Hacker Newsnew | past | comments | ask | show | jobs | submit | sophacles's commentslogin

You're not responding to their actual comment, you're arguing something else.

As for "someone else will do it if i don't".... (aka your argument). That's true of a lot of things, and I sleep great at night choosing not to steal from people even though I know others will choose to steal. It turns out I don't have the ability to choose their actions for them, only my own.


> "someone else will do it if i don't".... (aka your argument)

That's not the argument. It's more like "if I don't do it then I better hope somebody else will, otherwise my whole country will inevitably become subservient to a despotic regime". Basically, the question is whether strict pacifism is a tenable national policy in the real world. All of modern and ancient history up to this point seems to suggest it is not.


I think the better argument is that Europe has a credible nuclear defense, therefore they don't need conventional military. If Russia starts rolling tanks towards Berlin, drop a nuke outside their international waters and announce the next one will be on Moscow

How about if Russia starts sending troops to "protect" the ethnic Russian population in Latvia? Would the USA, UK, and/or France really threaten to nuke Moscow and start WW3 in that scenario? It's better to have a credible conventional deterrent and a range of possible responses instead of betting everything on an all-or-nothing nuclear response.

I dont think they would, but think it would work if they did

What about https://en.wikipedia.org/wiki/Occupied instead? I've found that to be rather entertaining, when the 1st season began. Though only the pilot and 1st few episodes. What came later was just so-so.

Enjoy.


Would you define Russia not nuking Ukraine as "strict pacifism"? Because every modern country and army seems to have some basic standard of ethics and morals that restrict them from waging total war even if you want to argue that's purely for diplomatic or PR reasons.

There are a whole lot of decisions that need to be made to get from "strict pacifism" to total war, so I don't know why we need to flatten this into a binary.


> Would you define Russia not nuking Ukraine as "strict pacifism"?

Nobody reasonable would. Russia started a war of choice. That's the opposite of pacifism.

Strict pacifism would be Ukraine refusing to fight after being invaded. Someone saying all war in all circumtances is evil and should not be contributed to, directly or indirectly, is sort of endorsing that view. The folks calling for nuclear disarmament, or no first use policy, are pretty far away from that.


>Nobody reasonable would. Russia started a war of choice. That's the opposite of pacifism.

Yes, that was my point. The person I replied to stated a nation taking actions off the table "will inevitably become subservient to a despotic regime". As a response, I pointed to a country that many would call "a despotic regime" who seems to operate with at least some consideration towards the ethics of war even if that is due to external pressure.


Maybe I'm slow , but how is that relevant to the point? Can you expand? Am I understand is that defense is important because sooner or later someone else may choose aggression.

You might put your life savings on the street in front of your house for a day or two without someone stealing it, but sooner or later someone unscrupulous is likely to come along based on the evidence we have


The person I replied to stated that a country refusing to develop military tech for moral reasons was destined to fall to a country that ignores morals and develops that tech. I pointed to an example of an aggressor nation that is refusing to use all the military tech at its disposal. Modern society has decided that ethics don't go completely out the window in war and by and large nation states at least pretend they agree.

I got that far. Does the 2nd point contradict the first (setting aside the question of if other deterrents are at play in Russia?)

I'll be as straightforward as possible. Ukraine does not have a nuclear deterrent and yet Russia is deterred from using nuclear weapons ergo Ukraine didn't need its own nuclear weapons as a deterrent to prevent Russia from using nuclear weapons. And when even the "despotic regimes" like Russia are refusing to use a weapon, it no longer becomes a credible threat for the ostensibly good guys to threaten to use.

Weapons can only act as a deterrent if your opponent believes you're willing to use them and there are some weapons that no one is willing to use. And if no one is willing to use them, it's probably a waste to develop them in the first place.


> Ukraine does not have a nuclear deterrent and yet Russia is deterred from using nuclear weapons

Ukraine giving up its Soviet nukes in the 1990s was, with the benefit of hindsight, a mistake that has cost over a hundred thousand Ukrainians their lives. Even if Ukraine just had the missiles in a basement, the possibility that it had cracked the control system–or shortened the runway to reprocessing the warheads for a domestic platform–would have likely deterred war.


