TechSNAP

TechSNAP

By Jupiter BroadcastingNewsTech News
Download on the App Store

TechSNAP episodes

  • 410: Epyc Encryption

    It's CPU release season and we get excited about AMD's new line of server chips. Plus our take on AMD's approach to memory encryption, and our struggle to make sense of Intel's Comet Lake line.

    Also, a few Windows worms you should know about, the end of the road for EV certs, and an embarrassing new Bluetooth attack.

    Links:

    • A detailed look at AMD’s new Epyc “Rome” 7nm server CPUs | Ars Technica
    — The short version of the story is, Epyc "Rome" is to the server what Ryzen 3000 was to the desktop—bringing significantly improved IPC, more cores, and better thermal efficiency than either its current-generation Intel equivalents or its first-generation Epyc predecessors.
  • AMD Rome Second Generation EPYC Review: 2x 64-core Benchmarked
  • — Ever since the Opteron days, AMD's market share has been rounded to zero percent, and with its first generation of EPYC processors using its new Zen microarchitecture, that number skipped up a small handful of points, but everyone has been waiting with bated breath for the second swing at the ball. AMD's Rome platform solves the concerns that first gen Naples had, plus this CPU family is designed to do many things: a new CPU microarchitecture on 7nm, offer up to 64 cores, offer 128 lanes of PCIe 4.0, offer 8 memory channels, and offer a unified memory architecture based on chiplets.
  • AMD EPYC Rome Still Conquering Cascadelake Even Without Mitigations - Phoronix
  • — Out of curiosity, I've run some unmitigated benchmarks for the various relevant CPU speculative execution vulnerabilities on both the Intel Xeon Platinum 8280 Cascadelake and AMD EPYC 7742 Rome processors for seeing how the performance differs.
  • Intel’s line of notebook CPUs gets more confusing with 14nm Comet Lake | Ars Technica
  • — Going by Intel's numbers, Comet Lake looks like a competent upgrade to its predecessor Whiskey Lake. The interesting question—and one largely left unanswered by Intel—is why the company has decided to launch a new line of 14nm notebook CPUs less than a month after launching Ice Lake, its first 10nm notebook CPUs.
  • A look at the Windows 10 exploit Google Zero disclosed this week | Ars Technica
  • — On Tuesday, Tavis Ormandy of Google's Project Zero released an exploit kit called ctftool, which uses and abuses Microsoft's Text Services Framework in ways that can effectively get anyone root—er, system that is—on any unpatched Windows 10 system they're able to log in to
  • Patch new wormable vulnerabilities in Remote Desktop Services (CVE-2019-1181/1182) – Microsoft Security Response Center
  • — Today Microsoft released a set of fixes for Remote Desktop Services that include two critical Remote Code Execution (RCE) vulnerabilities, CVE-2019-1181 and CVE-2019-1182. Like the previously-fixed ‘BlueKeep’ vulnerability (CVE-2019-0708), these two vulnerabilities are also ‘wormable’, meaning that any future malware that exploits these could propagate from vulnerable computer to vulnerable computer without user interaction.
  • KNOB Attack
  • — TL;DR: The specification of Bluetooth includes an encryption key negotiation protocol that allows to negotiate encryption keys with 1 Byte of entropy without protecting the integrity of the negotiation process. A remote attacker can manipulate the entropy negotiation to let any standard compliant Bluetooth device negotiate encryption keys with 1 byte of entropy and then brute force the low entropy keys in real time.
  • Troy Hunt: Extended Validation Certificates are (Really, Really) Dead
  • — With both browsers auto-updating for most people, we're about 10 weeks out from no more EV and the vast majority of web users no longer seeing something they didn't even know was there to begin with! Oh sure, you can still drill down into the certificate and see the entity name, but who's really going to do that? You and I, perhaps, but we're not exactly in the meat of the browser demographics.
  • Google wants to reduce lifespan for HTTPS certificates to one year | ZDNet
  • — Scott Helme argues that the security benefits of shorter SSL certificate lifespans have nothing to do with phishing or malware sites, but instead with the SSL certificate revocation process. Helme claims that this process is broken and that bad SSL certificates continue to live on for years after being mississued and revoked.
    51 min
  • 409: Privacy Perspectives

    We examine why it's so difficult to protect your privacy online and discuss browser fingerprinting, when to use a VPN, and the limits of private browsing.

