Live data from Hacker News

Servers as they should be – shipping early 2022

oxide.computer

231–240 of 264 posts

Re: Servers as they should be – shipping early 2022

#231
"Attests the software version is the version that is valid and shipped by the Oxide Computer Company"

this makes "Oxide Computer Company" the primary target and point of vulnerability in multiple ways.

1) rogue employees (state-sponsored, corporate espionage) could replace the software. customers could do nothing about it, and might not even be told.

2) sale of the company by the VCs or a Corporate take-over gives no guarantee that what is safe now will be safe in future, no matter what the VCs or the company says right now.

3) whatever expertise "Oxide Computer Company" thinks they have, they're the single-point-of-failure. the larger the number of customers, the less likely that a given vulnerability will be immediately fixed and distributed out.

this is just some of the possibilities. sorry to say that there's so many things wrong with this idea it's really hard to hold back and not say anything.

now, if the full source code right to the bedrock is available, and the CUSTOMER is given FULL CONTROL, THEN we do not have a problem.

by "full control", that includes:

* all DRM keys including TPM signing private keys * all peripheral initialisation source code (including DDR4 firmware, PCIe firmware and USB3 firmware) * BMC (Boot Management Console) source code * BIOS source code * Operating system source code * full source code for all tools and toolchains for the above to avoid vendor lock-in and the possibility of the toolchain itself introducing rogue code.

this is one hell of a list and it's almost impossible to fulfil with today's "NDA'd proprietary firmware 3rd party licensing" mindset. the only company in this secure server space to my knowledge that's achieved this is Raptor Engineering with the TALOS-II, when running with the Kestrel BMC replacement, on the Lattice ECP5 FPGA.

Re: Servers as they should be – shipping early 2022

#232

Hmm. They basically reinvented mainframes. Seems it has a lot in common with Z series. Scalable locked in hardware, virtualization, reliability, engineered for hardware swaps, upgrades. A proprietary operating system (?) from what someone said. (Offshoot of Solaris +++ (???) By that I mean that most of it, or all of it might be open sourced forks, but it will be an OS only meant to run on their systems. (It would be…

Their approach to reliability isn't quite on par with mainframes, AIUI. At least, not yet. And the programming model is also quite different - a mainframe can seamlessly scale from lots of tiny VM workloads (what Oxide seems to be going for) to large vertically-scaled shared-everything SSI, and anything in between.

Ignoring hardware reliability, thanks to the integration, their solution should be more reliable than whatever byzantine solutions are currently used in their target market. I've worked in a shop (a well-known name that I won't mention) that had a mix of "chat ops" and Perl scripts integrated with JIRA where you could request a Linux VM through a JIRA ticket and get it automatically provisioned, I assume from some big chassis running VMWare, and then use git+Puppet to configure it. It works, but it's a lot of software from different sources and there is always one thing or the other failing. And the security of all that stuff is probably patchy, regardless of audits.

That being said, this solution is the mother of all lock ins...

I could see it used for the non-critical part of a company's infrastructure. I would not run production stuff on it, but it could work for development systems, test boxes, etc. Basically give developers access and let them create and destroy as many VMs as they need, whenever they need.

Re: Servers as they should be – shipping early 2022

#233
post #157
post #146

Earlier quoted context omitted.

Going by that logic, you should never take a chance on a bad company because they are bad, and a good company because they are too good and might get acquired. So should you just never rely on a small company for anything?

That's the question I was genuinely asking. Do longer-term minded buyers think this way? Our company is too small and just use AWS, we're just not perspective buyers. But I'm trying to understand the mindset of a CapEx style buyer whose timelines are multiple years. This team is, by all measures, going to hit it out of the park. There's just a solid amount of talent, experience and insight all-round. And to be clear,…

No one is going to bet the farm on that solution. I'd be surprised if big SaaS vendors like Atlassian or DropBox go with it.

But on the other hand I can see F500s (oil & gas companies, big engineering and defense firms, etc.) getting a rack or two to run their cloud-like stuff. They would not be taking much risk; this would be one system among many others they have, and it will have a life of 5 to 7 years anyway (a few million dollars and 7 years is peanuts for an oil & gas or mining company whose CapEx goes into the billions, over 50+ years horizons). I think the value is in having a cloud-like system that doesn't require an entire IT/Ops team to run.