How is that an argument that demilitarized pacifism is a tenable national policy. This was the point you started arguing against. Russia hasent nuked Ukraine so nobody needs defenses or arms?

>How is that an argument that demilitarized pacifism is a tenable national policy.

I never made that argument. My original comment was refuting the idea that taking a singular option off the table is equivalent to pacifism. Ukraine didn't feel the need to develop a nuclear program, that doesn't make them pacifists.


That explains the confusion. I dont think anyone in the chain made that equivalency.

Russia not nuking Ukraine had nothing to do with ethics or morals. It's more pragmatic than that. Putin wants to take Ukraine largely intact to control its population and resources, not turn it into an irradiated wasteland. And he knows that use of WMDs would invite economic sanctions from key neutral trading partners such as India.

Also, it's questionable whether Russia's nuclear arsenal would even work reliably. The USA and other nuclear powers spend enormous amounts every year just on nuclear weapons maintenance and testing. Those munitions can't just be stored in a warehouse indefinitely like rifle cartridges and pulled out when needed; they require periodic remanufacturing in order to remain operational at all. Russia is a relatively poor and highly corrupt country so I suspect many of their nukes wouldn't deliver the rated yield if used today. From their perspective an attempted strike resulting in a fizzle would be even worse: all of the diplomatic disadvantages for no military gain.


> Putin wants to take Ukraine largely intact to control its population and resources, not turn it into an irradiated wasteland

Nuking Kyiv, Odessa and Lviv would probably force Ukraine to surrender.

> use of WMDs would invite economic sanctions from key neutral trading partners such as India

This is the real constraint. There is still the credible threat of being economically isolated by America, Europe, China and India. (Neither China nor India wants the normalisation of nuclear bombardment normalised. They both have border disputes with nuclear-armed neighbours.)


>Nuking Kyiv and Lviv would probably force Ukraine to surrender.

Or if we want to take nuclear options off the table because Russia values infrastructure, they aren't attacking population centers with bioweapons.

>This is the real constraint. There is still the credible threat of being economically isolated by America, Europe, China and India. (Neither China nor India wants the normalisation of nuclear bombardment normalised. They both have border disputes with nuclear-armed neighbours.)

Ethics enforced by external pressure are still ethics in action. The comment I replied to was basically arguing that we have to do this unethical thing because if we don't our enemies will. Well here is an example of our ostensibly unethical enemy not doing something because of ethical pressure. So why would this pressure work for nuclear weapons and not this new military tech?


> if we want to take nuclear options off the table because Russia values infrastructure

Putin doesn't care about infrastructure in Kyiv. He wants the natural gas and resources in the east. A nuked rump Ukraine isn't a threat to his power.

> why would this pressure work for nuclear weapons and not this new military tech?

Because the normalisation of nuclear weapons has global consequences in a way conventional warfare does not. The most problematic aspects of Trump's Iran war for India and China are that it raises oil prices.


>Because the normalisation of nuclear weapons has global consequences in a way conventional warfare does not.

And you don't think that has any chance of applying to some hypothetical yet to be developed future military tech?


Economic embargoes are the least of Putin’s worries if he nukes a country.

More than likely Russia is ostracized to the point that other countries will treat it with active hostility.

And the most likely possibility is Putin is assassinated and the government overthrown due to internal opposition.

The same thing that would happen to America if Trump acts on his musings about tactically nuking Iran.


Seems to me flock didn't prevent either kidnapping.

We care about the immigrants becaus we know the rest of the fucking poem.

I too base my political beliefs on poetry

You do realize that humans use art to communicate difficult or emotional ideas including political beliefs, right?

It makes me feel so much better than someone can be one-shotted into a political belief with a poem. I was worried they would rely too much on reasoning and evidence.

The poem in question conveys not just accurate history, but also it presents an argument in favor of standing for your neighbors . Even more, it conveys the feeling of loneliness when it comes to be your turn - both another argument for community and just a reminder that actual real humans are involves.

