Live data from Hacker News

Excessive load on NTP servers

news.ntppool.org

111–120 of 157 posts

Re: Excessive load on NTP servers

#111
post #97

Earlier quoted context omitted.

I agree with what you've said but IMHO is a dishonest way of living. I'd rather be poor than a suck up.

I don't disagree with you about the dishonesty of living a suck up life, but try actually being poor for a little while. Your tune will change to "Where would you like me to suck?" and "How hard?" very quickly. I have the advantage to be able to leave a job and find another relatively easily, and I would definitely agree that I'd rather leave then suck up, but for those who don't have that kind of mobility, sucking u…

Yeah, this is also an element that's important not to discount, and can help describe why it's hard for engineers and other high-IQ roles to accept that social compliance is the #1 factor in all ongoing voluntary associations.

We're really spoiled in tech because the field is so abundant. We offend someone or get offended, and we're off to greener pastures within weeks if not sooner. I've come to believe that hopping around like this, which I've done for most of my career up to this point, is not healthy, but the availability means that technical people don't have to learn to conform as well as everyone else to survive. And while that means we may be able to keep a job, it's hard to move up.

These things that we struggle with are just normal life to a lot of people. They had to swallow these compromises early in life when it was apparent that good feelings were all they would be able to offer.

This contributes to the cycle because those people pay their dues to the establishment, go through the process, and get used to the circlejerk. They then expect everyone else to do the same.

When someone wants to come in and challenge some of their thoughts, opinions, or practices, even minor things, in what the challenger feels is a sporting way or a way to drive an interesting and inoffensive discussion, the "good feelings violation" siren fires off in the non-technical person's head.

This brings in a large flood of negative feelings and resentment, including but not limited to jealousy that you can express your thoughts openly while they've always had to kowtow, a sense that you're entitled for thinking you should be able to do this and "dictate from your expertise" (as was expressed about me once) instead of "climbing the ranks" the hard way and then quietly and subtly implementing your opinion after you've won the social clout like everyone else has to do, and a sense that you may represent a threat to the perceived competency of the challenged person (and those least competent will be the most aggressive protectors of this perception) in the minds of the people whose trust they live off, which is really everyone -- colleagues, subordinates, and superiors -- which means it's very difficult to overtly question or discuss anything done by anyone, even in what you believe is a polite or considerate way.

Exceptions are basically not made to this. The potential of substantial data loss, massive security holes, etc., are irrelevant. If someone grossly incompetent like this is on your team, the smart move is NOT to challenge or disprove, because again, no one evaluates proof on any basis except "which proponent do I trust more?". The smart move is to frame the situation such that his failures are opportunities for you to deduct from his social clout and add into your own, without ever firing an alarm in anyone's mind that you're trying to do this.

It's all an image game. As an individual contributor, you can avoid a lot of this game as long as you're non-threatening, churn out semi-reliable work, and are at least not annoying if not socially pleasant. Once you try to move up the ladder, even just one rung, image and likability goes from 65% of the equation to 99%.

Re: Excessive load on NTP servers

#112

Why on earth would you do that? If you want to prevent users from altering their time use your server and do a time compare with your server. NTP can be easily intercepted and altered so it would make a lot more sense to do this via a encrypted certificate pinned communication path increasing my work load drastically to alter the time. I snapchat going to pay for the DDOS they created?

Stupid decision by SC for sure, but is there a reason there is no rate-limiting on the NTP servers? I'm not up to date on their structure. Maybe it's just not feasible because they don't synchronize clients?

NTP has rate limiting built into the protocol (https://www.eecis.udel.edu/~mills/ntp/html/accopt.html), but Snapchat appear to be using a large list of servers.

Also, NTP runs on UDP rather than TCP, and it only requires one packet from each party to exchange time, so it's harder to rate-limit it without making your server unreliable.

Re: Excessive load on NTP servers

#113

Earlier quoted context omitted.

I got told off for diagnosing issues in the past. The IT director is a megalomaniac and interprets it as a challenge to his power. The only time I offer suggestions now is when one of his employees specifically asks me for help. Edit: I realize "got told off" didn't really capture what happened. I came in early one day and noticed we were having a dns issue. I manually refreshed my DNS cache and it started to work. I…

If a cached DNS record expired it would not be a problem. If a bad or old record was cached before TTL, clearing your cache works to update it. Maybe ITs ego didn't like your terminology of DNS cache being expired, and telling them theirs is- by definition expired records get looked up again because they no longer exist locally. As former IT it was mildly irritating to get unsolicited advice, But still it sounds like…

Right, the DNS records weren't expired, they were no longer accurate. I'm not sure what the word for that is. The Windows DNS Cache on the local machines was inaccurate. Basically, I couldn't access any websites I had accessed before, but if I tried accessing a new site it worked fine. If I forced a DNS request for a site I had already visited, that site would start working but all the other sites would still be broken.

