… we’ve determined the appropriate path forward is to not pay the ransom.
As part of Grafana Labs’ standard security practices, we will share additional information from our post-incident review when our investigations are complete. (6/6)
I strongly believe there are entire companies right now under heavy AI psychosis and its impossible to have rational conversations about it with them. I can't name any specific people because they include personal friends I deeply respect, but I worry about how this plays out.
I lived through the great MTBF vs MTTR (mean-time-between-failure vs. mean-time-to-recovery) reckoning of infrastructure during the transition to cloud and cloud automation. All those arguments are rearing their ugly heads again but now its... the whole software development industry (maybe the whole world, really).
It's frightening, because the psychosis folks operate under an almost absolute "MTTR is all you need" mentality: "its fine to ship bugs because the agents will fix them so quickly and at a scale humans can't do!" We learned in infrastructure that MTTR is great but you can't yeet resilient systems entirely.
The main issue is I don't even know how to bring this up to people I know personally, because bringing this topic up leads to immediately dismissals like "no no, it has full test coverage" or "bug reports are going down" or something, which just don't paint the whole picture.
We already learned this lesson once in infrastructure: you can automate yourself into a very resilient catastrophe machine. Systems can appear healthy by local metrics while globally becoming incomprehensible. Bug reports can go down while latent risk explodes. Test coverage can rise while semantic understanding falls. Changes happens so fast that nobody notices the underlying architecture decaying.
I worry.
Cloudflare just autonomously blocked hyper-volumetric DDoS attacks twice as large as anything seen on the Internet before — peaking at 22.2 Tbps & 10.6 Bpps. Can your mitigation provider’s scrubbing capacity handle that scale?
billionaire tech bros dont seem to understand people just want to read some anonymous outback line cook posting shit like “she grunk on my grink” interspersed with breaking news
We recently thwarted a massive UDP Flood attack from 8-9K IPs targeting ~50 IP addresses of a Magic Transit customer. This was part of a larger campaign we covered in our Q3 2024 report. Check out the full details here: https://t.co/OR8lXdyEFP #DDoS
It turns out music, movies, entertainment, and society in general peaked during the exact time period when you, the person reading this, were a teenager.
We’ve helped discover a new zero-day vulnerability–dubbed HTTP/2 Rapid Reset–that generated a DDoS attack 3X the size we’ve ever seen before. On our blog, we’re sharing a full technical deep dive on what you need to know. https://t.co/LaV1YCjuy4
While exponential growth in DDoS volumes is expected, this is a rare outlier event that sits well above the trend-line. Even the largest providers must efficiently handle malicious traffic to absorb these 0-day events without impact. 3/3
I got Apple's visionOS Simulator streaming wirelessly to a Meta Quest using ALVR.
Download: https://t.co/bKYpz1tIaz
Demo of using the visionOS Simulator inside VR:
Lemme break down the jargon wars in #webassembly system calls
WASI was chartered as a POSIX team. It leveraged prior art from CloudABI and made wasi preview 1. This is used by most language compilers today, who call this abi "wasi" or "wasip1" ...
📣 REDDIT TURMOIL CONTINUES:
24 Hours after the blackout was supposed to end, 4974 subreddits are still dark. This includes r/funny, r/science, and r/music.
Here's why over 40% of Reddit is still dark: