Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
patrickmcmanus
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
61.
▲
Hacking Team targetted local exploits of Tor
(firstlook.org)
4 points
by
patrickmcmanus
11y ago
|
1 comments
62.
▲
by
patrickmcmanus
11y ago
tax-loss harvesting is particularly valuable when combined with charitable giving.. the usual harvesting dynamic is that you are trading a deduction now for a larger gain-liability later, but in the case of charitable giving of appreciated
63.
▲
by
patrickmcmanus
11y ago
domain sharding gives you parallelism - but it totally bypasses congestion control. At certain levels this works in your favor - because congestion control tends to be overly conservative for HTTP - but at levels of sharding too high it is
64.
▲
by
patrickmcmanus
12y ago
fwiw the reference in the blog post about integrity protection and random network noise was a reference to the inadequacy of the tcp/ip checksums for protecting your data from normal network errors of the accidental non-attacking varie
65.
▲
by
patrickmcmanus
12y ago
fwiw the h1 barrier was the lack of a scheme indication in an h1 transaction - not really the alpn ids (which can always be registered if need be). But without a scheme the server just needs to infer http vs https from the port/address
66.
▲
by
patrickmcmanus
12y ago
firefox 36 will negotiate any of {h2, h2-14, h2-15}
67.
▲
by
patrickmcmanus
12y ago
arbitrary levels of prioritized multiplexing within a functioning congestion control context is the killer feature of http/2. header compression exists merely to enable that as an implementation detail.
68.
▲
by
patrickmcmanus
12y ago
try ss -nt instead.. it uses netlink sockets instead of /proc and generally scales much better
69.
▲
by
patrickmcmanus
12y ago
I wanted to support the big picture idea of your comment about packet loss not being inherently bad. Too many strategies are based on the principle that every packet is precious rather than total system goodput. Indeed TCP congestion contro
70.
▲
by
patrickmcmanus
12y ago
Its a fair question but the h2 approach is doing the right thing on balance. The issue isn't really computational or memory requirements. The startup phase of a TCP stream is essentially not governed by congestion control feedback beca
71.
▲
by
patrickmcmanus
12y ago
otoh - http on sctp on ipv6 with ipsec hasn't really moved the internet forward.
72.
▲
by
patrickmcmanus
12y ago
The first answer is that parallelism without priority (which is what parallel h1 is) can lead to some really horrible outcomes. Critical pieces of the page get totally shoved out of the way while bulky, but less important parts, get the ban
73.
▲
by
patrickmcmanus
12y ago
you're right. Cancel's in H1 are very painful because all the in-progress transactions have to be torn down completely. New transactions have to set them all up again. H2 let's you just send the server a short message that sa
74.
▲
by
patrickmcmanus
12y ago
right. The other key fact is that request header compression is necessary to make parallelism work when interacting with tcp congestion control. Its critical.
75.
▲
by
patrickmcmanus
12y ago
> If it's public static content, what is SSL protecting? https:// helps protect the act of participation and deters the building of dossiers. Its the difference between the books in the library and the list of books in t
76.
▲
by
patrickmcmanus
12y ago
The semantics of the URL aren't different - just the protocol version details. You didn't want different schemes for http/1.0 vs http/1.1 right? The URL still represents the same resource and if the server would like to
77.
▲
by
patrickmcmanus
12y ago
i'm a firefox dev. That sounds like a sender (i.e. server) bug, but I'd like to rule out a client problem. Can you send me a specific steps-to-reproduce at pmcmanus@mozilla.com ?
78.
▲
by
patrickmcmanus
13y ago
the wrs book wears very well. he was a good man. as an aside, its generally a mistake to use IP-Size > PMTU (commonly ~1500).. the result is IP fragmentation and IP stacks commonly have very limited resources devoted to IP reassembly (ot
79.
▲
by
patrickmcmanus
13y ago
That's a variation of FEC and its good stuff http://en.wikipedia.org/wiki/Forward_error_correction we're seeing it come back into vogue in TCP and modern protocols. QUIC has a FEC component and TCP Tail Loss
80.
▲
by
patrickmcmanus
13y ago
The article emphasizes that TCP congestion control can make TCP underperform with respect to the actual available bandwidth. So True and So Frustrating! But it doesn't seem to talk about the virtues of congestion control - the primary
81.
▲
by
patrickmcmanus
13y ago
indeed - but I think its even worse than that, because even "faster" is rather contextual. proxies can inject dog leg routes, single points of failure, computational and i/o bottlenecks and they make lovely centralized dos an
82.
▲
HTTP/2 Considerations and Tradeoffs
(insouciant.org)
7 points
by
patrickmcmanus
13y ago
|
0 comments
83.
▲
by
patrickmcmanus
14y ago
Optional features tend to be broken in practice. So HTTP/2 is trying to have far fewer of them so that implementations will be more robust. Chunked requests and pipelines are good examples. They are rarely used but absolutely supported by t
84.
▲
Trekking the Road from SPDY to HTTP/2 in Firefox
(bitsup.blogspot.com)
31 points
by
patrickmcmanus
14y ago
|
13 comments
85.
▲
by
patrickmcmanus
15y ago
https://www.google.com/ for a little thing called "google search" using spdy! Spdy actually shines brightest on things like plus.google.com or picasa because of all the little icons.. images.google.com is also a very big beneficiary. It w
86.
▲
by
patrickmcmanus
15y ago
SSL rules remain the same, and SPDY runs over SSL. My opinion - get a real signed cert. A basic free one from startssl.com is available. The PKI has problems to be sure and needs to evolve. But simple forms of eavesdropping and MITM attacks
87.
▲
by
patrickmcmanus
15y ago
The link above is to a version being specified, not yet deployed. (v3). Its fair to say that v2 is deployed and was well documented and that google was very responsive to technical inquiries about it. The firefox and chrome implementations