Earlier quoted context omitted.
I really liked that there were HTML versions of the previous two books. Any chance that'll be up for this one? A bit far-fetched but: Have you (or anyone else at Google) looked at Amazon Builder's Library [0] and/or various re:Invent / re:Inforce talks from 2018/19 [1][2] that focus on similar topics as in this book and other SRE books? If so, what are some ideas (infrastructure, blast radius, incident management, re…
I'll flag the HTML pages with the team. I'm honestly not sure. I know we're able to offer epub and mobi this time, something not previously possible with the other books. I haven't looked at those other resources, but I'll ask if others have.
New Google SRE book: Building Secure and Reliable Systems
201–210 of 227 posts
Re: New Google SRE book: Building Secure and Reliable Systems
#202Earlier quoted context omitted.
There is certainly a huge YAGNI danger here. 10 people shops should read this, but keep their socks on. I love the part in that other SRE book where they say to “keep it simple” right after describing probably the most involved, meticulous and vast set of software engineering practices of the last 10 years. “Simple” if you have 10B+ in the bank and 1000+ engineers to run the show.
This is why we need strong open source or liberally licensed components to build with. Small companies need to work together to keep up with the complexity of modern systems
Re: New Google SRE book: Building Secure and Reliable Systems
#203Earlier quoted context omitted.
You're absolutely right. I have heard that argument first had used as a means to shut down an initiative as well. These philosophies require massive judgement calls from engineering leadership with payback periods tracked in years, not quarterly OKRs.
The capacity of engineering organizations to successfully undertake multi quarter efforts is probably the best sign of competence. There seems to be a lot of short term thinking nowadays with projects based on quarters and those that don't bear fruit getting canned. Without long term investments, the org has to continuously put out fires which hobbles it and ultimately affects its ability to compete with other compan…
Re: New Google SRE book: Building Secure and Reliable Systems
#204Earlier quoted context omitted.
> Google can go ask Microsoft how it does make OEMs play by the rules OEMs of what ? All the custom forks of windows floating around? The mobile device market doesn't work anything like the deskop market, and you know that. Unless you're suggesting that the drivers for the networked, LED-light-toting hyper-gaming mouse you can get from Razer is more secure than OEM Android, because that's the closest things I can com…
OEMs of Windows Phone for example. My Windows 10 devices still get more security updates than a couple of Asus Android ones I have here lying around about the same age. You are the one moving the goal posts to consumer OSes, in a failed attempt to protect Google's security story. Well, if you want to go that way, then iOS has definitely a better security story than Android ever will. Every iOS powered device has the…
Re: New Google SRE book: Building Secure and Reliable Systems
#205Earlier quoted context omitted.
> Personally, I believe software that reduces the risk appropriately can be made, so I believe we can make software to manage these systems which is contrary to what you think I believe. I think you're just grossly overestimating the "risk" for most software. > I glossed over the point that the bug bounty should generally be order of magnitude the cost of discovery The bug bounty is the order of magnitude of the cost…
No, my bar for proselytizing about security practices is adequate, not perfect. The distinction is that adequate is an absolute bar, not a relative one, so "better" and "worse" are irrelevant until it is achieved since a "better" solution that is inadequate is not a solution that can be used (it is inadequate) and does not provide clear directions to an adequate solution. It is like climbing trees to reach the moon,…
And again, you consistently overestimate the value of a hack. You're not going to get root on every device. So the idea that apple is spending 5c per device isn't correct.
Again, you're overestimating the risk by imagining a magic rootkit that can simultaneously infect every device on the planet. That's not how things work. It lets your imagine these crazy values of a hack, but again: that's not how things work.
If it did, you'd probably see more hacks that infect everyone so that some organization can extract minimal value from everyone. But you don't see that.
Why? Because that's not a realistic threat model. State actors who, at this point are the only groups consistently capable of breaking into modern phones aren't interested in financing. They're interested in targeted attacks against dissidents.
So anyway, what makes you believe that Googles safety isn't adequate for it's systems, since at the moment anyway, they aren't manufacturing cars.
Re: New Google SRE book: Building Secure and Reliable Systems
#206Re: New Google SRE book: Building Secure and Reliable Systems
#207Earlier quoted context omitted.
The books read quite easy. The first book is just stories from google; it doesn’t really prescribe anything- it’s a collection of people talking about what SRE means to them and also how it fits together with “devops”. The second book (the SRE workbook) is more prescriptive, walks through practical ways of implementing it. The most base description of SRE principles is simply that: 1) You automate aggressively and de…
If somebody was in a hurry, which sections of which book should they start with?
SRE Workbook (https://landing.google.com/sre/workbook/toc/): Chapters 1, 2, 5, 6, 8, 16, 17, 19, 20, 21, All the Appendixes
Re: New Google SRE book: Building Secure and Reliable Systems
#208Let me guess. Now trying to destroy careers of security folks and replace with bad practices from the mouths of managers at Google. Wow! Gee. I'll buy a paper copy and burn it. 99% of people here are not in Google's use case, so this info can not apply. Brag brag. If you didn't learn the lesson from last book, enjoy. I'm just amazed by Google's ability to run huge kubernetes clusters all on windows, with zero network…
Re: New Google SRE book: Building Secure and Reliable Systems
#209Hi, I want a physical copy. I went to see how much they were to ask HR to buy one for me and found it was $52 on Amazon! What's up with that?
Re: New Google SRE book: Building Secure and Reliable Systems
#210Genuinely curious: What secure and reliable systems has Google built? Nothing really springs to mind. Android, their most popular end-user product, is a security disaster [1]. Chrome, "the most secure browser in the world", has a huge list of serious vulnerabilities [2]. [1] https://www.cl.cam.ac.uk/~drt24/papers/spsm-scoring.pdf [2] https://www.cvedetails.com/vulnerability-list/vendor_id-1224...
You believe that Google Accounts, GMail, and GDrive are fundamentally insecure and unreliable? Compared to what?