The Register Home Page

* Posts by Nate Amsden

2694 publicly visible posts • joined 19 Jun 2007

Postgres pioneer credits Oracle with helping his database take over the world

Nate Amsden Silver badge

weird

Nothing Oracle could do I think would influence whether someone wants to use Postgres or not. MySQL has always been freely available. MariaDB has been around for a long time as well, as have other forks(I was using Percona's fork up until maybe 2015-ish).

The DBs are quite different. Postgres from what I understand is certainly closer to what a MSSQL or Oracle DB is than MySQL, that alone would be the biggest influence if that is an ability you need.

HPE extends validity of quoted hardware prices, possibly for months

Nate Amsden Silver badge

Re: Another sign that the AI hype bubble is faltering?

I have been casually tracking the price of a single stick of HPE 64GB DDR5 memory and it has been stable at ~$7,100 for several months now at least from CDW (whose prices matched what I was quoted 3-4 months ago from the HPE reseller/VAR I use)

https://www.cdw.com/product/hpe-smartmemory-ddr5-module-64-gb-dimm-288-pin-5600-mhz-pc5-448/8188855?enkwrd=P64986-b21

JFrog's 0-days let OpenAI's models hack Hugging Face

Nate Amsden Silver badge

Re: why would their own artifactory server be exposed?

needs internet access is outbound, doesn't need inbound internet access. Have been running artifactory myself(though managed by someone else most of it's life) for a decade now.

Nate Amsden Silver badge

why would their own artifactory server be exposed?

Sounds like it was directly exposed to the internet, no need to do that??

Hyperscale, hypersensitive: US teacher cuffed for applauding datacenter critics

Nate Amsden Silver badge

Re: I have relatives in the area

Even if it doesn't use evaporative cooling another point has been getting raised recently regarding power usage at the point of generation. So imagine this at multi GW scale as some of these facilities are claimed will be using in the future...

"Natural gas plants withdraw an average of 2,803 gallons per megawatt hour produced whereas coal-fired plants withdraw 19,185 gal/MWh. As the most water-intensive plants make up a smaller portion of the electricity generation mix, water withdrawals will continue to decrease."

https://www.energyindepth.org/natural-gas-reduces-water-consumption-in-power-generation/

Windows Server Update Services buckle under Microsoft's metadata mountain

Nate Amsden Silver badge

Maybe this would help

Not a WSUS expert(I mostly do linux stuff) but I did deploy it on a couple of occasions, I found the tool here to be useful and worthwhile investment(subscription)

WSUS Automated Maintenance

https://www.ajtek.ca/

There are free ways to do everything this tool does(the site links directly to 3 of them), but given the cost, if you aren't super confident with SQL etc I think it's a no brainer to get this tool if you have WSUS. Cost is $150/year. Set it and forget it(well except for occasional updates and annual license imports).

Airbus migrating 70 critical apps from AWS to France's Scaleway amid digital sovereignty push

Nate Amsden Silver badge

Re: You'd think Airbus is big enough...

Sometimes it takes a few years or a decade or more to break yourself out of the cult of the cloud

https://cultofthe.cloud/learning-the-hard-way/ (one of the articles on that site I created late last year) that page lists a bunch of example companies some small, some huge that learned public cloud really isn't all what it's made out to be.

Most of the rest of the site is devoted to large amounts of details behind every corner as far as debunking all the myths and exposing how hyperscale IaaS is broken by design - no amount of "FinOps" can fix it. Over 40,000 words(no LLMs were used) of my own writing.

Cinnamon 6.8 will support Wayland – if you want it

Nate Amsden Silver badge

Re: No rush...

Not that I have tried it, but I probably will in 2030 -- don't forget that you should be able to sign up for Ubuntu pro and continue to at least get Ubuntu-based updates for your Mint system(mint already pulls updates directly from Ubuntu so I expect it will work fine), you won't get any Mint-specific updates beyond that point for Mint 22 (which I use as well), but not really a big deal.

What has me a bit more worried though is when/if Firefox drops X11 support. Certainly not before 2030, but maybe by 2035? I have manually maintained my main browser (been Firefox ESR since ESR came out) probably for well over two decades now. There are forks of Firefox of course, but who knows how many of those will care about X11 by 2035.

I only care about X11 because I use a couple of features integral to my workflows since late 90s, the main one is edge flipping virtual desktops. I use a old Gnome app called brightside which hasn't been maintained since 2004 but I got it to build clean on Mint 22 still (phew). Another feature I use regularly but I often forget about because it's just there in the background is I launch many things using different user accounts(slightly better isolation) and use the command "xhost +si:localuser:<username>" to grant access for those users to display on my display. Unsure if Wayland has a way to do that either(assuming not). Also I use Pulse Audio's "network" server mode(unrelated to X11) so those other users can send audio as well.

