Live data from Hacker News

Interview with CEO of rsync.net: “no firewalls and no routers”

console.dev

91–100 of 343 posts

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#91
post #74

Don't know if running a dumb switch connected to your ISP is the best infosec policy: https://blogs.cisco.com/manufacturing/the-top-5-reasons-to-a...

The only "security risk" i see there is number 1, and that is all to do with physical security. > Disadvantage #1 – Open ports on unmanaged switches are a security risk Why? Is there something that would prevent an attacker with physical access from unplugging an existing cable? Does the average managed switch config have mac limits and auto shutdown if a link is lost for just a few seconds? Mac limits are easilly by…

> Correct they can't. Managed switches without qos set up can't prioritise traffic either.

> If your switch is dropping packets, you don't have enough bandwidth.

this isn't true, there exist more bottlenecks than just bandwidth, e.g. try sending 10 byte packets instead of 1500 byte packets and watch as your switch starts dropping due to CPU exhaustion

> Ultimately it comes down to how big your buffers are whether your packet gets through or not

not really, traffic prioritisation is about deciding which packets you drop when hitting your limits (or close to), not making sure that you never drop anything

obviously if you're never hitting any bottlenecks: the prioritisation does nothing

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#92
post #79

Earlier quoted context omitted.

I would love to use this simple setup as well. It's too bad ZFS snapshots cannot be sent and stored encrypted. I would love to use rsync.net but the idea to have my data sitting in someone else's computer in plain text feels wrong. So instead I have to use restic, which re-implements many features of ZFS and this also feels wrong.

You can 'zfs send' to a (special kind of) rsync.net account. We support encrypted zfs[1][2][3] and raw-send, etc. The pricing is the same but there is a 1TB minimum because we need to give you your own VM (bhyve) and we have to burn an ipv4 address for you, etc. [1] https://www.rsync.net/products/zfs.html [2] https://arstechnica.com/information-technology/2015/12/rsync... [3] https://www.servethehome.com/automating-p…

could you allocate the VM on demand? xinetd style

(you could route the ssh traffic similarly based on login)

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#93
post #57

Earlier quoted context omitted.

Fair criticisms. We're still waiting for the fabled "year of the linux desktop". Although, I feel the specific issues you raise are less of a problem on a desktop-focused distro like Ubuntu or Linux Mint. Those distros really focus on a complete desktop experience, and really try to never require a user to drop into a shell to get anything done. So, perhaps it's a case of people using the "wrong" distro for their nee…

I'm afraid the issues I describe have been with Ubuntu. Here's the first line from my "linux sins" file as an example: https://askubuntu.com/questions/1151283/disable-nautilus-cac... If you copy a large file to a USB drive on either Ubuntu or Mint the progress bar goes to 100% instantly and closes and the actual transfer of the file is done in the background without the knowledge of the user. And the answer is "It's…

Fair enough, but I'd just like to point out that specific issue you linked to happens on Windows too (and almost certainly MacOS as well).

It's just how device writes work, and is why Windows users have been told for years to select their device -> Eject instead of just yanking the USB drive out when Windows says 100%.

So, not exactly a fair criticism in my opinion, but your overall point stands - Linux can be rough around the edges for some use cases.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#94
post #79

Earlier quoted context omitted.

I would love to use this simple setup as well. It's too bad ZFS snapshots cannot be sent and stored encrypted. I would love to use rsync.net but the idea to have my data sitting in someone else's computer in plain text feels wrong. So instead I have to use restic, which re-implements many features of ZFS and this also feels wrong.

You can 'zfs send' to a (special kind of) rsync.net account. We support encrypted zfs[1][2][3] and raw-send, etc. The pricing is the same but there is a 1TB minimum because we need to give you your own VM (bhyve) and we have to burn an ipv4 address for you, etc. [1] https://www.rsync.net/products/zfs.html [2] https://arstechnica.com/information-technology/2015/12/rsync... [3] https://www.servethehome.com/automating-p…

Is this VM like a DigitalOcean or Linode VM with storage attached and the customer is fully responsible for it or is this VM managed by rsync.net like the normal storage accounts?

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#95
post #53
post #48

I wonder if they have any sales to large enterprises or similar institutions. In my experience, the larger organizations will have a "security" questionnaire required of their vendors, and the person administering it is a droid, incapable of evaluating whether the questions, originally written in the mid-00s and only updated for buzzword compliance since, are applicable to modern security practice today, or to the pa…

"I wonder if they have any sales to large enterprises or similar institutions." Yes, certainly. We frequently fill out very detailed checklists and questionnaires related to our quality policy, standards, internal policies, etc. We're also very honest about how we approach these issues: https://www.rsync.net/resources/regulatory/pci.html ... and they generally appreciate the honesty.

This is extremely honest and transparent. In addition to being good marketing, it probably attracts customers who won’t make BS support requests.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#96
This was a pleasure to read. I've been an rsync.net customer for ~6 months now, and am using Borg to send de-duped, encrypted backups to rsync.net from a few on-premise linux systems. As compared to other similar backup systems I've used, it's been a pure pleasure to implement and maintain.

Thank you for your great product and support, John!

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#97
post #48

I wonder if they have any sales to large enterprises or similar institutions. In my experience, the larger organizations will have a "security" questionnaire required of their vendors, and the person administering it is a droid, incapable of evaluating whether the questions, originally written in the mid-00s and only updated for buzzword compliance since, are applicable to modern security practice today, or to the pa…

I used to (late 2000s) work for a tiny, tiny company that was courting a customer in the mobile banking space. They wanted us to tick boxes. So we bought a box (some sort of Fortinet) that said it was a firewall and IDS. Plugged it in, used it as our new router. "Cost of doing business." Could we have argued with them during the sales process? Only if we wanted to lose the sale. The Fortinet was cheap compared to the…

Cost of doing business, or ... introducing new Fortinet vulnerabilities into your infrastructure?

I know you mentioned 2000s, but it's funny that these contractually obligated boxes might introduce more worry: https://www.bleepingcomputer.com/news/security/fortinet-fixe...

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#98
I always liked this set of marketing materials. But I also see where they conflict with my experience. "You may visit our datacenters any time you like for a personal tour and inspection to satis[f]y whatever due diligence requirements you may have" probably appeals to many customers, but for my dollar I would prefer a datacenter that nobody may enter.

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#99
I don't care for newsletters on tooling, but these Q&A interview posts are good -- immediately went in search of a twitter, couldn't find due to difficult naming, but want to follow to keep up from time to time

https://twitter.com/consoledotdev

Re: Interview with CEO of rsync.net: “no firewalls and no routers”

#100
post #16
post #12

A simple layer 2 network topology only works in very narrow use cases (like this one). But a "dumb switch" means you also lose a lot of observability and it's very difficult to apply consistent network acls.

Agreed - we are, in a sense, "cheating" because our product is so simple that we do have one of these "very narrow use cases". The benefits are tremendous, however, and go beyond day to day operations. A dumb switch has no credentials to protect and there is almost zero attack surface. Further, if our switch dies we can immediately replace it with any other dumb switch that just happens to be lying around. If you rea…

How are you providing network level redundancy with dumb switches? My only guess is that the ISP is already doing HSRP/VRRP on the gateway and you can setup multiple NICs/switches with something like CARP and being careful not to make L2 loops.
Post reply on HN