Live data from Hacker News

New Google SRE book: Building Secure and Reliable Systems

landing.google.com

51–60 of 227 posts

Re: New Google SRE book: Building Secure and Reliable Systems

#51
The most challenging part of this series is not in the material itself. These insights are learnings through hard experience and scale from Google are invaluable.

No, the hard thing for everyone is to recognize is that most companies are not Google and don't have Google's problems, resources, or time to follow these practices.

Definitely read the material, I will thoroughly, but don't apply this blindly. Solve YOUR problems, not theirs.

Re: New Google SRE book: Building Secure and Reliable Systems

#53
post #32

Earlier quoted context omitted.

You mean the same program that also "infiltrated" (I guess you take those companies at their word that they weren't cooperating) every other tech giant? Again, that's why I asked "Compared to what?" What is your favorite tech company, uninfiltrated by the NSA while also serving billions of users, whose SRE books would be more worthwhile?

Assuming that an answer to your question is even quantifiable (it isn't since you're asking me to prove nonexistence), how is it relevant to my original question? The security failures that allowed the NSA to come in were comical. Deliberate choices that Google made are for the most part responsible for the Android fiasco. In fact, Google is one of the behemoths that put us all at -ever increasing- risk in the name o…

Can you suggest another company with the experience and expertise at this scale to go with the unbesmirched reputation needed to write an information and helpful book on this topic?

Re: New Google SRE book: Building Secure and Reliable Systems

#54

The most challenging part of this series is not in the material itself. These insights are learnings through hard experience and scale from Google are invaluable. No, the hard thing for everyone is to recognize is that most companies are not Google and don't have Google's problems, resources, or time to follow these practices. Definitely read the material, I will thoroughly, but don't apply this blindly. Solve YOUR p…

We were very much aware that not all companies can afford to staff a dedicated security team. We tried to do our best to make sure that the book is applicable to a wider audience: from startups, to big corporations.

(disclaimer: I work at Google)

Re: New Google SRE book: Building Secure and Reliable Systems

#55

Earlier quoted context omitted.

I’m on mobile safari and the ePub and mobi files open as text. This means I can’t export them to Apple Books or the iOS kindle app. Could you please trigger a download instead if possible ?

Thanks for the feedback. This is a known issue that another user flagged this morning. The team is pursuing a fix. The content-type on the file is incorrect :/. In the meantime, you can open it in a browser and email it to yourself. Not ideal, but a workaround. [EDIT]: s/pursing/pursuing

I was wondering about that. I knew the native Books app supported both formats. Thanks for the quick response.

Re: New Google SRE book: Building Secure and Reliable Systems

#56

Is there a more digestible version of SRE concepts somewhere? I'm just looking for an easier way to communicate core principles and concepts to my team without asking them to sink into 500 pages?

Shame you got downvoted for what seems a reasonable request.

Re: New Google SRE book: Building Secure and Reliable Systems

#57
I scanned the introduction, but failed to see any concrete information on the expertise of the authors on security. Can anybody speak to the expertise of the authors on security?

In particular, I am interested in specific projects or initiatives they directed or lead. The state of systems before and after these projects. If there were any long-term regressions after their involvement.

To be even more concrete if possible:

1. What was the project and what would occur in the event of unmitigated compromise?

2. What was the threat model?

    2a. Why was that the appropriate threat model given the possible outcomes? 
3. How did they validate that the project met its goals in mitigating the threats in the threat model?

4. What level of resources would be necessary to compromise the systems they were trying to protect?

    4a. Would the system prevent compromise by a red team with a $1 Billion, $1 Million, $1000, $1 budget? 

    4b. What resources did the red teams have?
Personal questions for the responder:

1. Would you feel comfortable using the processes you have used in the past to develop a system where compromise would result in the loss of human life?

2. If you answered yes, what project and process and why do you believe that it sufficient?

3. If you answered no, do you have any first hand knowledge of systems that achieve that standard?

4. What is the best system that you have first hand knowledge of that has achieved at least that standard? Is there a non-theoretical gold standard?

Re: New Google SRE book: Building Secure and Reliable Systems

#58

Hey everyone - Seth from Google here. Thank you for all the positive comments about the book. I'll be around to answer any questions you might have. As noted, the book can be downloaded for free in digital formats. PDF: https://landing.google.com/sre/static/pdf/SRS.pdf EPUB: https://landing.google.com/sre/static/pdf/srs-epub.epub MOBI: https://landing.google.com/sre/static/pdf/srs-mobi.mobi

I really liked that there were HTML versions of the previous two books. Any chance that'll be up for this one? A bit far-fetched but: Have you (or anyone else at Google) looked at Amazon Builder's Library [0] and/or various re:Invent / re:Inforce talks from 2018/19 [1][2] that focus on similar topics as in this book and other SRE books? If so, what are some ideas (infrastructure, blast radius, incident management, re…

Download the epub version and on the Linux command-line execute `tar -zxvf srs-epub.epub` then cd into unpacked `OEBPS/` folder and there's your HTML files. Not exactly what you are looking for, but you can browse the content in a web browser.

Re: New Google SRE book: Building Secure and Reliable Systems

#59
post #8

Earlier quoted context omitted.

Upvoted since I was going to make the same comment. I have been dealing with some downfall from that issue today. As a user of their cloud services, my perception of their reliability is pretty low compared to competitors. I still like GCP the best though.

> As a user of their cloud services, my perception of their reliability is pretty low compared to competitors. I still like GCP the best though. I guess we tend to notice more the flaws of the services we use the most

Not in this case. At work, we use AWS and GCP, everything that runs on top of Kubernetes is deployed on both clouds. If I isolate the number of service stopping incidents this year for that vertical, I can find 3 on GCP's side, and zero on AWS.

Re: New Google SRE book: Building Secure and Reliable Systems

#60
post #28
post #23

Earlier quoted context omitted.

Google search, gmail, maps, their ad systems...?

Weren't they all compromised by NSA, as well as China. And those are the issues that became public. Look up Operation Aurora for instance, or the famous slide deck that highlighted lack of encryption inside Google's network - and security intelligence even put a smile face there!

If your best examples of security failings from Google are from 7 and 10 years ago suggests a fairly robust security track record, does it not?

And Aurora "became public" when Google announced it, it was the other 30+ companies affected by it that kept silent on the issue (some to this day).

Post reply on HN