    Plus Apple's blaring bluetooth beacons and Facebook's worrying plans for WhatsApp.

    Links:

    • Apple bleee. Everyone knows What Happens on Your iPhone – hexway
    — If Bluetooth is ON on your Apple device everyone nearby can understand current status of your device, get info about battery, device name, Wi-Fi status, buffer availability, OS version and even get your mobile phone number
  • Facebook Plans on Backdooring WhatsApp - Schneier on Security
  • — In Facebook's vision, the actual end-to-end encryption client itself such as WhatsApp will include embedded content moderation and blacklist filtering algorithms. These algorithms will be continually updated from a central cloud service, but will run locally on the user's device, scanning each cleartext message before it is sent and each encrypted message after it is decrypted.
  • Signal
  • — Privacy that fits in your pocket.
  • xkcd: Security
  • — Turns out it's a $5 wrench, even better!
  • Jim Salter on Twitter
  • — I wonder why #privacy wonks aren't talking about browser fingerprinting more frequently? Privacy Badger, Ghostery, etc don't do a damn thing to prevent or mitigate Canvas / WebGL #fingerprinting.
  • Browser Fingerprinting: What Is It and What Should You Do About It? - PixelPrivacy
  • — Browser fingerprinting is a powerful method that websites use to collect information about your browser type and version, as well as your operating system, active plugins, timezone, language, screen resolution and various other active settings.
  • Canvas Fingerprinting - BrowserLeaks.com
  • — The technique is based on the fact that the same canvas image may be rendered differently in different computers. This happens for several reasons. At the image format level – web browsers uses different image processing engines, image export options, compression level, the final images may got different checksum even if they are pixel-identical. At the system level – operating systems have different fonts, they use different algorithms and settings for anti-aliasing and sub-pixel rendering.
  • WebGL Browser Report - WebGL Fingerprinting - WebGL 2 Test - BrowserLeaks.com
  • — WebGL Browser Report checks WebGL support in your web browser, produce WebGL Device Fingerprinting, and shows the other WebGL and GPU capabilities more or less related web browser identity.
  • AmIUnique
  • — Device fingerprinting or browser fingerprinting is the systematic collection of information about a remote device, for identification purposes. Client-side scripting languages allow the development of procedures to collect very rich fingerprints: browser and operating system type and version, screen resolution, architecture type, lists of fonts, plugins, microphone, camera, etc.
  • Panopticlick
  • — Panopticlick will analyze how well your browser and add-ons protect you against online tracking techniques. We’ll also see if your system is uniquely configured—and thus identifiable—even if you are using privacy-protective software. However, we only do so with your explicit consent, through the TEST ME button below.
  • How private is your browser’s Private mode? Research into porn suggests “not very” | Ars Technica
  • — This leaves browser fingerprinting as a method to tie your profiles together—and unfortunately, Incognito mode doesn't appear to help.
  • Privacy Tools - Encryption Against Global Mass Surveillance
  • — You are being watched. Private and state-sponsored organizations are monitoring and recording your online activities. privacytools.io provides services, tools and knowledge to protect your privacy against global mass surveillance.
  • ‘Fingerprinting’ to Track Us Online Is on the Rise. Here’s What to Do. - The New York Times
  • — Fingerprinting involves looking at the many characteristics of your mobile device or computer, like the screen resolution, operating system and model, and triangulating this information to pinpoint and follow you as you browse the web and use apps. Once enough device characteristics are known, the theory goes, the data can be assembled into a profile that helps identify you the way a fingerprint would.
  • Digital 'Fingerprinting' Is The Next Generation Tracking Technology | The Takeaway | WNYC Studios
  • — This growing technology is almost invisible, making it impossible for users to opt-out of the tracking system. As it becomes more popular, tech companies are developing new ways to try and protect consumers from this form of tracking. But is it going to work?
  • New Warning Issued Over Google's Chrome Ad-Blocking Plans
  • — The plans, dubbed Manifest V3, represent a major transformation to Chrome extensions including a revamp of the permissions system. As a result, modern ad blockers such as uBlock Origin—which uses Chrome’s webRequest API to block ads before they’re downloaded–won’t work.
  • Comment on Chrome extension manifest v3 proposal by gorhill
  • — The blocking ability of the webRequest API is still deprecated, and Google Chrome's limited matching algorithm will be the only one possible, and with limits dictated by Google employees.
    It's annoying that they keep saying "the webRequest API is not deprecated" as if developers have been worried about this -- and as if they want to drown the real issue in a fabricated one nobody made.
  • CanvasBlocker
  • Ghostery
  • Disconnect
  • 40 min
  • 408: Apollo's ARC

