Notably NTPd doesn't support leap-smear, which means those who absolutely must have monotonic time can't use it at all.
... shouldn’t be using a Unix timestamp, or anything else that’s not a count of SI seconds elapsed since a fixed reference point, to begin with.
[1] https://people.csail.mit.edu/rachit/post/you-have-built-a-co..., https://news.ycombinator.com/item?id=29891428
...rather than setting a rather awful minimum performance spec of 10ppm smearing over a leap second day.
Three lies: Universal - multiple smear implementations, linear vs cosine off the top of my head.
Coordinated - whose in charge here? Google? Facebook?
Time - doesn't even try for 1s/s
UTC is, for all intents and purposes, yet another human readable time zone. And should be treated as such. The underlying hardware problems I have and understand. Don't need the software making it worse.
I am vaguely aware he has some unpopular political beliefs (though exactly what I don't know). Is that it?
Oh, also he doesn't really "contribute" to tech projects so much as "exists near/within them and writes long form ramblings".
If he just "exists near", I see even less of a case why someone should avoid it.
But horses for courses, people can choose to avoid for whatever reason.
It is not even his beliefs, though many of them are — to my ears and hopefully to most — quite repugnant.
It is his attitude, approach, and at various times the kinds of people he attracts.
As it goes, I've seen him speak, back in the 90s, CatB era. He was genial enough but he seemed to have a coterie around him of rather less pleasant people. It could just have been a bad day but it has stuck in my mind ever since: it was the first time I understood that there's not really any sort of inclsive geek community.
ntpsec as a project seems to be doing ok. They are releasing new versions, fix reported issues, accept patches, and develop the code publicly. While ntp still has a huge list of acknowledged but unfixed CVEs.
It should be noted that there currently exists no standard, technical or statutory, for how to do leap smearing. If an event happens and you need to tie your timestamped event logs to the 'greater reality' in some legally binding way there's (AIUI) no way to do that.
A few years ago there was a draft on the idea:
* https://datatracker.ietf.org/doc/draft-stenn-ntp-leap-smear-...
And the currently-draft NTPv5 has something about:
* https://datatracker.ietf.org/doc/draft-ietf-ntp-ntpv5/
Though the flag simply says that the timescale is smeared and not (AFAICT) how it is being done.
See also perhaps RFC 8633 § 2.7.1:
[…]
Operators who have legal obligations or other strong requirements to
be synchronized with UTC or civil time SHOULD NOT use leap smearing
because the distributed time cannot be guaranteed to be traceable to
UTC during the smear interval.
[…]
Any use of leap-smearing servers should be limited to within a
single, well-controlled environment. Leap smearing MUST NOT be used
for public-facing NTP servers, as they will disagree with non-
smearing servers (as well as UTC) during the leap smear interval, and
there is no standardized way for a client to detect that a server is
using leap smearing. However, be aware that some public-facing
servers may be configured this way in spite of this guidance.
* https://datatracker.ietf.org/doc/rfc8633/TAI (Temps Atomique International), is UTC without leap seconds and is the source of truth for "what time is it"
I'm finding conflicting reports of being able to actually use TAI on linux but there are several claims of at least specialty setups existing. You would absolutely not want smearing or anything like that in your time synchronization software in this case.
But yeah, critical infrastructure usually goes criminally underfunded.
Relatedly: surely you're not of the opinion that the various GPS constellations are not critical infrastructure?
[0] <https://www.nist.gov/pml/time-and-frequency-division/time-se...>
Listen to my last prayer
Hi-ho-silver-o
Deliver me from nowhere
You can use the public Google or AWS pools if you want. Note that they have their own software, too, so be sure you understand the differences like leap smearing.
Blocking FAANG IPs from the NTP Foundation’s pools wouldn’t hurt FAANG at all. It would only hurt people who weren’t aware and used the NTP Foundation’s pool for things.
Research is put front and centre in their pitch for funding.
And given that ntp.org runs servers that so many organizations use they should be near the top of the funding queue for any NTP research. My 2c.
I too would be interested in knowing what the Network Time Foundation is researching, and I think conversation about that is appropriate here. NTP certainly _seems_ like it’s been ‘good enough’ for decades to an uninformed observer, and discussing if and why it’s not would be interesting (and perhaps motivate donations!)
Really? The sentence at the top of the Donate page seems pretty clear to me:
> Your donation helps Network Time Foundation maintain the NTP website and provide resources and support to NTP developers.
Is it unclear to you?
https://gist.github.com/mutin-sa/eea1c396b1e610a2da1e5550d94...
But..it's $1k. This is basically pocket change on an institutional level. I've been part of some very scrappy and poorly funded community organizations and even they took in more than $1k every year. Even if you don't believe NTP maintainers should be paid anything for their work (an opinion I don't hold), it's trivial to spend this amount on modest everyday expenses like renting a venue a couple of times, buying insurance, and paying for hosting and technical resources.
EDIT: Here is their 2024 tax return
https://www.nwtime.org/about/documents/2024_NTF_IRS_990.pdf
It looks like they took in more than $200k and spent $100k on "contract services" (I can't tell what that means) and somewhat modest amounts on other things. Unfortunately I need to exit the rabbit hole now.
How much more clear can they reasonably be?
It seems a big waste of effort to maintain -say- a damnable Trello board with upcoming priorities and roadmaps <strike>and Kickstarter stretch goals</strike> when their bug tracker and mailing list are visible to the public. (Though, it seems that they've recently put the list behind some broken moderation software, so you have to go to -say- the IETF's archive of the thing to read it. "AI" crawlers ruin everything.)
EDIT: Do note that that tax return you found is for the Network Time Foundation, not the NTP Project. I don't know if the two are separate entities for tax purposes, but do note that the NTF supports several projects, of which the NTP Project is one. The NTP Project is just for NTP.
I can't imagine its much more than that if we are talking about such a small sum.
and $1000 seems at the same time to be quite a bit of money, but also too little to be for funding people long term.
Thankfully, that's also on the front page:
What they are doing:
> The NTP Project produces an open source Reference Implementation of the NTP standard, maintains the implementation Documentation, and develops the protocol and algorithmic standard that is used to communicate time between systems
And why it matters:
> NTP is what ensures the reliability of billions of devices around the world, under the sea, and even in space
Now, it doesn't explain why a reference implementation is a good thing, but I think that at this point, you have a good enough idea to decide if you want to donate or not.
Edit: However, $1000 seems too low to matter. It may not even pay for the expense of the fundraising itself. I think it is more of an awareness campaign: "look at the protocol we all use, you would think we are talking many millions of dollars, but the truth is, you are off by orders of magnitude"