@tdp_org@mastodon.social
@tdp_org@mastodon.social avatar

tdp_org

@tdp_org@mastodon.social

Lead Architect @ BBC. Snowboarder, skateboarder. Oxfordshire, UK. Opinions mine. He/Him.
Interested in #serverless #nodejs #googlecloud #terraform #bigquery #analytics #web #cdn #http #tls #http2 #http3 #security #infosec #privacy #webperformance #webperf etc.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

tdp_org, to random
@tdp_org@mastodon.social avatar

Despite the very clever people working at Google & Fitbit, my Pixel Watch still marks me mowing the lawn as "Biking" every time.
I do get that the arm position will be pretty much identical but maybe they ought to consider metadata - how many people are cycling for an hour whilst in wifi range and within ~60 metres of their home location whilst moving at walking pace? 🤣

tdp_org, to random
@tdp_org@mastodon.social avatar

We're being force-migrated from Zoom to Teams (to save some Schekels) which was a bit of a wrench at first but I've found a few things which I prefer in Teams:

  • Dedicated "raise hand" vs "react" buttons on the toolbar
  • Visualised sequencing for people who raised their hand so you can go through in order
    I do always struggle to find the "mute" button for some reason (seems to be common with lots of people) and the video quality is pretty poor compared to Zoom but I can live with it.
tdp_org, to random
@tdp_org@mastodon.social avatar

If you could launch any 3 people to Mars and never see or hear from them again, who would it be?

tdp_org,
@tdp_org@mastodon.social avatar

@janl V similar to mine. I'd probably put pooptin in there too - feels like doing that might nullify tronald - 2 for 1 deal! 🍻

tdp_org, to random
@tdp_org@mastodon.social avatar

@tomatospy isn't pulling any punches (and is absolutely correct, IMO) on today's Risky Biz newsletter.

https://news.risky.biz/corporate-freeloading-makes-open-source-vulnerable/

tdp_org, to random
@tdp_org@mastodon.social avatar

🚨 **UK TV Licensing scam! **🚨

I just recieved this scam email purporting to be a TV Licensing renewal reminder. It's reasonably well done except for:

  1. The sender email address
  2. The trademark symbol - AFAIK that's never used by TVL

I believe they're using the data from the People's Energy data breach as the email address they sent this to used the unique plus alias I used on my account with PE.

The "sign in" link goes to an AWS S3 hosted file BTW.

https://www.bbc.co.uk/news/technology-55350995

#DataBreach

tdp_org,
@tdp_org@mastodon.social avatar

@markwalker Yep, and it works with more email services than you might think...just wish more websites/services would support them.

tdp_org, to random
@tdp_org@mastodon.social avatar

Every time you think they can't stoop lower...
https://www.bbc.co.uk/news/world-europe-68788110

tdp_org, to random
@tdp_org@mastodon.social avatar

Is it "no one is registering for our conferences so let's spam everyone and offer free tickets" week or something?
I must have had 5-10 every day so far.
Blocked every sender.

tdp_org,
@tdp_org@mastodon.social avatar

@tomw +1

tdp_org, to webdev
@tdp_org@mastodon.social avatar

I enabled Brotli compression on the CDN which serves the main BBC websites (www.bbc.co.uk. www.bbc.com etc.) outside the UK this morning.
Over ~4 hours, we're seeing a mean of ~20% better compression (smaller responses) via Brotli & ~95% of responses being Brotli now.
I've not had time to look in detail at performance but there doesn't look to be a significant change (LMK if you see diferent!).
(the spikes are breaking news events linking to a large "live" pages)

tdp_org,
@tdp_org@mastodon.social avatar

@slink Unfortunately I don't know any of that, sorry. This is on Fastly so it's all tied in to their platform.
I am planning on doing the same on our platform too though, once time allows. So at that point I can provide the info.

tdp_org,
@tdp_org@mastodon.social avatar

@kura @slink Not sure on Fastly but I think nginx can do that - haven't looked in a while.
There's also the client CPU to consider too of course.

tdp_org,
@tdp_org@mastodon.social avatar

A little update on our enabling of Brotli for www.bbc.co.uk, www.bbc.com etc.
We're seeing compression improvements of roughly 15-40% over gzip. 15% is for HTML only, 40% is the overall. The caveat is that some clients which don't support Brotli request unusual content so this may be skewed to some degree.
I'll cover an issue which has cropped up in the next post.

