Earlier quoted context omitted.
A massively decentralised protocol would not exactly be the model of reliability, either. I'm not even sure how that could possibly work in a service like Twitter.
Has email ever been down, like, everywhere?
Twitter Completely Down
151–160 of 194 posts
Re: Twitter Completely Down
#152Earlier quoted context omitted.
Another striking example is the failure of Fukushima I and II. Basically what happend was that they had a power failure (of the external line)! They thought that was somehow too unlikely to account for, which I really have trouble with understanding. Isn't it obvious that multiple systems can fail because of some unaccounted for event external event? One that affects both, on-site and external power? And in the Japan…
Pedantic footnote: the Fukushima Daichi plant failure wasn't just a power failure: they had multiple backup diesel generators and batteries, and the diesels kicked in after the earthquake hit and the reactors tripped and they lost the grid connection. The problem was that all the diesel generators and fuel were at ground level and the sea wall wasn't high enough to keep the tsunami from flooding them a few minutes la…
My main beef with their failure handling is actually this: you need to be able to face a situation where _all_ you smart emergency systems fail. In the case of an NPP this can mean an almost global environmental crisis, and need relocate millions of people, making hundreds of square kilometers uninhabitable, etc. In that case you don't really want to rely on five generators on some roof. Which may or may not work on that day.
And this is not something I make up here now. I remember discussing nuclear safety in high school, and the bottom line was: NPPs are ok, since they become uncritical when _everything_ fails, because the moderator rods slide down into the reactor vessel.
But after Fukushima I read, that actually the situation there, with that specific model, is different, unfortunately. Tough luck. Because that model still needs some cooling because the fully moderated reactor still produces 1% it's total energy, an that is enough to bring the reactor into an 'undefined' state, iirc. And it is easy to imagine what that means for a station that has just been struck by an earthquake anyway.
My whole point is: your comment makes it appear as if the security layers actually were plenty, and I would (respectfully, of course) disagree with that. I think it was poor.
That point is important: if NPPs aren't build safely, what is then built safely? My guess is: nothing.
So what to do? Design for failure. (Politically, technically, economically, can be applied everywhere.)
End Of Rant :)
Re: Twitter Completely Down
#153Earlier quoted context omitted.
Pedantic footnote: the Fukushima Daichi plant failure wasn't just a power failure: they had multiple backup diesel generators and batteries, and the diesels kicked in after the earthquake hit and the reactors tripped and they lost the grid connection. The problem was that all the diesel generators and fuel were at ground level and the sea wall wasn't high enough to keep the tsunami from flooding them a few minutes la…
Yes, I know the full scenario was a bit more involved. My main beef with their failure handling is actually this: you need to be able to face a situation where _all_ you smart emergency systems fail. In the case of an NPP this can mean an almost global environmental crisis, and need relocate millions of people, making hundreds of square kilometers uninhabitable, etc. In that case you don't really want to rely on five…
Yup.
On a similar note, the French response to Fukushima Daichi is rather interesting (France relies on nuclear generation for over 80% of its electricity):
http://www.nature.com/nature/journal/v481/n7380/full/481113a...
"The ASN has also come up with an elegant technical solution to get around the (universal) dilemma of how to protect a plant from external threats, such as natural disasters. The report recommends that all reactors, irrespective of their perceived vulnerability, should add a 'hard core' layer of safety systems, with control rooms, generators and pumps housed in bunkers able to withstand physical threats far beyond those that the plants themselves are designed to resist."
(And a mobile emergency force who can move in and stabilize a reactor after an unforseen catastrophic disaster that kills everyone on-site and destroys most of the safety systems.)
In other words, they now expect unpredictable Bad Things to happen and are trying to build a flexible framework for dealing with it, rather than simply relying on procedures for addressing the known problems.
Re: Twitter Completely Down
#154Earlier quoted context omitted.
Pedantic footnote: the Fukushima Daichi plant failure wasn't just a power failure: they had multiple backup diesel generators and batteries, and the diesels kicked in after the earthquake hit and the reactors tripped and they lost the grid connection. The problem was that all the diesel generators and fuel were at ground level and the sea wall wasn't high enough to keep the tsunami from flooding them a few minutes la…
Yes, I know the full scenario was a bit more involved. My main beef with their failure handling is actually this: you need to be able to face a situation where _all_ you smart emergency systems fail. In the case of an NPP this can mean an almost global environmental crisis, and need relocate millions of people, making hundreds of square kilometers uninhabitable, etc. In that case you don't really want to rely on five…
Totally agree with you here - Until recently, no nuclear power plan was designed such that it could survive failure of all their emergency systems. Hopefully, with the negative repercussions of Fukushima on the industry, engineers are rethinking their approach to Nuclear Power.
Re: Twitter Completely Down
#155I think that a lot of you guys are confusing "Disaster Recovery" with "Business Continuity". Disaster Recovery is a reactive approach. It's what you do to get things back up AFTER a system or site has failed. Business Continuity is a proactive approach. It's what you do to ensure that your critical services will remain viable whenever disaster occurs. In the cases of Heroku, Amazon, Twitter, and many more, their Disa…
Re: Twitter Completely Down
#156Earlier quoted context omitted.
If a large manufacturer had a fire in their facility, it would certainly be industry news. This seems like a similar situation.
This is more like a large manufacturer having a power outage. A fire would destroy machinery or stock. Nothing's getting lost here, something's just unavailable.
Re: Twitter Completely Down
#157Earlier quoted context omitted.
Accidents happen. (expanding my reply) No risk assessment in the world will stop a cage monkey from tripping over a pile of 1Us and falling onto the big red button. Figure out what your pain threshold is and live with it.
This is called "acceptable risk". If it would cost $3m to eliminate the risk and the damages would only total $1.5m, that would be an acceptable risk.
statistical distributions that include a risk aversion parameter exist precisely to model this kind of problem (unfortunately their names have slipped my mind, otherwise I'd provide links)
Re: Twitter Completely Down
#158Earlier quoted context omitted.
If one of the largest services in the valley being down is not tech news, then what exactly do you think would be news? Think of "twitter being down" as Silicon Valleys equivalent to hollywoods "Lindsey Lohan is drunk in jail again".. The tech companies, their founders staff and services are our pop-culture to gossip about.
> Think of "twitter being down" as Silicon Valleys equivalent to hollywoods "Lindsey Lohan is drunk in jail again".. This is Hacker News, not Globe for Hackers. Seriously, tabloid-esque coverage of tech companies adds nothing of value at all.
the word has been appropiated by those who are needy like that: you don't call yourself hacker, just like you don't call yourself saint. only mediocre people to whom it never applied and never will would do that. the end.
Re: Twitter Completely Down
#159x is down: http://blog.jgc.org/2010/10/x-is-down.html
xx Next time your favorite waste of time is down, just shut up about it. xx Twitter is infrastructure for us in media. It's well worth discussion.
also, "us in the media", what kind of whore talk is that even? twitter is correctly referrerd to in w3c docs as medium preventing intelligent discussion. so it was down? GOOD. people are inconvenienced? even better! it cannot possibly have hit anyone or anything that was worth fuck all.