Chaos in the Cloudflare Lisbon Office
blog.cloudflare.com
blog.cloudflare.com
https://refikanadol.com/works/bosphorus/
Bosphorus is a data sculpture inspired by high frequency radar data collections of Marmara Sea provided by Turkish State Meteorological Service in every 30 minutes intervals. The data collection of 30 days long sea surface activity transformed into a poetic experience and visualized on a 12 meters by 3 meters long LED media wall. The art work exhibited at Pilevneli Gallery on 11th of December, 2018 – 27th of January, 2019 in Istanbul, Turkey.
Really ?
Why do people feel the need to appeal to authority for the things they made. This has nothing to do with a sculpture. But it doesn't take anything away from its value.
That's an interesting way of saying "if the wall loses power". Your name wouldn't be Hans Gruber, would it?
There's a SF story to be had here: the global superintelligence uses bits of litter and fallen leaves and stuff to generate unbreakable encryption; the terrorists wage a global campaign to clean up litter, prune trees, get everything neat and orderly in order to hack the system...
Crystals are generally considered pretty orderly, yet the oversaturated solution actually gains entropy when it crystallizes.
This is why, in an app, you might seed with timestamp and process ID and /dev/urandom, in case any of them happen to be non-unique or unsupported.
Prevents not only technical issues but attacks like someone blocking the camera or putting a static photo in front of the camera.
Now I wonder about some periodic offsets. E.g. if the lights are off at night, or if the skies are overcast in winter, does it skew the results in some significant way. I seriously doubt that though.
What I love about this, the lava lamp wall in San Francisco, and the double pendulums in London, is that it takes something very abstract and makes it tangible for our team and our customers.
I used to think the same but here's a counter-example of a (hypothetical) attack based on a malicious entropy source being able to manipulate the hash/PRNG output:
https://blog.cr.yp.to/20140205-entropy.html
Now, it's not necessarily the most likely attack to materialize, as already pointed out downthread: https://news.ycombinator.com/item?id=43391377.
Another much smaller pendulum in the hands-on science exhibits, you scooped sand into it and then set it swinging freely across a square black surface. It would trace out amazing patterns as it spilled sand hourglass-style.
So then some bully would rock up next to me and smack the pendulum, stop it from swinging, and spill a big blob on the formerly-geometric pattern. And they invariably said "just to see what would happen". AStonesThrow would have a small meltdown or become rather indigant. I suppose their empirical science is just as valid as kicking down sandcastles on the beach.
And that's how I came to prefer single-player games...
https://en.wikipedia.org/wiki/Lissajous_curve
The sand pendulum drew lissajous curves as it swung. [I learned it today because they called the ESA Gaia probe's orbit "Lissajous" around the Lagrange point.]
https://www.esa.int/Enabling_Support/Operations/Farewell_Gai...
Though this is certainly a pretty expensive if nice looking backup entropy source.
It all nets out to "these are fine blog posts; don't try it at home".
There has to be some code that already does that.
There is also dedicated "TRNG" hardware which will measure random thermal noise. Some will even get fancy with quantum effects.
Any source of randomness will do, you just feed it into a hash function and extract uniform randomness you can use in cryptography.
For example, if you have an image sensor that takes an image (and does no post-processing) and you feed that image into SHA256 you get 256 bits which you can use for cryptography. As long as the image is never saved there is no practical way to recreate the input and in fact the input will contain more entropy (degrees of freedom) than the output, so no one would even want to try. Most of the degrees of freedom in the image would come from sensor noise and not the scene, so you don't even need to take off the cap from the camera.
In practice, multiple sources are combined. The Linux kernel does this for /dev/[u]random though it doesn't use the camera. There is a potential risk with such combination: one of the inputs may come from a source which is able to interrogate all the other sources, it would then be able to adversarially choose its contribution to skew RNG results. This is a somewhat obscure and unlikely threat model.
It doesn't really go bad unless you disseminate the material to inappropriate parties. You could store terabytes of it in S3 buckets for an emergency.
So what’s really going on?
Is it:
- it IS somehow a good return on investment??
- marketing had a budget and didn’t know how else to spend it, and no one wanted to be the unpleasant person and say how it’s all a silly waste of money?
- they are making a tonne of money and no one really cares, so we’ll just spend it on fun cool stuff as long as there’s a plausibleish story to go with it?
- fits with a broader global company branding concept that leadership seems to like, so there’s just the momentum to keep it going (and see points above)?
I can’t figure it out. I agree it’s cool! Just the make believe puzzles me a little. I’ve not worked at a big corp like this and just have to understand what’s actually happening.
SGI did this almost three decades ago:
https://web.archive.org/web/19971210213248/http://lavarand.s...
...harnessing the power of Lava Lite® lamps to generate truly random numbers since 1996.
According to https://www.lavarand.org/news/lavadiff.html:
Seed production rate was about 8000 bits of seed per second on a 200 MHz SGI O2 under IRIX 6.5.