    We take a look at the amazing abilities of the Apollo Guidance Computer and Jim breaks down everything you need to know about the ZFS ARC.

    Plus an update on ZoL SIMD acceleration, your feedback, and an interesting new neuromorphic system from Intel.

    Links:

    • ZFS On Linux Has Figured Out A Way To Restore SIMD Support On Linux 5.0+
    — Those running ZFS On Linux (ZoL) on post-5.0 (and pre-5.0 supported LTS releases) have seen big performance hits to the ZFS encryption performance in particular. That came due to upstream breaking an interface used by ZFS On Linux and admittedly not caring about ZoL due to it being an out-of-tree user. But now several kernel releases later, a workaround has been devised.
  • ZFS On Linux Runs Into A Snag With Linux 5.0
  • NixOS Takes Action After 1.2GB/s ZFS Encryption Speed Drops To 200MB/s With Linux 5.0+
  • — A NixOS developer reports that the functions no longer exported by Linux 5.0+ and previously used by ZoL for AVX/AES-NI support end up dropping the ZFS data-set encryption performance to 200MB/s where as pre-5.0 kernels ran around 1.2GB/s
  • Linux 5.0 compat: SIMD compatibility · zfsonlinux/zfs@e5db313
  • — Restore the SIMD optimization for 4.19.38 LTS, 4.14.120 LTS,
    and 5.0 and newer kernels. This is accomplished by leveraging
    the fact that by definition dedicated kernel threads never need
    to concern themselves with saving and restoring the user FPU state.
    Therefore, they may use the FPU as long as we can guarantee user
    tasks always restore their FPU state before context switching back
    to user space.
  • no SIMD acceleration · Issue #8793 · zfsonlinux/zfs
  • — 4.14.x, 4.19.x, 5.x all have no SIMD acceleration, it is like a turtle. very slow.
  • Chris's Wiki :: ZFS on Linux still has annoying issues with ARC size
  • — One of the frustrating things about operating ZFS on Linux is that the ARC size is critical but ZFS's auto-tuning of it is opaque and apparently prone to malfunctions, where your ARC will mysteriously shrink drastically and then stick there.
  • Software woven into wire, Core rope and the Apollo Guidance Computer
  • — One of the first computers to use integrated circuits, the Apollo Guidance Computer was lightweight enough and small enough to fly in space. An unusual feature that contributed to its small size was core rope memory, a technique of physically weaving software into high-density storage.
  • Virtual Apollo Guidance Computer (AGC) software
  • — Since you are looking at this README file, you are in the "master" branch of the repository, which contains source-code transcriptions of the original Project Apollo software for the Apollo Guidance Computer (AGC) and Abort Guidance System (AGS), as well as our software for emulating the AGC, AGS, and some of their peripheral devices (such as the display-keyboard unit, or DSKY).
  • The Underappreciated Power of the Apollo Computer - The Atlantic
  • — Without the computers on board the Apollo spacecraft, there would have been no moon landing, no triumphant first step, no high-water mark for human space travel. A pilot could never have navigated the way to the moon, as if a spaceship were simply a more powerful airplane. The calculations required to make in-flight adjustments and the complexity of the thrust controls outstripped human capacities.
  • Brains scale better than CPUs. So Intel is building brains | Ars Technica
  • — Neuromorphic engineering—building machines that mimic the function of organic brains in hardware as well as software—is becoming more and more prominent. The field has progressed rapidly, from conceptual beginnings in the late 1980s to experimental field programmable neural arrays in 2006, early memristor-powered device proposals in 2012, IBM's TrueNorth NPU in 2014, and Intel's Loihi neuromorphic processor in 2017. Yesterday, Intel broke a little more new ground with the debut of a larger-scale neuromorphic system, Pohoiki Beach, which integrates 64 of its Loihi chips.
  • Dancing Demon - YouTube
  • — Written in 1979 by Leo Christopherson for the Radio Shack TRS-80 Model I computer. This is the best game ever for at that time.
    36 min
  • Problematic Privileges