Not bad for a few lines of text... very efficient.

Of course your whole statement is ridiculous - the notion that a poem is the foundation of a belief rather than a good conveyance of it, is so stupid that all you are saying is that you can't come up with a good argument and are reaching for bad, unfunny snark to deflect.


I'm sure you do. The poem can be taken both as a lesson in why one should defend all humans, as well as a lesson in exclusion from the bottom up.

Good comparison. One is a multi-year claim by people who have been given ample opportunity to provide proof and completely refuse to do, even in courts of law. The other is a potential development in a breaking story.

Oh wait... its not a good comparrison, its an incredibly obvious false equivalence.

Note for the fools: I'm only commenting on the bad faith claim in the comment I'm replying to, not taking a stance on the validity of theft claims. Given the players involved the truth probably some nuanced middle-ground that is worth paying attention to anyway.


Trump claimed they stole the election immediately, and people agreed with him immediately. There's no false equivalence here. He did the same thing in this past election even despite winning.

It's a perfect example of people wanting to believe what they want to believe and ignoring evidence in order to do so.

Currently, there's no evidence. So saying it was stolen has no basis other than typical academic posturing and being a bad sport about "losing the race to the solution". Its happened 1000000 times before in academia and it will continue to happen.

If there's proof of OpenAI malfeasance than I'll happily curse them for it at that time. But until then I won't rely on heresay and vibes.


Most of them seem like a pretty common kitchen garden to me.

And all of the plants are native to that area, or close enough that people who had been farming for a few thousand years at that point would have brought them from neighboring lands to use.


It's also worth noting that the idea of Antifa as any sort of organization is 100% shitty fiction.

It's a fucking hashtag (and the spiritual predecessors of hastags like email label, etc for the years prior). Anyone organizing or "promoting" an event (demonstration, protest, whatever) would label it antifa if they felt that the people who were strongly opposed to fascism would find it worthwhile to support the cause.

Yes there are people out there who primarily focused on supporting anything that opposed fascism, and weirdly some of them know each other. (Strange things happen when people congregate, some of them talk to each other and even form friendships... shocking I know).

The idea that its anything other than people in a scene knowing each other is just as dumb as people saying OSS is a terrorist organization because Anonymous released loic under a public domain license.


Yes, and Isis is a bunch of independent cells held together by an ideology too.

Is Life, Liberty, and the pursuit of Happiness a bunch of independent cells held together by an ideology... or is it just an ideology?

I guess it depends on how you define ideology, but I suppose I mean a more killing-based belief. "Rich Jews are to blame for all of Germany's problems" or "Death to the West" or "From the river to the sea" are statements with murder as the goal, as is "Everyone I disagree with is a Nazi and also it's fine to kill a Nazi".

So is Christianity and the GOP. What's your point?

The GOP isn't a bunch of independent cells. It's a single organisation with a strong hierarchy. Like the Democrats. Or most Western political parties.

Antifacist, styled "antifa," and Republican are adjectives like Christian. Christianity and the GOP are massive, documented networks with representatives and hierarchies.

So without a hierarchy, things scare you to the point of declaring them terroists?

So why aren't you screaming about the horrors of OSS and family parties?

(BTW Christianity does not have a hierachy, not a universal one anyway, some groups do of course, like the Catholics... but the baptists, various orthodoxies, and many many more groups don't recognize that hierarchy).


Imagine you're an engineer at cloudflare, an 8 year old (at the time of launch of 1.1.1.1) company. The company is wildly popular and any service launched is going to have a lot of traffic and a lot of attacks right away. Any problems with it are going to embarass the company a lot.

You're tasked with making a DNS caching recursive resolver that can operate at a large scale and will be run on thousands of servers each of which has a lot of GBs of ram.

You are given some period of time to build this and make it production ready. How do you spend your time:

* Focusing on making sure that the resolver works correctly?

* Focusing on make sure that it actually provides improved DNS performance for internet users?

* Handles an very large number of record requests/s?

* Saves a few GB of ram per server?

