HNHacker News
TopNewBestAskShowJobs

aaronk6

3 karma · joined July 9, 2013

submissionscomments
aaronk6··on Page was served from Nginx on ReactOS
Exactly! I had only posted the link on www.reddit.com/r/reactos and didn’t expect it to get attention from a wider audience :-) Also, I deliberately avoided CDNs and caches to see if the source system can handle the load. I know that this woudn’t make any sense in real-world scenario, but for this project, this was part of the fun.
aaronk6··on Page was served from Nginx on ReactOS
Yeah, but not necessarily ReactOS’s fault! The machine it’s running on doesn’t have much power as I didn’t expect it to get much attention really. Also see my notes regarding the HTTPS link that was temporarily broken: https://news.ycombinator.com/item?id=32480404
aaronk6··on Page was served from Nginx on ReactOS
HTTPS is fixed now.
aaronk6··on Page was served from Nginx on ReactOS
This.

Part of the challenge for me was to avoid any proxies and and have all requests go directly to the ReactOS system.

I’m totally aware that this doesn’t make any sense in a real-world scenario.

aaronk6··on Page was served from Nginx on ReactOS
I’m the author of the page. It’s now reachable via HTTPS (again).

I think this is what happened:

I experimented with HTTPS on Sunday and actually got it up and running by patching msafd.dll (see https://jira.reactos.org/browse/CORE-14486 and https://github.com/reactos/reactos/pull/4086).

While the page was running on HTTPS, @timeoperator must have posted this (without me realizing it). Shortly after, the site was down due to the HN Hug of Death®. However, at the time, I thought it had something to do with my recent HTTPS change, so I rolled it back. As a result, the HTTPS link posted here stopped working.

In addition, I wanted to be smart and added a Strict-Transport-Security header:

  add_header Strict-Transport-Security 'max-age=31536000; includeSubDomains; preload' always;
So people who had accessed the HTTPS version (while it was active for a few hours) would never see the non-HTTPS version again.

I didn’t expect it to get so much attention, so next time I attempt something like this, I’ll perform proper load tests, have a dev deployment in place, and check access logs more often!

aaronk6··on Page was served from Nginx on ReactOS
Hi, I’m the author of the page.

> Probably doesn't have a letsencrypt client.

Right, Certbot doesn’t work because of an issue with Python, however, it’s easy to generate the certificates elsewhere and inject them into the virtual machine.

> Maybe there's no SSL/TLS library that works on it at all.

There is, but the OS needs to be patched to fix a socket issue (see https://github.com/reactos/reactos/pull/4086 which was never merged because of side effects). The patch does seem to work for my use case and I had actually the site running on HTTPS, but a few hours later it become unresponsive. I didn’t realize that this was probably just due to the HN DOS. I will give HTTPS another shot later today.

aaronk6··on [dead]
I cannot confirm this. I've just updated via iTunes and it asked for the PIN code.