123 karma · joined January 2, 2015
It's a bit marketing-y though :-)
Disclosure: we host an OSM compatible geocoder at https://locationiq.org
It's OSM compatible at the moment.
https://blog.cloudflare.com/unmetered-mitigation/
"So today, on the first day of our Birthday Week celebration, we make it official for all our customers: Cloudflare will no longer terminate customers, regardless of the size of the DDoS attacks they receive, regardless of the plan level they use. And, unlike the prevailing practice in the industry, we will never jack up your bill after the attack.
Doing so, frankly, is perverse.
We call this Unmetered Mitigation. It stems from a basic idea: you shouldn't have to pay more to be protected from bullies who try and silence you online. Regardless of what Cloudflare plan you use — Free, Pro, Business, or Enterprise — we will never tell you to go away or that you need to pay us more because of the size of an attack. Cloudflare's higher tier plans will continue to offer more sophisticated reporting, tools, and customer support to better tune our protections against whatever threats you face online. But volumetric DDoS mitigation is now officially unlimited and unmetered."
:-|
Strange thing if we run 'top' from the main host, all containers running redis say 'statd' as their user; inside the container the user showed 'redis'. We removed nfs and all related files, and now it shows a user ID number. Is this something we should worry about?
We searched the whole system for authorized_keys files and found one created in a /var/lib/redis/ of a staging container (with no firewall) on this host. We then came across the redis vulnerability https://kevinchen.co/blog/postmortem-server-compromised/ . A junior dev had spawned this container without help from dev-ops and hence left ports open.
What doesn't make sense to us is how this daemon (yam) was running under a statd username when the container doesn't have such a user, but the host does? Are LXC containers able to run daemons on the host?
Would you how we could hire professionals to investigate this for us? And report it to appropriate groups..?
PS: These are dedicated servers :-/
If geocoding needs are enterprise-grade / you are OK with spending a bit, you should look at Mapzen, OpenCage, and now, Geocodio.
Thanks for your wishes!
Our current config allows an import in 8 hours and responds within 20ms (not including network latency). It's not cheap though.
We love Moz & have offered to help them but with all respect, we have over 10x the global coverage at this time.
Quicker - Googles Geolocation services primarily are hosted in US East. We offer multiple datacenters globally.
Better - Google's Geolocation offers primitive triangulation / trilateration; even if you submit multiple cell towers / WiFis, they locate with just the first one.
Update: While Google does have massive amounts of data, we get also lot of data from both Google androids (we tie up with apps), and traditional GPS companies. All said, we've spent more time with our data-cleansing & trilateration algorithms for more reliable location.
Better - Google's Geolocation offers primitive triangulation / trilateration; even if you submit multiple cell towers / WiFis, they locate with just the first one.
Please correct me if I'm wrong, I'll edit out the word.