Re: Servers as they should be – shipping early 2022

#235

Earlier quoted context omitted.

Your approach to pay is really refreshing and attractive as an engineer, and also seems like the exact type of thing most VC or larger tech firms would really hate. That alone feels like evidence of your conviction

Ha! Well, I think our investors think we're very idiosyncratic -- but they also can't help but admire the results: a singular team, drawn in part by not having to worry about the Game of Thrones that is most corporate comp structures. ;)

I hope you are able to keep the investors convinced and stick with it! I'm a Swedish-American that's mostly lived in the US, but has been working back in Sweden for the last 4 years. I'm culturally mostly Californian, but the work atmosphere in Sweden is just less cut throat and much nicer. You pay with salary sure, but it's definitely worth it. Your descriptions on the website feel a bit similar.

I presume you wouldn't consider European remote given your PST timezone requirement, but I guess I'll consider your company one of those dream places to work were I to make my return to the US!

Re: Servers as they should be – shipping early 2022

#236
post #13

Earlier quoted context omitted.

Can definitely see it for a company size of Dropbox, big enough to already be working with ODMs, big enough to be sensitive to the kind of headaches you get from a heterogeneous fleet of ILOM processors designed by deranged engineers.

> ILOM processors designed by deranged engineers. As opposed to what? But seriously, why do all ILOMs suck and are there any exceptions?

The people behind OpenBMC, RunBMC, LibreBMC are hoping to fix this.

Re: Servers as they should be – shipping early 2022

#237

Earlier quoted context omitted.

This is not my area of expertise, but it does look like that[0]. That "custom software," though, is where the magic often lies. As a software person that worked at hardware companies for most of my career, I know all too well, how disrespectful hardware people are of software. If they have a good software-respecting management chain, then it might be pretty awesome. [0] https://www.prnewswire.com/news-releases/viking…

Let's be honest, software people are pretty disrespectful about hardware, too.

Not me. I started as an EE.

Wanna check out my first professional engineering project ever?

https://littlegreenviper.com/TF30194/TF30194-Manual-1987.pdf (Downloads a PDF)

Re: Servers as they should be – shipping early 2022

#238
post #9

This looks interesting (although I'm not in the target market, too small)... But if I were looking at this, judging from the quality of people they've amassed in their engineering team, is there any chance they won't be acquired in 6 months? To anyone looking to take a bet on this, what is the answer to "what's your plan for when your stellar team gets acquired?" And what answer will satisfy that buyer? Update: Addin…

Private companies can't just get bought out. They have to agree to be acquired. There is not some roaming force of Big Corp M&A people who forcefully acquihire companies.

I don't understand this concern at all.

Re: Servers as they should be – shipping early 2022

#239
post #90

May be instead of asking target market or audience, who are their competitors? (Edit: Previous Discussions https://news.ycombinator.com/item?id=21682360 ) Also thinking if the Website is not finished? All the "Read More" actually hide very little information, if so why hide it? And doesn't seems to explain the company very well. Seems like we need to listen to their PodCast to find out what is going on. ( Edit: Found…

> ...who are their competitors?

Literally every single server vendor, and almost all (if not all?) storage vendors on the planet are pushing HCI because that is what mid and large size companies want. This is the fastest growing market segment in hardware (because they now realize that hybrid-cloud is the preferred customer model, and most of their customers now are deploying or already have deployed their own internal cloud). Oxide appears to me to be HCI done correctly. I currently work for one of their competitors, and for one, am keeping at eye on their careers page!

Also, 100Gb meets requirements for 99.999% of the customers out there.

Re: Servers as they should be – shipping early 2022

#240

Earlier quoted context omitted.

Your approach to pay is really refreshing and attractive as an engineer, and also seems like the exact type of thing most VC or larger tech firms would really hate. That alone feels like evidence of your conviction

Ha! Well, I think our investors think we're very idiosyncratic -- but they also can't help but admire the results: a singular team, drawn in part by not having to worry about the Game of Thrones that is most corporate comp structures. ;)

Just curious - do 0xide employees currently receive ISOs or RSUs?
Post reply on HN