    Wes takes a quick look at a container escape proof-of-concept and reviews Docker security best practices.

    Links:

    • Understanding Docker container escapes | Trail of Bits Blog — Linux cgroups are one of the mechanisms by which Docker isolates containers. The PoC abuses the functionality of the notify_on_release.
    • Felix Wilhelm on Twitter — Quick and dirty way to get out of a privileged k8s pod or docker container by using cgroups release_agent feature.
    8 min
  • 407: Old School Outages

    Jim shares his Nagios tips and Wes chimes in with some modern tools as we chat monitoring in the wake of some high-profile outages.

    Plus we turn our eye to hardware and get excited about the latest Ryzen line from AMD.

    Links:

    • Third parties confirm AMD’s outstanding Ryzen 3000 numbers | Ars Technica
    — AMD debuted its new Ryzen 3000 desktop CPU line a few weeks ago at E3, and it looked fantastic. For the first time in 20 years, it looked like AMD could go head to head with Intel's desktop CPU line-up across the board. The question: would independent, third-party testing back up AMD's assertions?
  • The Internet broke today: Facebook, Verizon, and more see major outages | Ars Technica
  • — Last week, Verizon caused a major BGP misroute that took large chunks of the Internet, including CDN company Cloudflare, partially down for a day. This week, the rest of the Internet has apparently asked Verizon to hold its beer.
  • It was a really bad month for the internet | TechCrunch
  • — In the past month there were several major internet outages affecting millions of users across the world. Sites buckled, services broke, images wouldn’t load, direct messages ground to a halt and calendars and email were unavailable for hours at a time.
  • Cloudflare outage caused by bad software deploy (updated)
  • — For about 30 minutes today, visitors to Cloudflare sites received 502 errors caused by a massive spike in CPU utilization on our network. This CPU spike was caused by a bad software deploy that was rolled back.
  • How Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline Today
  • — Today at 10:30UTC, the Internet had a small heart attack. A small company in Northern Pennsylvania became a preferred path of many Internet routes through Verizon (AS701), a major Internet transit provider.
  • Getting started | Prometheus
  • — This guide is a "Hello World"-style tutorial which shows how to install, configure, and use Prometheus in a simple example setup.
  • prometheus/node_exporter
  • — Prometheus exporter for hardware and OS metrics exposed by *NIX kernels, written in Go with pluggable metric collectors.
  • Using netdata with Prometheus
  • — Prometheus is a distributed monitoring system which offers a very simple setup along with a robust data model. Recently netdata added support for Prometheus.
  • prometheus/nagios_plugins
  • — Nagios plugin for alerting on prometheus query results.
  • RobustPerception/nrpe_exporter
  • — The NRPE exporter exposes metrics on commands sent to a running NRPE daemon.
  • m-lab/prometheus-nagios-exporter
  • — The Prometheus Nagios exporter reads status and performance data from nagios plugins via the MK Livestatus Nagios plugin and publishes this in a form that can be scrapped by Prometheus.
  • Comparison to alternatives | Prometheus
  • — Prometheus is a full monitoring and trending system that includes built-in and active scraping, storing, querying, graphing, and alerting based on time series data.
  • Quality server monitoring solution using NetData/Prometheus/Grafana
  • — I’m going to quickly show you how to install both netdata and Prometheus on the client and server. We can then use grafana pointed at Prometheus to obtain long-term metrics netdata offers.
  • Monitoring stack by using Grafana + Prometheus + Netdata
  • — This monitoring stack you can monitoring in real-time by Netdata and see the history by using Grafana.
  • Monitoring Agent · NCPA
  • — New to NCPA? See some of the awesome features present in the Web GUI and API, available on any operating system.
  • Nagios 101: Understanding the Fundamentals - Nagios
  • Nagios Documentation
  • 43 min
  • 406: SACK Attack

