TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Network Update: Multihomed, Increased Transit, Peering

82 点作者 stenius超过 8 年前

8 条评论

pjungwir超过 8 年前
&gt; per-customer VLANs<p>I am looking forward to that! Linode is my go-to hosting service, but it&#x27;s a little troubling that anyone in the datacenter can hit your private IPs [1]. On the other hand, maybe it shouldn&#x27;t matter, and you should always act like the network is compromised. Isn&#x27;t trusting their private network how Google leaked traffic to the NSA? Still, it seems like a nice improvement that would make compromises less likely.<p>[1] <a href="https:&#x2F;&#x2F;blog.linode.com&#x2F;2008&#x2F;03&#x2F;14&#x2F;private-back-end-network-support&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.linode.com&#x2F;2008&#x2F;03&#x2F;14&#x2F;private-back-end-network-...</a>
评论 #12856859 未加载
评论 #12856875 未加载
secure超过 8 年前
I appreciate how transparent they are about their locations, transit and peering.<p>I’m looking to replace one of my VPS at digitalocean because of stability issues (need to reboot the VM every couple of months, it just entirely drops off the network apparently).<p>Linode seems like a good alternative. My criteria for this application are ≥ 1G of RAM, SSD storage, fast RTT to my other VPS, native IPv6 support.
geuis超过 8 年前
I fucking love Linode. I&#x27;ve been hosting with them for years and over time I&#x27;ve gotten more performance and more data transfer for the same money.<p><a href="https:&#x2F;&#x2F;jsonip.com" rel="nofollow">https:&#x2F;&#x2F;jsonip.com</a> is hosted with Linode and supports millions of requests a day. It&#x27;s been a great home for the service.
评论 #12859545 未加载
swalsh超过 8 年前
I guess it never occurred to me before, but with the increased amounts of attacks lately it&#x27;s been near the top of my mind. These guys seem to be throwing around the physical addresses of data centers pretty freely. What is the security of these places like? How decentralized are we really? It seems like a few strategic strikes could deal a devastating blow to our edge infrastructure. I know personally, my servers are only hosted in a single datacenter. The company I work for is in 3 datacenters, but I&#x27;m not sure the other 2 data centers could handle the full load for an extended period of time if the primary one was completely taken down.<p>Granted not as big of deal as power plants etc, but if you&#x27;re looking for soft targets, it&#x27;s a scary thought.
评论 #12857412 未加载
评论 #12856921 未加载
vetrom超过 8 年前
Are they still running a hard-to-audit ColdFusion CMS?
评论 #12863267 未加载
StanAngeloff超过 8 年前
This is good news for their users, incl. us given the frequency of DDoS attacks lately. There has been hardly a month go by without their status page flagging an incident report involving increased traffic to one of their datacentres as a result of a DDoS attack.
hhw超过 8 年前
&quot;we now manage our own true service provider network, allowing us to deliver robust and reliable connectivity.&quot;<p>What&#x27;s needed to combat DDoS attacks is distributed defense. Without their own backbone &#x2F; private transport links between all of their locations, their network is just a disparate set of data centres and there is no advantage to their having multiple locations, so far as protection from DDoS attacks are concerned.<p>They also fail to mention what capacity each of the links are. They could be anywhere from 1Gbps to 100Gbps, but I presume they&#x27;d mention as a selling point anything 40Gbps and up, so let&#x27;s assume they&#x27;re using all 10Gbps links and not 1Gbps to give them the benefit of the doubt. So, they range from 50Gbps (Singapore) to 100Gbps (London) per location.<p>It&#x27;s an impressive list to look at in aggregate, but not really that much for any one location in 2016, especially given a company of their size and visibility, when you can rent shared access to a 200Gbps+ botnet for $19.99. <a href="https:&#x2F;&#x2F;www.nanog.org&#x2F;sites&#x2F;default&#x2F;files&#x2F;20161015_Winward_The_Current_Economics_v1.pdf" rel="nofollow">https:&#x2F;&#x2F;www.nanog.org&#x2F;sites&#x2F;default&#x2F;files&#x2F;20161015_Winward_T...</a><p>Instead of buying transit from up to 7 carriers per location, when there are starkly diminishing returns after 3 or 4 so far as routing performance is concerned, they should have instead bought higher capacity to each provider (to ensure at least 10Gbps of unused capacity per provider outside of regular legitimate traffic), external DDoS mitigation, or domestic backbone links and turned up more capacity at the LA Any2 (for Asia) and NYIIX (for Europe) to absorb the majority of DDoS traffic which comes from those regions. With up to 7 carriers, they simply have 7x different points of failure each at only 10Gbps, while getting worse deals on transit pricing due to lower volumes with each provider.
评论 #12861677 未加载
neom超过 8 年前
Reminds me of DigitalOcean in 2015. Curious what a &quot;per-customer VLAN&quot; is in reality.
评论 #12857347 未加载