I knew what the problem was because I had run in to that issue a few years back with my own computers. After I updated my DNS, all the Windows computers were having issues, but none of the Linux ones were. That's when I learned that Linux doesn't typically cache DNS records on local machines.

Re: Excessive load on NTP servers

#114

Earlier quoted context omitted.

where do you work, and more importantly, why do you still work there?

I work in non-profit fundraising. I'm currently looking for a role, but I've worked here for 3 years because I have been able to basically do whatever I want. I'm a combination of analyst, data scientist, and marketer. I'm in charge of our appeals, from strategy all the way to the money coming back in house. We have over half a million constituents. It's really great if you are interested in testing. I've sent out ma…

you've got a great skillset. I think you could find a similar role at another company where you weren't being limited by a shitty IT department and internal politics.

Re: Excessive load on NTP servers

#115

Earlier quoted context omitted.

I work in non-profit fundraising. I'm currently looking for a role, but I've worked here for 3 years because I have been able to basically do whatever I want. I'm a combination of analyst, data scientist, and marketer. I'm in charge of our appeals, from strategy all the way to the money coming back in house. We have over half a million constituents. It's really great if you are interested in testing. I've sent out ma…

If you're looking for a role, you might want to put contact info in your profile. I certainly looked :)

Good call. I thought it was possible to message me as long as the email field was filled in. I hadn't put my email in the description because it's my actual name at gmail. I've added it now.

Re: Excessive load on NTP servers

#116
post #97

Earlier quoted context omitted.

I agree with what you've said but IMHO is a dishonest way of living. I'd rather be poor than a suck up.

I don't disagree with you about the dishonesty of living a suck up life, but try actually being poor for a little while. Your tune will change to "Where would you like me to suck?" and "How hard?" very quickly. I have the advantage to be able to leave a job and find another relatively easily, and I would definitely agree that I'd rather leave then suck up, but for those who don't have that kind of mobility, sucking u…

I've been poor. £12 a week ($20) to feed three, evicted from rental, no job (because of an asshat)

Re: Excessive load on NTP servers

#117
post #79

Earlier quoted context omitted.

Even without thinking about storing some context, replying to NTP request is probably similarly expensive as evaluating whether it should be rate limited.

Yeah exactly this. Rate limiting isn't free. It's almost certainly more expensive to rate limit than to statelessly respond with the time.

NTP does store context for a limited number of clients (600 by default). https://www.eecis.udel.edu/~mills/ntp/html/miscopt.html

Re: Excessive load on NTP servers

#118

Earlier quoted context omitted.

I work in non-profit fundraising. I'm currently looking for a role, but I've worked here for 3 years because I have been able to basically do whatever I want. I'm a combination of analyst, data scientist, and marketer. I'm in charge of our appeals, from strategy all the way to the money coming back in house. We have over half a million constituents. It's really great if you are interested in testing. I've sent out ma…

you've got a great skillset. I think you could find a similar role at another company where you weren't being limited by a shitty IT department and internal politics.

Thanks, that's a real confidence boost. My formal education was in biology with an almost minor in computer science. I am a little self-defeating sometimes because I don't have a stats/marketing or CS degree, and a lot of job postings have a relevant degree as a requirement.

The IT may be terrible, but I'm very thankful for the opportunity I've had to develop these skills. It's really unfortunate how one or two people can ruin an organization. The rest of the people here are incredibly kind and incredibly driven people.

Re: Excessive load on NTP servers

#119
post #78

Earlier quoted context omitted.

They could just use their own canonical time (from their server) instead of hammering NTP. It doesn't say anything about synchronisation between phone and server. EDIT: In fact it is easier to implement it this way than using NTP. I've implemented something similar and I found it easier to add an API endpoint that returns time() than to ship an NTP client...

But then you need to manage a server and ensure that the time is running accurately. Why add such a large level of responsibility for little to no gain?

They could at least be good citizens and use their success to beef up the NTP pool.

Re: Excessive load on NTP servers

#120
post #76

Earlier quoted context omitted.

Currently looking. I finally came to my last straw recently. A coworker sent me an email because some data I was in charge of adding to the system was missing. I looked, and somehow data in our database had gone missing. I use the data to add information to another database, and that database had the information in it. So somehow he managed to lose information in SQL Server. A few weeks later, my boss brought me in t…

I've seen this happen as well. Data "mysteriously" reverted and it turned out to be an unrequested database restore. They reverted to a recent backup but didn't mention it to anybody so a few days of data was missing.

That is definitely what happened. One manager found out about this and called him and ended up verbally tearing in to him for like an hour. She is really task-oriented and gets really frustrated with how often I want to change things just to see what happens. It felt really good to hear her step up to defend me, because she would only do that for someone who she really respects.
Post reply on HN