    A new vulnerability may be the next 'Ping of Death'; we explore the details of SACK Panic and break down what you need to know.

    Plus Firefox zero days targeting Coinbase, the latest update on Rowhammer, and a few more reasons it's a great time to be a ZFS user.

    Links:

    • SACK Panic Security Bulletin
    — Netflix has identified several TCP networking vulnerabilities in FreeBSD and Linux kernels. The vulnerabilities specifically relate to the Maximum Segment Size (MSS) and TCP Selective Acknowledgement (SACK) capabilities. The most serious, dubbed “SACK Panic,” allows a remotely-triggered kernel panic on recent Linux kernels.
  • Ubuntu SACK Panic Guidance
  • — You should update your kernel to the versions specified below in the Updates section and reboot. Alternatively, Canonical Livepatch updates will be available to mitigate these two issues without the need to reboot.
  • Red Hat SACK Panic Advisory
  • — Red Hat customers running affected versions of these Red Hat products are strongly recommended to update them as soon as errata are available. Customers are urged to apply the available updates immediately and enable the mitigations as they feel appropriate.   
  • RFC 2018 - TCP Selective Acknowledgment Options
  • — TCP may experience poor performance when multiple packets are lost from one window of data. With the limited information available from cumulative acknowledgments, a TCP sender can only learn about a single lost packet per round trip time. An aggressive sender could choose to retransmit packets early, but such retransmitted segments may have already been successfully received. A Selective Acknowledgment (SACK) mechanism, combined with a selective repeat retransmission policy, can help to overcome these limitations.
  • Ping of Death
  • — In a nutshell, it is possible to crash, reboot or otherwise kill a large number of systems by sending a ping of a certain size from a remote machine.
  • Firefox zero-day was used in attack against Coinbase employees, not its users | ZDNet
  • — A recent Firefox zero-day that has made headlines across the tech news world this week was actually used in attacks against Coinbase employees, and not the company's users.
  • Mozilla fixes second Firefox zero-day exploited in the wild | ZDNet
  • — Mozilla has released a second security update this week to patch a second zero-day that was being exploited in the wild to attack Coinbase employees and other cryptocurrency organizations.
  • RAMBleed
  • — RAMBleed is a side-channel attack that enables an attacker to read out physical memory belonging to other processes. The implications of violating arbitrary privilege boundaries are numerous, and vary in severity based on the other software running on the target machine. As an example, in our paper we demonstrate an attack against OpenSSH in which we use RAMBleed to leak a 2048 bit RSA key.
  • Digging into the new features in OpenZFS post-Linux migration | Ars Technica
  • — One of the most important new features in 0.8 is Native ZFS Encryption. Until now, ZFS users have relied on OS-provided encrypted filesystem layers either above or below ZFS. While this approach does work, it presented difficulties.
  • Allan Jude on Twitter
  • — Once the FreeBSDs are upstreamed, everything is changing to 'OpenZFS', including the github organization currently know as 'zfsonlinux'.
  • ZFS on Linux Releases
  • Linux Academy is hiring!
  • Mozilla teases $5-per-month ad-free news subscription
  • — Mozilla has started teasing an ad-free news subscription service, which, for $5 per month, would offer ad-free browsing, audio readouts, and cross-platform syncing of news articles from a number of websites.
    44 min
  • 405: Update Uncertainty

    We explore the risky world of exposed RDP, from the brute force GoldBrute botnet to the dangerously worm-able BlueKeep vulnerability.

