I just wonder why MIT didn't give more time to move and why it doesn't provide a replacement in eg cloud credits.
I just wonder why MIT didn't give more time to move and why it doesn't provide a replacement in eg cloud credits.
Disclaimer: I wasn't actually party to any of this, I heard it second hand, corrections welcome.
Andrew was pretty dated and virtually everyone I knew was already forwarding their emails through their Gmail anyways. Transitioning to Google Apps was basically cutting out the middle-man while adding on some interesting functionality.
1. Now everyone also had a better calendar system and file sharing with Google Drive within the CMU namespace. This meant that clubs, for example, could create Google Forms that were restricted to actual CMU students with CMU email addresses, and they could use that guarantee to do more interesting things like adding information from the Directory on top of those emails without having to ask for it (such as Major and School).
2. We also got a way to allow people to use their Andrew logins on any student-made website with simple OAuth2 that restricted to using the @andrew.cmu.edu emails on Google Accounts. Before this, apps like ScheduleMan and the StuGov apps (which I developed on when I was there) had to get special permission to use Shibboleth and there were a bunch of restrictions for having those certs including having to run on CMU infrastructure.
Now, any student can create applications with the same login guarantees of only being accessed by CMU students and allow for one-click login and registration (since most relevant information can be obtained by looking up their email in the Directory), vastly increasing the usability of these apps.
In my view, that transition was definitely a net-positive to the CMU ecosystem, in both usability and development.
For all of the cool things I got to do (troubleshoot a breakin at the South Pole, send the RIAA a DMCA takedown notice when they stole our content (absolutely the highlight of my career), etc.), we spent the vast majority of our time on nonsense. We processed dumb breakins by the hundreds, had to enforce DMCA takedowns, and the like.
I'm also all for innovation and giving people the freedom to deploy services and innovate, but I would have killed to deploy all IPs by default behind NAT/firewalls and work with researchers to help them understand their responsibilities before giving them public IPs.
These are two separate things.
There is no security difference between "route port 80 of one of our public IPs through to my NATted address" and "open port 80 for my public address".
The public addresses are easier to administrate, troubleshoot, log, etc.
Also ironically, I can't reach any of the newly NAT'd networks from my XVM instance. I bet the XVM maintainers haven't been warned about the NAT.
Edit: In the late 80s the morris worm was launched from MIT, but the network admins of the 80s didn't overreact like this. I wonder why.
Things I got to try at MIT that would be a lot harder on AWS:
- set up a TOR exit node
- set up a single-system image cluster across five 1U servers
- set up a ZFS box with RAID-Z and dm-crypt
- played with a real lisp machine
- put a raspberry pi on the internet (something I did for several projects)