There are tradeoffs to consider. RAM is cheap, even at today's prices RAM is not the most expensive thing that can go wrong in such a scenario. Having the responses be slow or incorrect is a far more expensive problem. A good engineer would pick a simple data structure that has the right shape but might not be optimal in footprint to focus on correctness and response time. The few extra GBs of RAM per server can be dealt with later.

When building things at scale you want to make sure it works correctly, fails correctly, and does the thing quickly before worrying about reducing resource consumption. I've never seen a project fail on Vec<T> vs Box<[T]> memory differeneces, or even on a few GBs of RAM usage per instance. I have seen them fail on "one wierd corner case of correctness" though, and on poorly thought through failure modes.


> The company is wildly popular and any service launched is going to have a lot of traffic and a lot of attacks right away.

Doesn't this also inform you that your cache will be very large, so you shouldn't use growable structures with slack space when cache entries won't grow; slop space reduces the size of your cache. And also that the query volume will be high so the cached data should require as little work as possible before returning data; spending time marshalling response data on every cache hit increases response time and decreases capacity.


RAM is cheap. I'd find myself far far more concerned with:

* unbounded growth of the cache and properly invalidating after TTL expires (a few GBs of slop is nothing on a server with 64 or more GBs of ram, unbounded growth is a problem).

* making sure the DNS implementation works correctly on both the serving side and recursive resolution side.

* What strategy is best for deduping recursive requests across machines (if something a few miliseconds away has a live result, why do a full lookup taking hundreds or thousands of milliseconds?). This potentially improves RAM usage across the datacenter too from not having a given record on dozens (or more) machines' local cache. I don't know exactly how they do it, but naively I'd look at some sort of DHT shaped solution to look for records in peers within the datacenter. Or maybe some sort of tiered caching with the upper tier being sharded on domain name or the like.

* The biggest performance gains cloudflare can provide in Web and DNS cache come from a cache hit. This is on the order of 10s or 100s of ms due to having a big cache and short distance to the requesting machine. A suboptimal lookup algorithm that is a few microseconds slower in local compute and ram access is just not as important as the other concerns for dedup and cache sharing. That's not to say it's unimportant, just that it's not the top priority when you're trying to deliver this much larger performance gains from other aspects of the system. Thats why they are getting to it several years after release.

Cloudflare writes a lot about distributed systems solutions to various problems. They likely don't think as hard about single machine performance as much as whole datacenter performance when approaching problems.

Keep in mind that the per-server cost of the whole program pre-optimization seems to be about 10GB (from the graph in the post). IME that's not bad for a big busy caching service.


> The biggest performance gains cloudflare can provide in Web and DNS cache come from a cache hit.

Using twice as much ram per cache entry makes the cache half as large, assuming your cache is bounded by ram, unless the queried, unexpired result set is less than the ram budget (which I would tend to doubt... lots of randomized queries out there; maybe I'm wrong if the cache size dropped).

When you're storing billions of records, it makes sense to spend a few minutes to consider how they're used and make a good choice about how to store them.

When you're getting a cache hit tons of times per second, it makes sense to consider every step and which ones don't need to happen every time. You have to consider every step while you're pursing correctness anyway, so might as well have the performance lens active too.

I'm not asking for heroic optimization: I didn't ask for vectorized stuff or kernel/nic offloading or kernel bypass networking... Just you have to use some data structures, you might as well not use ones that are expensive for features you don't need; and you have to store something in your cache, you may as well store something that requires less munging on the way out.

If this were a small local cache, that didn't want to use something already existing like unbound for some reason then yeah, data structures don't make a huge difference, extra marshalling doesn't make a huge difference, just don't reimplement all the CVEs that BIND had in the 90s. But if you're going to allocate 100 TB of ram, make it count. Even if you do use twice the ram but you get value from it, maybe that's fine... I've run wacky systems with bloated storage when there was a benefit. Vec doesn't give any value over a Box<[]> in this case; convenience or lazyness would be fine except that the sheer number of objects makes it worth the few minutes it takes to do something better.