    Plus the importance of automatic updates, and Jim's new backup box.

    Links:

    • Errata Security: Almost One Million Vulnerable to BlueKeep Vuln (CVE-2019-0708)
    — Microsoft announced a vulnerability in it's "Remote Desktop" product that can lead to robust, wormable exploits. I scanned the Internet to assess the danger. I find nearly 1-million devices on the public Internet that are vulnerable to the bug.
  • Even the NSA is urging Windows users to patch BlueKeep (CVE-2019-0708) | ZDNet
  • — "[The] NSA is concerned that malicious cyber actors will use the vulnerability in ransomware and exploit kits containing other known exploits, increasing capabilities against other unpatched systems.
  • Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) – MSRC
  • — This vulnerability is pre-authentication and requires no user interaction. In other words, the vulnerability is ‘wormable’, meaning that any future malware that exploits this vulnerability could propagate from vulnerable computer to vulnerable computer in a similar way as the WannaCry malware spread across the globe in 2017
  • BlueKeep - everyone agrees, you should patch PCs running legacy versions of Windows
  • — I have this horrible feeling that the only way we’re going to wake the world up to the need to patch their ageing versions of Windows against the BlueKeep vulnerability is to wait until a malicious worm begins to spread around the world.
  • CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
  • — A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
  • Customer guidance for CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability
  • — Microsoft is aware that some customers are running versions of Windows that no longer receive mainstream support. That means those customers will not have received any security updates to protect their systems from CVE-2019-0708, which is a critical remote code execution vulnerability.
  • Forget BlueKeep: Beware the GoldBrute | Threatpost
  • — In the past few days, GoldBrute (named after the Java class it uses) has attempted to brute-force Remote Desktop Protocol (RDP) connections for 1.5 million Windows systems and counting, according to Morphus Labs chief research officer Renato Marinho. The botnet is actively scanning the internet for machines with RDP exposed, and trying out weak or reused passwords to see if it can gain access to the systems.
  • The GoldBrute botnet
  • — The latest round of bad news emerged last week when Morphus Labs’ researcher Renato Marinho announced the discovery of an aggressive brute force campaign against 1.5 million RDP servers by a botnet called ‘GoldBrute’.
  • Ubuntu Automatic Updates
  • — The unattended-upgrades package can be used to automatically install updated packages, and can be configured to update all packages or just install security updates.
  • AutoUpdates - Fedora Project Wiki
  • — You must decide whether to use automatic DNF or YUM updates on each of your machines.
  • It's time to block Windows Automatic Updating | Computerworld
  • — Those of you who feel it’s important to install Windows and Office patches the moment they come out – I salute you. The Windows world needs more cannon fodder.
  • Windows 10's Ugly Updates Just Got Uglier. Here's How To Stay Safe by Disabling Automatic Updates
  • — Stay safe by disabling automatic updates? How is that possible? As a general rule of thumb, I’d never recommend disabling updates because security patches are essential. But the situation with Windows 10 has become intolerable. Microsoft continues to fail and continues to release update after update that they know, or should know, has serious problems.
  • Jim's New Rig
  • — I build, sell, and manage much bigger and meaner systems than this all the time. But this one's MINE! 12 hot swap bays, Ryzen 7 2700 w/ ECC RAM, quiet enough to share an office with, and the trays can take either HDD or SSD with no adapter needed.
    31 min
  • Waiting Game

    The next episode of TechSNAP is still in the works, so Wes takes a quick look at an interesting application of public-key cryptography in Apple's Find My feature.

