Live data from Hacker News

New Google SRE book: Building Secure and Reliable Systems

landing.google.com

221–227 of 227 posts

Re: New Google SRE book: Building Secure and Reliable Systems

#221
post #220

Earlier quoted context omitted.

If you believe a zero click iOS compromise would infect more than 20k devices, can you give an example of such a thing happening? If not, why not? Do you believe that 20000 people would never noticed such a thing over a sustained period? As for 2: there are public examples (again, Aurora) of teams with more funding being caught in less time. So I think you are underestimating the security capabilities of Google (and…

https://googleprojectzero.blogspot.com/2019/08/a-very-deep-d... 5 zero-click compromises. Thousands per week for a total of 2 years before discovery. The 5 chains being: 3 months, 6 months, 10 months, 6 months, 3 months each. At thousands per week, that is 12k, 24k, 40k, 24k, 12k new compromises per chain at a minimum, probably closer to 5x those numbers. Incidentally, at the bottom of the initial post they mention:…

You're not likely to get any more information on Aurora than what's on the wikipedia page. It includes some breakdown of the attacks (among other things, zero days in internet explorer).

> At thousands per week, that is 12k, 24k, 40k, 24k, 12k new compromises per chain at a minimum, probably closer to 5x those numbers.

That assumes every visitor uses iOS 10-12. Which is...not likely. My understanding is that these sites were likely Chinese dissident forums, and I don't think that iOS 10-12 makes up even half of browsers in china. Nor does it make sense that every user is unique. This isn't to downplay the danger of these attacks, but no you're likely looking at compromising 1-2K devices total when it comes down to it.

But again, you're looking at state actors (not even nation state actors at this point, but like the Chinese version of the NSA/CIA) with hundred million or billion dollar budgets. If those are the only people capable of exploiting your software, you're doing an objectively good job.

Re: New Google SRE book: Building Secure and Reliable Systems

#222
post #192

Earlier quoted context omitted.

Actually the epub is so badly formatted, that Google Play Books does not even process it and fails. When i run it through epubchecker/Calibre, it shows 215 errors. Probably something you want to look at.

Thank you for letting us know Lucian! I shared your comment with our publisher (O'Reilly). (disclaimer: I worked on the book)

Here is the patch for the faulty epub.css: https://gist.github.com/luckylittle/9a6d99def44a48796fbcb147...

Re: New Google SRE book: Building Secure and Reliable Systems

#224

Earlier quoted context omitted.

It's not as applicable to startups as you would think. The real calculation startups are making all of the time that this book doesn't mention is "is it worth making this particular piece scale/secure/robust before we run out of money?" While it's technically true that the advice would apply to startups in the sense that it would improve their reliability, the elephant in the room is that it doesn't matter. The engin…

The "is it doing X before we run out of money?" question is way overblown in startup land, usually by product people to skew developer time towards more features instead of much needed foundational work. In reality, this question is almost always instantly answerable. You're either still building out your MVP and desperately need customers to validate your idea, in which case the answer is "No", or you're an establis…

I disagree. There is a valuable question of "how reliable does this system need to be?" and for startups, the answer is often not 5 9s of uptime.

99% uptime is 14 minutes of downtime per day. There are an awful lot of processes and even whole businesses that can eat 14 minutes of downtime a day. Especially if it's not a full outage.

Re: New Google SRE book: Building Secure and Reliable Systems

#225
post #27

Off-topic: It made me chuckle to see this well-designed page, with great+free content, and also pulling in angular.js, doesn't follow Google's recommended practices for SERP, e.g. meta tags so that pasting the link into Slack, etc. displays some info rather than just the bare URL

Is there a Slack setting for this? I personally prefer bare URLs and always have to manually edit my messages to remove the URL info snippets.

Yeah as long as you're admin: https://slack.com/intl/en-fi/help/articles/360001502048-Mana...

Re: New Google SRE book: Building Secure and Reliable Systems

#226
post #197

Let me guess. Now trying to destroy careers of security folks and replace with bad practices from the mouths of managers at Google. Wow! Gee. I'll buy a paper copy and burn it. 99% of people here are not in Google's use case, so this info can not apply. Brag brag. If you didn't learn the lesson from last book, enjoy. I'm just amazed by Google's ability to run huge kubernetes clusters all on windows, with zero network…

Did you get rejected while Interviewing at Google? It's the only plausible explanation for the vitriol on your throwaway account.

Are you a Linux Systems Administrator? If not, stfu.
Post reply on HN