tdp_org,
@tdp_org@mastodon.social avatar

Our stack is: Fastly -> GTM (BBC CDN) -> Belfrage (BBC routing) -> origins for most of our modern web pages.
Currently, only Fastly supports Brotli, the others do gzip, deflate & no compression.
Fastly strips gzip,deflate from the accept-encoding header sent to origin so our layers all return uncompressed content which means they're using more egress bandwidth. It's not a huge problem for us but something I thought might be useful for others to know.

tdp_org, to webdev
@tdp_org@mastodon.social avatar

Somehow, we never got round to enabling Brotli compression on www.bbc.co.uk & www.bbc.com so I am just in the final throws of deploying that.
So far in ~1 hour on our staging site, I'm seeing ~24% smaller files under Brotli (vs. gzip). 🤞this (or better) also happens on live which'll be tomorrow.

tdp_org, to random
@tdp_org@mastodon.social avatar
tdp_org, to ai
@tdp_org@mastodon.social avatar

I'm going to say it now, i'd pay more for a computer without AI BS hardware and software.

tdp_org, to pizza
@tdp_org@mastodon.social avatar

Any tried add trusted (I can search for recipes, looking for genuine recommendations) recommendations for a good, authentic Italian pizza dough recipe which is realistic for me to make at home?
(We have a mixer etc)

tdp_org, to random
@tdp_org@mastodon.social avatar

BBC Websites are officially blocked in Russia & China.

China blocks via DNS (returns incorrect answers). They probably also monitor for connections outside of China (e.g. using hosts file), I assume they block foreign DNS resolution.

Russia blocks mainly via TLS SNI snooping & connection termination, done by their major ISPs.

There's a big discrepency between the volume of requests we see between the two countries. I honestly don't know why.
Odd.

icing, to random
@icing@chaos.social avatar

Obvious: keyboards should have all the keys on one side, so that we can type everything with one hand comfortably.

tdp_org,
@tdp_org@mastodon.social avatar

@icing Just rotate your keyboard 90 degrees. Problem solved 🤣

tdp_org, to infosec
@tdp_org@mastodon.social avatar

If you run a public web service, do you attempt to attribute DDOS to an attacker?
If so, how do you do it?

Interested to see what other folks/orgs do.

tdp_org, to webdev
@tdp_org@mastodon.social avatar

I made a change on our NEL/Reporting API report collector earlier which changed the response status from 500 to 403 when the client fails to send a valid/any Origin request header on the POST.

This caused a ~2x increase in reports.
(ignore the spikes, they're known)

I then changed the response from 403 to 201 and the reports returned to their previous level. No other changes were made.

Anyone know why this'd be? Would browsers retry on 403?

Edent, (edited ) to random
@Edent@mastodon.social avatar

Hello friends! I'm still testing out my personal ActivityPub server - and I need your help 🙂

If you click this link → @example

Do you see the user's account or a page of JSON code?

If you do see the code, could you please let me know which platform / app you're using?

THANKS GANG!

tdp_org,
@tdp_org@mastodon.social avatar

@Edent @example I get a "try original site" error (this is a generic issue with Elk).
If I remove "@mastodon.social" from the URL, it works.
Elk 0.11.0 on Firefox latest, Mac.

image/png

tdp_org, to random
@tdp_org@mastodon.social avatar

Dang, Terraform is persistent!
2 hours and 40 minutes to deploy a CDN change.
Thanks for sticking with it TF!

tdp_org,
@tdp_org@mastodon.social avatar

@markwalker TBH, I forgot about it after the first 20 minutes 🤣

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • everett
  • magazineikmin
  • Durango
  • thenastyranch
  • Youngstown
  • slotface
  • hgfsjryuu7
  • osvaldo12
  • rosin
  • kavyap
  • mdbf
  • PowerRangers
  • DreamBathrooms
  • modclub
  • khanakhh
  • InstantRegret
  • tacticalgear
  • vwfavf
  • ethstaker
  • ngwrru68w68
  • normalnudes
  • tester
  • GTA5RPClips
  • cubers
  • cisconetworking
  • Leos
  • provamag3
  • All magazines