nickwitha_k (he/him)

  • 0 Posts
  • 18 Comments
Joined 2 years ago
cake
Cake day: July 16th, 2023

help-circle








  • I maintained a CEPH cluster a few years back. I can verify that speeds under 10GbE will cause a lot of weird issues. Ideally, you’ll even want a dedicated 10GbE purely for CEPH to do its automatic maintenance stuff and not impact storage clients.

    The PGs is a separate issue. Each PG is like a disk partition. There’s some funky math and guidelines to calculate the ideal number for each pool, based upon disks, OSDs, capacity, replicas, etc. Basically, more PGs means that there are more (but smaller) places for CEPH to store data. This means that balancing over a larger number of nodes and drives is easier. It also means that there’s more metadata to track. So, really, it’s a bit of a balancing act.










  • By acting as a man-in-the-middle with the ability to read unencrypted message data (absolutely required in order to try to match against known CSAM), this is absolutely providing a backdoor as well as undermining privacy and security. By needing to trust another party, there is now a greater threat surface which is outside of end user control. One compromised account with access to that third-party is all it would take to extract private details from any messages, undetected, whether for sale on there blackmarket or for suppressing political dissidents, that’s exactly where this would go and we know this because state actors have been caught doing it and getting their toolkits leaked to criminals.

    This kind of law doesn’t make children or regular people any safer.