    Links:

    • Apple's 'Find My' Feature Uses Some Very Clever Cryptography — In upcoming versions of iOS and macOS, the new Find My feature will broadcast Bluetooth signals from Apple devices even when they're offline, allowing nearby Apple devices to relay their location to the cloud. That should help you locate your stolen laptop even when it's sleeping in a thief's bag. And it turns out that Apple's elaborate encryption scheme is also designed not only to prevent interlopers from identifying or tracking an iDevice from its Bluetooth signal, but also to keep Apple itself from learning device locations, even as it allows you to pinpoint yours.
    7 min
  • 404: Prefork Pitfalls

    We turn our eye to web server best practices, from the basics of CDNs to the importance of choosing the right multi-processing module.

    Plus the right way to setup PHP, the trouble with benchmarking, and when to choose NGiNX.

    Links:

    • Jim's Blog: Installing WordPress on Apache the modern way
    — It’s been bugging me for a while that there are no correct guides to be found about using modern Apache 2.4 or above with the Event or Worker MPMs. We’re going to go ahead and correct that lapse today, by walking through a brand-new WordPress install on a new Ubuntu 18.04 VM.
  • Apache Performance Tuning
  • — Apache 2.x is a general-purpose webserver, designed to provide a balance of flexibility, portability, and performance. Although it has not been designed specifically to set benchmark records, Apache 2.x is capable of high performance in many real-world situations.
  • Tuning Your Apache Server
  • worker - Apache HTTP Server Version 2.4
  • — This Multi-Processing Module (MPM) implements a hybrid multi-process multi-threaded server. By using threads to serve requests, it is able to serve a large number of requests with fewer system resources than a process-based server.
  • event - Apache HTTP Server Version 2.4
  • — The event Multi-Processing Module (MPM) is designed to allow more requests to be served simultaneously by passing off some processing work to the listeners threads, freeing up the worker threads to serve new requests.
  • PHP-FPM
  • — PHP-FPM (FastCGI Process Manager) is an alternative PHP FastCGI implementation with some additional features useful for sites of any size, especially busier sites.
  • FastCGI overview
  • — FastCGI is a way to have CGI scripts execute time-consuming code (like opening a database) only once, rather than every time the script is loaded. In technical terms, FastCGI is a language independent, scalable, open extension to CGI that provides high performance without the limitations of server specific APIs.
  • Alexa Top 500 Global Sites
  • What Is a CDN? How Does a CDN work?
  • — A content delivery network (CDN) refers to a geographically distributed group of servers which work together to provide fast delivery of Internet content.
  • W3 Total Cache – WordPress plugin
  • — W3 Total Cache improves the SEO and user experience of your site by increasing website performance, reducing load times via features like content delivery network (CDN) integration and the latest best practices.
  • krakjoe/apcu: APCu - APC User Cache
  • — APCu is an in-memory key-value store for PHP. Keys are of type string and values can be any PHP variables.
  • PHP: APCu - Manual
  • Introduction to Varnish — Varnish HTTP Cache
  • — Varnish Cache is a web application accelerator also known as a caching HTTP reverse proxy. You install it in front of any server that speaks HTTP and configure it to cache the contents. Varnish Cache is really, really fast. It typically speeds up delivery with a factor of 300 - 1000x, depending on your architectur
  • ab - Apache HTTP server benchmarking tool
  • — ab is a tool for benchmarking your Apache Hypertext Transfer Protocol (HTTP) server. It is designed to give you an impression of how your current Apache installation performs. This especially shows you how many requests per second your Apache installation is capable of serving.
  • HTTP(S) Benchmark Tools
  • jimsalterjrs/network-testing
  • — This is a small collection of GPLv3-licensed tools to assist an intrepid researcher in testing the performance of networks, wired or wireless.
    34 min
  • 403: Keeping Systems Simple

    We’re back from LinuxFest Northwest with an update on all things WireGuard, some VLAN myth busting, and the trade-offs of highly available systems.

