Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jsn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
17 ms
·
121.
▲
by
jsn
17y ago
A funny hack. He uses "while" loops with "continue" to emulate backward jumps. Not sure how he does forward jumps (is it implemented at all? "break" could help, i suppose..) Anyway, AFAICS, cross-function gotos are impossible with this impl
122.
▲
by
jsn
17y ago
Why FastCGI, though? Proxying HTTP to backends seems to work just fine.
123.
▲
by
jsn
17y ago
Sorry, wrong again. Stream byte acks are way more effective than packet ones. Tcp endpoint can receive several packets of data and then send just one very small ack packet (you only have to send the byte stream position after the last rec
124.
▲
by
jsn
17y ago
When your byte-trading program encourages you to trade bytes, there's nothing to be upset about. When your [web based] pdf reader forces you to trade bytes -- well, some people get upset. IMHO, you should have rather used rapidshare or mega
125.
▲
by
jsn
17y ago
They don't acknowledge packets, just bytes. It's pretty reasonable for a reliable streaming protocol. Their DDOS attacks target our servers. For example, Russia has some issues with Estonia, opposition sites post some independent statements
126.
▲
by
jsn
17y ago
1. You're wrong, see rfc793. TCP flow control acknowledges streamed bytes, not packets. 2. I just tell you what works in real life. Blocking 500 supernodes (out of 5000 machines botnet) is basically a non-issue for linux iptables on usual m
127.
▲
by
jsn
17y ago
Sorry, most of that is wrong :) 1. No, it's not the simplest approach. The attacker can trivially send perfectly credible set of headers, then start receiving the response, acknowledging 1 byte per 30 minutes. It's routinely seen in the wil
128.
▲
by
jsn
17y ago
It's trivial to counter indeed; you don't need any packet inspection for that. The main anomaly is not in the header structure, it's in the number of sessions opened simultaneously by one host. This particular tool uses broken headers for s
129.
▲
by
jsn
17y ago
And this is news somehow? Color me unimpressed. First time we'd been subjected to this kind of attack was, what, a year ago? Maybe two. It's a trivial next step after the old boring flood of http get requests.
130.
▲
12th annual ICFP programming contest begins next weekend
(icfpcontest.org)
3 points
by
jsn
17y ago
|
0 comments
131.
▲
by
jsn
18y ago
it's probably a discount for future dividend cuts / bankruptcies.
132.
▲
by
jsn
18y ago
the tin foil folks here in russia think that google has ( cough ) somehow persuaded the regulators to block the deal, because google thinks they can acquire the same company (or, in fact, some other company) for a much lower price in a few
133.
▲
by
jsn
18y ago
the main shock for an average soviet citizen quickly becoming a russian citizen probably wasn't the abrupt drop in the quality of life [though there sure was quite a drop]. it was more about how to live when nobody tells you what to do ever
134.
▲
by
jsn
18y ago
well, i was born in ussr and i've seen it collapsing. i have to say that the author is full of it. the main sources of troubles in collapsing ussr were, in no particular order: * dying agriculture sector and massive dependence on imported f
135.
▲
by
jsn
18y ago
http://www.gandi.net/hosting/proposal/price/ it's pretty much an elastic cloud. i didn't try it myself yet, though. unmetered bandwidth in 5mbps increments, plenty of other resources, and very attractive pricing. i think it's as good as i
136.
▲
by
jsn
18y ago
Last time we were under serious ddos, the attack vector shifted several times in response to our countermeasures. One of those shifts was looking quite similar to what fyodor describes. An attacking machine opened 1000+ connections, sent th
137.
▲
by
jsn
18y ago
nothing runnable there, unfortunately. sorry, i should've noticed the "Note:" there.
138.
▲
by
jsn
18y ago
oops. right. shame on me.
139.
▲
by
jsn
18y ago
the source and build instructions for linux are available. checking it out now, but it will probably take a while on my laptop. edit: http://dev.chromium.org/developers/how-tos/build-instruction...
140.
▲
by
jsn
18y ago
you probably don't need perl for that. afaics from the snippet, it fits into nginx mod_rewrite. maybe something like this: if ($http_cookie ~* "auth=1" ) { proxy_pass http://backend ; break ; } if (!-f $request_filename) { pr
141.
▲
by
jsn
18y ago
not if you normalize by e.g. minimal string length.
142.
▲
by
jsn
18y ago
Not really impossible, just much harder, much more expensive, took much longer, etc. The usual story with The Right Thing. And that's exactly the point i was trying to make. The Right Thing is hard, that's why it fails. What Schneier sugges
143.
▲
by
jsn
18y ago
It's good old "worse is better" all over again. Of course we should design our protocols and our software as The Right Thing. Of course, it will take much longer to design and implement; or, worse, it might just fail because it's hard to fi
144.
▲
Amazon S3, July 2008, and Bell Systems, January 1990
(jsn13.blogspot.com)
23 points
by
jsn
18y ago
|
2 comments
145.
▲
by
jsn
18y ago
Or, one possible way to prepare for some big future war is to facilitate a surplus of young single men. And that should apply equally well to different kinds of "hot" and "cold" war.
146.
▲
by
jsn
18y ago
insulting the scribd product is somewhat unfair, imho. it's not that the product is inherently bad or something. maybe someone finds it useful (ycombinator owners apparently think so). i certainly don't, so i use my greasemonkey script to r
147.
▲
by
jsn
18y ago
rsync is usually configured to use ssh by default. no need for -e.
148.
▲
by
jsn
18y ago
no, the link you posted is my script.
149.
▲
by
jsn
18y ago
my version ( http://userscripts.org/scripts/show/26925 ) was there 1 minute before that :)
150.
▲
by
jsn
18y ago
or they might just add a hyperlinked "[pdf]" or "[scribd]" after the original link, pointing to scribdified version. internets ignoring my choice of pdf viewer -- that sure feels wrong. oh well, greasemonkey to rescue.
More ›