HNHacker News
TopNewBestAskShowJobs

laz

81 karma · joined August 6, 2010

submissionscomments
laz··on Google Shows How To Scale Apps From Zero To One Million RPS, For $10
The big thing they're crowing about is because you can spin something like this up quickly on demand in the G cloud.

Most sites aren't remotely close to this artificial traffic pattern (1 packet request, 1 packet response).

It's kinda cool from an L4 load balancing perspective that it's only one fault tolerant IP address. In terms of L4 LB throughput though, a single box with IPVS will happily do 1M pps.

laz··on And Here It Is: The New Google Reader Revealed
sigh. I'm now looking at http://tt-rss.org/
laz··on Ask HN: good, quick algorithms course to prepare for big tech interviews?
This isn't the only prep that you'd need, but this is a good one to get your mind in the right place.

(I've given ~2 "big tech" interviews a week pretty solid for the past 6 years)

laz··on Bada Bing, Bada Boom: Culture inside Bing
BWAHAHAHAHA.

Dude, Larry IS the lunatic.

laz··on [dead]
Google has moved past GFS, but the basic concept is right: every machine in the cluster is a storage server.

There are some machines that are equipped with more disks than others where local density is needed.

laz··on Google+ comes up short
the unsubscribe link was 404ing for days and days
laz··on Google on today’s massive Google+ spam influx: “We ran out of disk space”
Mentioning devops undermines your credibility. What service is 5 nines? How is that measured?

In general, Google SRE just gets it done. Sometimes people screw up. It happens.

laz··on Even Facebook can't get their SSL setup right
Missing certs in the chain are fixed, BTW. Thanks for pointing it out.

We tracked down a bug in config autogeneration, and are going to add paranoia to monitor for it in the future.

laz··on Even Facebook can't get their SSL setup right
AFAICT, the tool is broken WRT renegotiation detection.

~% openssl s_client -connect 69.171.228.13:443 2>/dev/null < /dev/null | grep Reneg

Secure Renegotiation IS NOT supported

laz··on Why DNS-based Global Server Load Balancing does not work [2004]
http://tools.ietf.org/html/draft-vandergaast-edns-client-sub... is an RFC to fix this problem.
laz··on Dispelling the New SSL Myth
here's the response by Adam Langley, the guy who kicked off the "ssl is cheap" thing with another blog post: http://www.imperialviolet.org/2011/02/06/stillinexpensive.ht...
laz··on Dispelling the New SSL Myth
Source IP persistence causes hot spots. Big web proxies etc end up clobbering a single machine.
laz··on Dispelling the New SSL Myth
The lack of mention of SNI is odd ... like the author doesn't know what they're talking about.

Most of the latter part is FUD.

One real problem that is encountered when moving to terminating SSL on many machines, instead of a single LB, is the problem of SSL session resumes. When the LB terminates all SSL on a single VIP, it has an SSL session cache and can resume with clients. If you make that LB DSR to servers behind it for SSL, they are going to have local session caches only. Odds are subsequent connections that try to resume the SSL session are going to map to a different machine, and without a distributed SSL session cache, the resume will fail.

We saw the ballpark of ~40-50% of SSL sessions were resumes at $BIG_INTERNET_COMPANY

laz··on The penultimate guide to stopping a DDoS attack – A new approach
Compared to HTTP DNS is crazy cheap to serve, but you'll still end up bottlenecking on the pps rate of your NIC and OS. Everybody optimizes for high throughput and ignores small packets.

Speaking of DNS DDoS, DNS Made Easy saw a 40Gbit DNS DDoS a few weeks back.

← PreviousPage 2 of 2