> Using twice as much ram per cache entry makes the cache half as large, assuming your cache is bounded by ram, unless the queried, unexpired result set is less than the ram budget (which I would tend to doubt... lots of randomized queries out there; maybe I'm wrong if the cache size dropped).

This is true. I'm arguing that its unlikely this was ever bound by available RAM. Cloudflare is a DDoS protection company that absorbs attacks. They have a lot of available capacity at any moment. When you're building a service in a sitaution where you have more capacity than you'll likely need.

The savings were 100 TB across >300 data centers. The savings were on the order of 50%. So prior to this reduction the service was using something less than 2/3 of TB per datacenter. The service ram usage was about 10GB per instance according to the graph in post. IDK how cloudflare divides thier stuff between machines, but assuming they don't run less than 64 GB per server that's less than 12 servers per datacenter of ram for a flagship product, and they likely run it spread across 65 of the machines in the datacenter that are also doing other stuff. The per-instance RAM likely isn't the the concerning limit.

Overall RAM usage is proabably a bigger concern. Thats why I would think about dedup between instances and distributed caching strategy first. I could focus on redudcing the ram needed per service instance and get a 50% reduction per machine. Or I could focus on deduping 1/n (where n > 2) reduction in total memory usage across all instances. Personally if I was worried about reducing RAM I'd put more energy into growing N.

However all this is a red herring. The assumption people are making is that the cache was always read-only, and it's obvious that Box<[T]> was the best decision because in a RO cache smaller entries hold more things.

The 1.1.1.1 service advertises improved DNS performace. That's its value add. The biggest performance gain you can have from a cache is not having a cache miss, and in DNS a cache miss means a very expensive recursive lookup. So there's concerns about how to minimize those lookups. If one instance has does a lookup, it makes sense to share that result to the other instances that may need to do a lookup [1]. I don't know off the top of my head if it makes sense to get those updates and modify the existing record or just replace it in the local cache. That comes down to locking strategies and reading patterns in the specific code and service traffic patterns. Until i have hard evidence one way or another I'd like my cache to be able to do both and keep the data structs modifiable until that's nailed down. If per-isntance ram ever becomes the issue, there's easy wins there to buy me time to find better large scale solutions to the problem.

No one is disagreeing that the larger datastructures are larger. No one is disagreeing that they take more RAM, and or even if RAM was the the problem reducing it would be good.

The thing people are pointing out is that this isn't a homework problem about an optimal cache structure in a vacuum. We're pointing our that engineering real large scale solutions has a lot more to consider than a homework problem, and that the thing you're harping about likely didn't have any real budgetary or noticable performance impact on bulding that system. The reduction in ram is just a smallish improvement in operating costs after all the more expensive stuff was figured out.

Put another way 100TB of RAM is ~$350K. Thats one engineer year for a mid-level engineer.[2] Would you rather spend that money to save an equivalent amount of money somewhere, or... would you spend that money putting the engineer on something that saved $700K elsewhere (alternately that generated $700K)?

[1] I talked a lot about dedup and the simple gotcha is "hahah then its not deduped so you need smaller objects". But on a service that is running on a few dozen instances having a few redundant copies to deal with loss of a machine and/or load can still result in 1/(n>2) savings in total ram.

[2] I'm not saying someone worked on this for a year btw, a couple people likely spent a couple months on the code, validation and testing of it. A manager spent time overseeing it. Operations people spent time understaning any effects it had on running systems. Costs add up and it wouldn't suprise me if this didn't end up being roughly break-even for the year.


Cloudflare talks about having datacenters in 300+ cities. Presumably they have at least a few servers per datacenter. They saved 130 servers worth of memory... not even the minimum number of servers they have (seriously though, they probably have a LOT of servers)... a few GBs of memory per server running the service. At that scale this is a nice-to-have.


I'd reckon that even in this modern age there are on the order of 10^9 people who don't know what a syslog server is.


If you're buying second hadn books by the lot, you'll get a lot of duplicates and its eaiser to scan wholesale and dedupe in the computers than it is to try to run a sorting operataion on "things".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: