Live data from Hacker News

Interview with CEO of rsync.net: “no firewalls and no routers”

console.dev

151–160 of 343 posts

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#151
post #91
post #74

Earlier quoted context omitted.

The only "security risk" i see there is number 1, and that is all to do with physical security. > Disadvantage #1 – Open ports on unmanaged switches are a security risk Why? Is there something that would prevent an attacker with physical access from unplugging an existing cable? Does the average managed switch config have mac limits and auto shutdown if a link is lost for just a few seconds? Mac limits are easilly by…

> Correct they can't. Managed switches without qos set up can't prioritise traffic either. > If your switch is dropping packets, you don't have enough bandwidth. this isn't true, there exist more bottlenecks than just bandwidth, e.g. try sending 10 byte packets instead of 1500 byte packets and watch as your switch starts dropping due to CPU exhaustion > Ultimately it comes down to how big your buffers are whether you…

> not really, traffic prioritisation is about deciding which packets you drop when hitting your limits

But everything is the same: ssh traffic for backups. And both ends do congestion control.

I don't care if nightly backups take 1 or 2 hours.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#152
post #53
post #48

I wonder if they have any sales to large enterprises or similar institutions. In my experience, the larger organizations will have a "security" questionnaire required of their vendors, and the person administering it is a droid, incapable of evaluating whether the questions, originally written in the mid-00s and only updated for buzzword compliance since, are applicable to modern security practice today, or to the pa…

"I wonder if they have any sales to large enterprises or similar institutions." Yes, certainly. We frequently fill out very detailed checklists and questionnaires related to our quality policy, standards, internal policies, etc. We're also very honest about how we approach these issues: https://www.rsync.net/resources/regulatory/pci.html ... and they generally appreciate the honesty.

Isn't the nice thing about having an access fortress, that you can monitor the access more simply? Or is it just as simple for you to monitor access to all the identically configured machines? I suppose it might be.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#153

John's usage reminded me of something I read in Rob Rike's "Uses This" interview[1]: "I want no local storage anywhere near me other than maybe caches. No disks, no state, my world entirely in the network. Storage needs to be backed up and maintained, which should be someone else's problem, one I'm happy to pay to have them solve." [1] https://usesthis.com/interviews/rob.pike/

Essentially a Chromebook

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#154
post #98

I always liked this set of marketing materials. But I also see where they conflict with my experience. "You may visit our datacenters any time you like for a personal tour and inspection to satis[f]y whatever due diligence requirements you may have" probably appeals to many customers, but for my dollar I would prefer a datacenter that nobody may enter.

> I would prefer a datacenter that nobody may enter.

If a disk break, who changes it?

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#155
post #53

Earlier quoted context omitted.

"I wonder if they have any sales to large enterprises or similar institutions." Yes, certainly. We frequently fill out very detailed checklists and questionnaires related to our quality policy, standards, internal policies, etc. We're also very honest about how we approach these issues: https://www.rsync.net/resources/regulatory/pci.html ... and they generally appreciate the honesty.

It’s hilarious that the first "vulnerability" in the example report[0] linked in this page is basically "SSH is accessible". Well… Duh ! [0] https://www.rsync.net/resources/regulatory/PCI_usw-s005_repo... EDIT: It’s marked as "PASS" though, so it’s all fine, just funny.

I once had a someone report responding to ping as a vulnerability. For the public facing firewall.

We sent them back a link of prominent servers that respond to ping.

Including the web server of the expensive agency that had produced the report. And whose web server had an expired SSL certificate.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#156
post #79

Earlier quoted context omitted.

I would love to use this simple setup as well. It's too bad ZFS snapshots cannot be sent and stored encrypted. I would love to use rsync.net but the idea to have my data sitting in someone else's computer in plain text feels wrong. So instead I have to use restic, which re-implements many features of ZFS and this also feels wrong.

You can 'zfs send' to a (special kind of) rsync.net account. We support encrypted zfs[1][2][3] and raw-send, etc. The pricing is the same but there is a 1TB minimum because we need to give you your own VM (bhyve) and we have to burn an ipv4 address for you, etc. [1] https://www.rsync.net/products/zfs.html [2] https://arstechnica.com/information-technology/2015/12/rsync... [3] https://www.servethehome.com/automating-p…

Sounds like a good opportunity for an IPv6-only version at a discount/lower minimum. Many people (Google says 45% in the US) don't need servers to have v4 these days.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#157
post #125

I used to run Linux for everything but I’m having to use Windows these days. What would it take to get rsync.net playing nicely with windows? I’m imagining Windows subsystem for Linux (ubuntu) with duplicity installed to it? Are there any major hiccups to that sort of setup?

Rsync.net is amazing for Linux servers. For windows servers backups are complex and expensive. I tend to offload that to a cloud provider like Azure. Onsite I rotate hard drives. But for desktop users backblaze does everything I need. If anyone has a recommendation for backing up Windows servers I'd love to hear it.

It looks like rsync.net is indeed compatible with Windows, just perhaps not out of the box. Keeping in mind that SSH on windows is somewhat new and I haven't really tried it with a service like this yet.

If you can get command line access to rsync.net with openssh and either CMD or Pwsh, then robocopy can forklift your stuff. This is without even getting into the weeds of the fact that WSL exists...

I am also seeing that some documentation exists for pointing Veeam at it, which is my preference. I don't run any metal computers that aren't hypervisors and using that to back up my VMs, be they windows or linux, is my preference.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#158
post #41

Earlier quoted context omitted.

As opposed to how “easy” it is to install Linux this doesn’t seem half bad.

What do you mean? You download an ISO, put it on a USB key or burn it to a CD, and install it like you would Windows10 or any other OS.

You download an ISO, put it on a USB key or burn it to a CD, and install it like you would Windows10 or any other OS.

If only it was that easy all the time.

I have an old laptop (2017) that I wasn't for anything else, using so I tried putting Linux on it. Nope. I went through five distributions before I found one that would finally work. And then, it was not really useable.

The whole reason people use MacOS is because they know what to expect. Linux is still a crapshoot.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#159
Meta: I really dislike the style of console.dev, the article is shunted to the left and leaves the rest of the screen real estate to be taken up by an - albeit pretty - but unnecessary piece of digital artwork. This - https://ibb.co/nzbFxjW - is what the article looks like on my ultrawide which made for very uncomfortable viewing

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#160

John's usage reminded me of something I read in Rob Rike's "Uses This" interview[1]: "I want no local storage anywhere near me other than maybe caches. No disks, no state, my world entirely in the network. Storage needs to be backed up and maintained, which should be someone else's problem, one I'm happy to pay to have them solve." [1] https://usesthis.com/interviews/rob.pike/

Essentially a Chromebook

It’s worth reading the rest of the interview, I find Rob Pike has a very interesting/unique take on the current landscape given his involvement with Plan 9:

> Now everything isn't connected, just connected to the cloud, which isn't the same thing. And uniform? Far from it, except in mediocrity. This is 2012 and we're still stitching together little microcomputers with HTTPS and ssh and calling it revolutionary.

Post reply on HN