriaco
14y ago
Our goal with this change was not to radically redesign our network in one bite. We are making incremental improvements in our existing environment to solve very specific, ongoing problems. Given the flexibility to completely rearchitect ou
86.
▲
by
imbriaco
14y ago
That is super interesting, thanks for the pointer. Looking forward to reading over the paper.
87.
▲
by
imbriaco
14y ago
Shameless is exactly right. Any inclination I may have had to even consider looking at your product just evaporated.
88.
▲
by
imbriaco
14y ago
It was a lock that was being held by software but also prevented hardware updates to certain hash locations in the CAM. So MAC addresses that hashed to those locations couldn't be learned by any means.
89.
▲
by
imbriaco
14y ago
Yes.
90.
▲
by
imbriaco
14y ago
Yeah, if you read a little further down we worked with the vendor to get them extensive diagnostics and get to the root problem. TL;DR: Lock contention on the CAM table. "We have worked with our network vendor to provide diagnostic informat
More ›