The patent has since expired: https://patents.google.com/patent/US5732138A
(And Cloudflare re-implemented it, seemingly starting just after the patent expired in 2016.)
Nevertheless, it's a great tradition to carry forward and I'm happy you guys are doing it.
Meanwhile, every single real estate developer / agent sets their prices incredibly high hoping to sell or rent out the property to those mythical "wealthy expats". I saw a stat somewhere that less than 0.2% of all real estate transactions in the country each year involve foreigners, and yet everyone blames them for high real estate prices.
Seriously? How about:
- Avenida da Liberdade
- The Botanical Garden in Principe Real
- Parque Eduardo
- The beautiful gardens around the Gulbenkian Museum
- Jardim da Estrela
- Tapada das Necessidades
- Jardim do Principe Real
and one of the prettiest urban neighborhood green spaces I've ever been to: Jardim Fialho de Almeida
Edit: formatting
https://en.wikipedia.org/wiki/List_of_cities_by_internationa...
I think it deserves to be higher.
I would say it's rated highly by tourists and expats.
Saw someone call the The Wild Robot, nominated for 3 Oscars, underrated the other day.
Edit: I just googled the location and it's right next to LX Factory, a rehabilitated, trendy shopping area where one of my favorite bookstores is located (Ler Devegar).
Source: I live in Portugal and notice all the discussion about it from my Bay Area friends who want to expatriate. To here, specifically.
Source: Portuguese/US citizen. Lived there for a year with a "good" Portuguese salary of 2000 euros a month; much different lifestyle than what the typical US tech worker is accustomed to. And not doable long term unless you plan to retire in Portugal and not do much travelling.
I never said that I support this oversimplification of Portugal. Which is why I live in a small town, socialize with Portuguese, and study Portuguese.
Lots of similarities with the last city I lived in - San Francisco: Big red suspension bridge that spans the gateway to the ocean (same vendor), cable cars running on impossibly hilly streets, cosmopolitan, diverse LGBTQ+ friendly people, amazing food, nearby vineyards, blossoming tech scene....
It cannot help that more and more Americans are moving there.
So cool to see that they've built something similar in their Portugal office.
I hope we should not read too much in the hanging of rainbows in Austin, Texas
An interesting question I would have is do you get just as much randomness without the fluid at all?
It's a chaotic system (turbulent flow is chaotic). Even tiniest differences between the real and simulated state will add up and amplify over time.
Fluid simulation is a notoriously hard problem. We don't have a solution to Navier-Stokes equations. Practical implementations have limited resolution in time and space, and plenty of simplifying assumptions.
way to completely ruin an otherwise lovely article
I don't know how you think "this is how TLS works" is relevant here. Just e.g. terminating a TLS connection certainly doesn't mean that you're going to be logging all the unencrypted data. And you claim, again, was about logging.
Again: your claim was that Cloudflare had admitted to logging the passwords. You've been unable to provide any evidence of such an admission. Why not admit that it was an incorrect claim?
What you wrote initially was verifiably incorrect. It's not clear whether you made an honest mistake and just can't admit it now for some reason; whether you intentionally lied; or whether you genuinely can't see that what you wrote is not supported even by your own sources. It might be possible to figure out which, if you actually engaged in the discussion and explained what you mean.
Like, anybody can see what your initial claim was. Everyone can also verify that you've still not provided any evidence for it. Other than the "this is literally how TLS works" non sequitur.
Could you possibly be thinking that "logging" and "inspecting" are the same thing? Seems hard to believe. The two are obviously totally different things. In particular, the security and privacy properties of the two would be totally different. If you knew from the start that that the passwords were not being stored anywhere, saying it was "logging" is just acting in monumentally bad faith.
Almost a month ago now my account was incorrectly charged for a pro plan I didn't have --- aside from the week+ long waits between replies from support, they refuse to refund me until the engineering problem is fixed. I'm still waiting for a reply to my follow-up mail from last week.
Yea, $25 is not much - but as an indie dev this makes me HUGELY nervous if that amount had even 1 more zero after it.
But hey, cool office guys.
"What I try and encourage is our leaders to take responsibility and fix them wherever they see them."
Is kinda the opposite of "throw your hands up in the air".
Not sure how you got there.
Even if you saw all the "cf fucked up" tweets/posts/etc, you still couldn't make that assertion without knowledge of all the times they didn't fuck up. People are far more likely to make noise about issues than things just working. This assertion is like assuming the starbucks corporation is incapable of producing a coffee people will buy because you saw a couple tweets about a messed up order.
There is a big difference between mistakes due to an individual and mistakes due to systemic issues, which is what GP was referring to.
True - but if a user resorting to HN receives a very positive, public reply from their CxO within 2 minutes...that's a pretty favorable sign overall.
(And even if jgrahamc does nothing except fix this n=1 problem, his brighter underlings are likely scrambling to minimize recurrences.)
How the mighty have fallen.