If it were me, and I wasn't willing to just block the traffic, I might just set a 128 kbps limit on it and call it a day[1]. Eventually, the other side will figure out that their fetchers are all backed up and work out how to do their job without burning so much bandwidth. [1] Yeah, that can be a bit of a pain to setup depending on the server settings, but some people have to pay for bandwidth and server resources, s…
Google has been DDoSing Sourcehut for over a year
61–70 of 225 posts
Re: Google has been DDoSing Sourcehut for over a year
#62Earlier quoted context omitted.
> In the meantime, if you would prefer, we can turn off all refresh traffic for your domain while we continue to improve this on our end. That would mean that the only traffic you would receive from us would be the result of a request directly from a user. This may impact the freshness of your domain's data which users receive from our servers, since we need to have some caching on our end to prevent too frequent fet…
How are his arguments in bad faith if he is the one that gets DDoSed by your software for over a year, and still tries to be helpful? Not sure if you realize the absurdity of this, but he has to pay traffic and server costs. Like everyone else, except probably Google as it seems!? I mean, you didn't even consider implementing a simple fetch of an already cloned repository in your mirroring server code . So yeah, I'd…
"Assuming everyone else have exactly same design choice and architecture as yourself, making suggestion on this ground and calling other people crazy because they can't implement what you suggest them to do" is not trying to be helpful.
Well, or maybe I'm just frustrated reading his repeated "please keep a copy 'locally' somewhere and run git fetch". Just like how I'm frustrated arguing with him on HN about whether sending patch to mail list is better than GitHub pull request.
Don't get me wrong, I understand this is a real Google-scale system v.s. individual code hosting website issue, I just don't see how his "please stop being Google and instead try my works-fine-on-one-box solution" take is helpful.
Re: Google has been DDoSing Sourcehut for over a year
#63Earlier quoted context omitted.
> In the meantime, if you would prefer, we can turn off all refresh traffic for your domain while we continue to improve this on our end. That would mean that the only traffic you would receive from us would be the result of a request directly from a user. This may impact the freshness of your domain's data which users receive from our servers, since we need to have some caching on our end to prevent too frequent fet…
How are his arguments in bad faith if he is the one that gets DDoSed by your software for over a year, and still tries to be helpful? Not sure if you realize the absurdity of this, but he has to pay traffic and server costs. Like everyone else, except probably Google as it seems!? I mean, you didn't even consider implementing a simple fetch of an already cloned repository in your mirroring server code . So yeah, I'd…
Re: Google has been DDoSing Sourcehut for over a year
#64Earlier quoted context omitted.
I think he's been banned from the issue tracker.
Possibly, but he was actively participating in https://github.com/golang/go/issues/44577 up until the week it was fixed. If that's the root of the issue though, most of the article ("no one will get promoted for prioritizing that at Google.", "the go team has not prioritized it", etc.) is wrong. They may not have addressed the issue in the precise way he wanted, but I also think it's rather unreasonable to expect som…
The other user who accepted that proposed fix had a single module that had a single user, so they can tolerate some weird caching behavior for their toy project.
Re: Google has been DDoSing Sourcehut for over a year
#65Wait... Why not black hole them? Make it their problem and they'll eventually do the correct thing.
Re: Google has been DDoSing Sourcehut for over a year
#66The fact that a programming language calls home to by Google by default should make it a non-starter for most sane developers. The fact that it calls home so it can DDoS other sites is low-key hilarious. And you'd think Google would know how to like... operate an efficient CDN, perhaps? Like, if this was managed by a competent company, you'd think this service would be akin to putting Cloudflare in front of your serv…
Are you going to get upset at node for calling home to Microsoft (npm owned by github owned by microsoft) when using the supplied package management too?
Re: Google has been DDoSing Sourcehut for over a year
#67Earlier quoted context omitted.
Are you going to get upset at node for calling home to Microsoft (npm owned by github owned by microsoft) when using the supplied package management too?
How could node not do that? NPM hosts all the packages so of course it does.
Re: Google has been DDoSing Sourcehut for over a year
#68Re: Google has been DDoSing Sourcehut for over a year
#69Earlier quoted context omitted.
> In the meantime, if you would prefer, we can turn off all refresh traffic for your domain while we continue to improve this on our end. That would mean that the only traffic you would receive from us would be the result of a request directly from a user. This may impact the freshness of your domain's data which users receive from our servers, since we need to have some caching on our end to prevent too frequent fet…
How are his arguments in bad faith if he is the one that gets DDoSed by your software for over a year, and still tries to be helpful? Not sure if you realize the absurdity of this, but he has to pay traffic and server costs. Like everyone else, except probably Google as it seems!? I mean, you didn't even consider implementing a simple fetch of an already cloned repository in your mirroring server code . So yeah, I'd…
https://github.com/golang/go/issues/44577#issuecomment-11378...
> We did consider caching clones, but it has security implications and adds complexity, so we decided not to. It is certainly not trivial to do and not something we are likely to do based on this issue.
Drew continues to act as though he is always correct, and any viewpoint that isn't his is just moronic. I've repeatedly seen this behavior from him in multiple venues over the years, and I'm happy to see the wider community start calling this out as childish.
Re: Google has been DDoSing Sourcehut for over a year
#70Earlier quoted context omitted.
How are his arguments in bad faith if he is the one that gets DDoSed by your software for over a year, and still tries to be helpful? Not sure if you realize the absurdity of this, but he has to pay traffic and server costs. Like everyone else, except probably Google as it seems!? I mean, you didn't even consider implementing a simple fetch of an already cloned repository in your mirroring server code . So yeah, I'd…
bad faith refers to his behavior on other issue threads. also he (used to) spam the issue tracker with ads for his services
If there's any entity I'm totally ok with anyone spamming with ads, it's Google.