HNHacker News
TopNewBestAskShowJobs

ybloviator

61 karma · joined November 29, 2017

submissionscomments
ybloviator··on FreeBSD at 30: Its secrets to success
[citation needed]

(not in a snarky way, I want the story!)

ybloviator··on FreeBSD at 30: Its secrets to success
not at all weird for him
ybloviator··on FreeBSD at 30: Its secrets to success
Yes! It was so huge in the ISP space back then because trying to run something like NNTP on Linux at the time was just not a great experience for customers. Indy ISPs aren't really a thing these days I guess, but back then it was a really strong market for FreeBSD.
ybloviator··on FreeBSD at 30: Its secrets to success
And I think the userland got a bit of a refresh from current FreeBSD when OS-X came out.
ybloviator··on FreeBSD at 30: Its secrets to success
With heavy use in Netflix's CDN resulting in something like more than 15% of internet traffic being delivered by FreeBSD, that's some kind of success I imagine.
ybloviator··on FreeBSD at 30: Its secrets to success
monoculture is bad, especially for security
ybloviator··on FreeBSD at 30: Its secrets to success
I thought 3.x was the bumpy one (first SMP, IIRC).
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
I'm not a security guy, but monoculture always scared the shit out of me.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
(on linux)
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
If anyone wants to learn (as opposed to arguing), the papers on Netflix's TLS offloading work are a fun read.

And say what you will, something like 20% of all internet traffic has a FreeBSD endpoint. And doing 400Gb/s of encrypted streaming from one box is quite an accomplishment.

I would argue the reason someone like Netflix or any of the other large orgs using FreeBSD come there is for the simplicity/cohesiveness. If you're looking to do something like in-kernel TLS or something, way easier on something smaller, documented, and with an OS devel team that will likely incorporate your work in future releases.

ybloviator··on We're migrating many of our servers from Linux to FreeBSD
This is nonsense. Please educate yourself a bit on systems automation in general if you think this is the case.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
The unsaid thing here is Linux is largely not used by sysadmin/unix types. Devops has driven this bloat so that people new to the field can just not have to learn any fundamentals about the OS they're building their tools on. For rapid "move fast and break things" VC nonsense, this is a great match. For efficiency, correctness, and long-term maintainability and security, it's a nightmare.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
If your BSD init script is 500 lines long, you've done something horribly wrong.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
And they say BSD users have attitude issues, lol.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
Yeah, it's a weird argument. I've used vnet, but rarely need it. I bind my jails to their own IPs and that's that. That has been available from the very early days of jails.

Again, mature, simple and secure, with very few surprises lurking. There's likely fewer lines of code to support all jail functionality than in systemd.

ybloviator··on We're migrating many of our servers from Linux to FreeBSD
In FreeBSD see the "-J" and "-j" options to cron.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
And iocage makes all of this extremely simple, it can manage IPs for you and all that nonsense. There's also a sort of "clone" of iocage for bhyve.
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
Did you try "pkg install bash"?
ybloviator··on We're migrating many of our servers from Linux to FreeBSD
If you're getting the "do it by hand" answer, you're asking in the wrong places.

Ansible, SaltStack, all the devops automation stuff is available and can certainly handle "freebsd-update fetch; freebsd-update install; reboot".

ybloviator··on We're migrating many of our servers from Linux to FreeBSD
This speaks more to the issues regarding the "made of many little pieces without coordination" spelled out in the linked post than to using simple scripts for service management. Also the idea that you would have pid files scattered all over instead of /var/run seems like the sort of chaos linux spawns.

The *BSD rc systems are robust and rely on a framework that abstracts stuff out, you're never going to be digging in there for a pid file's location.

ybloviator··on AWS us-east-1 outage
Technically, there are already regulations. SLA lies are fraud.

But I'm leery of any business who's so dishonest they fear any outside oversight that brings repercussions for said dishonesty.

"If not happy, switch" is silly - it's not the customer's problem. And if you're a large customer and have invested heavily in getting staff trained on AWS, you can't just move.

ybloviator··on Freenode ops take control of 700 channels
Nope, they nuked a local user group's channel simply for having Libera in the topic.
ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
Didn't one of the major ISPs get their ass handed to them in court for trying to say that they were somehow exempt from keeping exactly this sort of information? I mean, you can SAY it, but it would be sort of insane to make a statement like that without a lawyer signing off on it. The law doesn't have a "this is too hard for us" or "we didn't build our network for this" exemption, does it?
ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
$4K sounds incredibly overpriced.
ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
Pilot is doing this cheaper than others, look into how they get their fiber in the ground...
ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
How does it work for torrenting?

Does VoIP work?

What if I want to run a server at home?

ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
Ah, so you get free bandwidth from people that want to balance their traffic for better peering contracts. That's clever. Probably not a helpful model for other areas that aren't bandwidth centers like NYC, and should probably be more out there when you're evangelizing so people understand you're getting a large portion of your operating expenses donated...

I have to assume another cost that's not noted is roof rights. That's not free - most people either have to pay or give the property management a kickback.

NYC is an interesting place for this - if you live in Manhattan, you clearly can afford the $80 for 1Gb/s FiOS or $40 for 100Mb/s FiOS or whatever Spectrum is charging. It would be way more interesting to plop this in a rust-belt city where people are on a paycheck-to-paycheck salary...

ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
"The network connects directly to the internet backbone, so we do not rely on an ISP."

That makes no sense. I doubt they're a tier-1 backbone themselves, they have to be purchasing transit from an ISP. It feels like lots of the docs are written by marketing-type folks. Also there's a weird diagram that insinuates NAT happens before bgp peering with the not-ISPs they buy internet from. Weird shit.

ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
Screenshot of a UBNT p2mp at 2 miles in Manhattan please. The dashboard will show the distance. Please post.
ybloviator··on 'Anti-authority' tech rebels take on ISPs, connect NYC with cheap Wi-Fi
I missed the "industrial grade equipment" part in the arcticle, TBH. In fact I saw no real technical details at all. "Mesh" isn't even really defined. You'd think they'd at least mention what firmware they're running on their gear to implement "Mesh".
Page 1 of 2Next →