    Links:

    • TechSNAP Episode 390: What’s Up with WireGuard
  • WireGuard Sent Out Again For Review
  • — WireGuard lead developer Jason Donenfeld has sent out the ninth version of the WireGuard secure network tunnel patches for review. If this review goes well and lands in net-next in the weeks ahead, this long-awaited VPN improvement could make it into the mainline Linux 5.2 kernel.
  • CloudFlare announces Warp VPN
  • — Using Cloudflare’s existing network of servers, Internet users all over the world will be able to connect to Warp VPN through the 1.1.1.1 app. In the same vein, Warp VPN will not significantly increase battery usage by using an efficient protocol called WireGuard.
  • CloudFlare Launches "BoringTun" As Rust-Written WireGuard User-Space Implementation - Phoronix
  • — CloudFlare took to creating BoringTun as they wanted a user-space solution as not to have to deal with kernel modules or satisfying certain kernel versions. They also wanted cross platform support and for their chosen implementation to be very fast, these choices which led them to writing a Rust-based solution.
  • cloudflare/boringtun
  • — BoringTun is an implementation of the WireGuard® protocol designed for portability and speed.
  • VPN protocol WireGuard now has an official macOS app
  • — You can already download the WireGuard app on Android and iOS, but today’s release is all about macOS.
  • WireGuard Windows Pre-Alpha
  • — I've been mostly absent these last weeks, due to being completely absorbed in Windows programming. I think we're finally getting to the state where we might really benefit from testing of the "pre-alpha".
  • Wintun – Layer 3 TUN Driver for Windows
  • — Wintun is a very simple and minimal TUN driver for the Windows kernel, which provides userspace programs with a simple network adapter for reading and writing packets. It is akin to Linux's /dev/net/tun and BSD's /dev/tun.
  • WireGuard for Kubernetes: Introducing Gravitational Wormhole
  • — Wormhole is a Kubernetes network plugin that combines the simplicity of flannel with encrypted networking from WireGuard.
  • gravitational/wormhole: Wireguard based overlay network CNI plugin for kubernetes
  • NetworkManager 1.16
  • — NetworkManager 1.16 is a big feature release bringing support for WireGuard VPN tunnels
  • Portal Cloud - Subspace
  • — Subspace is an open source WireGuard® VPN server that supports connecting all of your devices to help secure your internet access.
  • subspacecloud/subspace
  • — A simple WireGuard VPN server GUI
  • jimsalterjrs/wg-admin
  • — Simple CLI utilities to manage a WireGuard server
  • 5 big misconceptions about virtual LANs
  • — In the real world, VLANs are anything but simple.
  • High Availability vs. Fault Tolerance vs. Disaster Recovery
  • — You need IT infrastructure that you can count on even when you run into the rare network outage, equipment failure, or power issue. When your systems run into trouble, that’s where one or more of the three primary availability strategies will come into play: high availability, fault tolerance, and/or disaster recovery.
  • High Availability: Concepts and Theory
  • — Running server operations using clusters of either physical or virtual computers is all about improving both reliability and performance over and above what you could expect from a single, high-powered server.
  • RPO and RTO: Understanding the Differences
  • — Recovery time objective refers to how much time an application can be down without causing significant damage to the business. Recovery point objectives refer to your company’s loss tolerance: the amount of data that can be lost before significant harm to the business occurs.
  • JupiterBroadcasting/Talks
  • — Public repository of crew talks, slides, and additional resources.
  • Command Line Threat Hunting
  • — That viruses and malware are Windows problems is a misnomer that is often propagated through the Linux community and it's an easy one to believe until you start noticing strange behavior on your system. What do you do next? Join Ell Marquez and Tony Lambert in discussing a common sense approach to threat detection using only command line tools.
  • Fear the Man in the Middle? This company wants to sell quantum key distribution
  • — For now, Quantum XChange has only said about a dozen companies are part of the pilot. But with the appetite for quantum solutions in the US increasing—the National Quantum Initiative was just signed into law at the end of 2018 to advance the tech—this could be an opportune time to enter the market, so long as the service lives up to its billing.
    47 min

About TechSNAP

From the publisher's feed

Systems, Network, and Administration Podcast. Every two weeks TechSNAP covers the stories that impact those of us in the tech industry, and all of us that follow it. Every episode we dedicate a…

More shows like TechSNAP

Packet Protector by Packet Pushers

Packet Protector

7 Listeners