For the different users etc, worst case I could work around that running many different full Linux VMs on different desktops and edge flip between them. Lot more memory usage but I got 100G of unused memory in my laptop so not an issue. Better isolation for sure too, though unsure how to handle audio, not going to bother trying this before 2030.

But the most important thing is edge flipping, I had an exchange with someone on LinkedIn about this specifically who seemed to know quite a bit about Wayland and believed what I wanted to do is not yet possible on Wayland(at least at that point). Unsure if anyone cares enough to make it possible in the coming years or not. Happy to admit I may be the only one left in the world who does things in this way, so I don't hold it against Wayland for not supporting it, just means I'll try to hang on to X11 for as long as I can (even if it means running unsupported stuff, again I could isolate internet exposed things in a VM worst case).

T-Mobile appears to be quitting VMware – and fighting a very familiar battle for support rights on the way out

Nate Amsden Silver badge

Re: Meanwhile…

and here we are in 2026 and KVM-based stacks still can't compete with where Vmware was 16 years ago with version 4.1 in some cases anyway

https://web.archive.org/web/20110221002303/http://www.vmware.com:80/support/vsphere4/doc/vsp_40_new_feat.html

See the laundry list of new features that came out with that build, 4.x was the last version of vSphere I was really excited about, everything since has been meh mostly just security updates and new hardware support.

For me personally, a solid VMFS replacement would be nice, GFS2 exists, though it seems outside of HPE VM Essentials nobody is willing to risk fully supporting it (as far as I can tell anyway). I didn't realize this myself till I looked into it much deeper late last year. When El Reg posted about a new Xen Server today or yesterday I checked their docs again, and there is no real change.

vSphere APIs for performance monitoring with 3rd party tools(I use LogicMonitor), unsure if KVM-based systems have anything remotely resembling that(or the degree of depth that the data that is provided). While I don't need the feature myself I did poke around to try to see if there was any KVM-based solutions that provided equivalent to vSphere's "fault tolerance" feature but came up empty(other than some discussion from Red Hat I think speculating whether or not they need it, and that was many years ago).

The fact that T-mobile only made 2 support calls is testament to how rock solid the vSphere platform has been. When I was using it for work maybe I reached out to support 4-5 times over a decade(small installation). I stayed behind the curve in versions, with a conservative configuration and shit just never broke. To be clear the ONLY things I cared about from VMware was ESX/ESXi (preferred ESX), vCenter, and VMware Workstation(and VMware GSX/Server two+ decades ago). Never gave a shit about the 90+ other products they tried to sell since ~2012.

I still run ESXi 6.7+vcenter 6.7 in my personal colo on old gear, will look to replace it with something else when I refresh hardware again maybe around 2030.

Have been using VMware since before v1.0 was released on Linux back in 1999. I misplaced my "VMware for Linux 1.0.2" CD maybe 15 years ago, was a nice bit of history for me anyway. I did keep several of my vmware downloads, I don't know why I'll never use them again but I can't bring myself to delete them(and they only consume 2GB of disk space, so it wouldn't save me anything)

From ~6MB for vmware 2.0.3 (before they renamed it to "workstation") to almost 400MB for VMware workstation 17.

-r--r--r-- 1 root root 5.9M Jan 12 2001 VMware-2.0.3-799.tar.gz

-r--r--r-- 1 root root 6.3M Jun 22 2001 VMware-2.0.4-1142.tar.gz

-rw-r--r-- 1 root root 35M Aug 23 2008 VMware-mui-1.0.6-91891.tar.gz

-rw-r--r-- 1 root root 35M Sep 6 2008 VMware-mui-1.0.7-108231.tar.gz

-rw-r--r-- 1 root root 103M Aug 23 2008 VMware-server-1.0.6-91891.tar.gz

-rw-r--r-- 1 root root 103M Sep 6 2008 VMware-server-1.0.7-108231.tar.gz

-rw-r--r-- 1 root root 540M Dec 19 2008 VMware-server-2.0.0-122956.i386.tar.gz

-rw-r--r-- 1 root root 467M May 3 2009 VMware-server-2.0.1-156745.i386.tar.gz

-rw-r--r-- 1 root root 483M Oct 29 2009 VMware-server-2.0.2-203138.i386.tar.gz

-rw-r--r-- 1 root root 9.1M Jun 3 2009 VMware-server-console-1.0.8-126538.tar.gz

-r--r--r-- 1 root root 9.3M Nov 4 2001 VMwareWorkstation-3.0.0-1455.tar.gz

-r--r--r-- 1 root root 11M Jul 6 2002 VMware-workstation-3.1.1-1790.tar.gz

-r--r--r-- 1 root root 12M Dec 10 2002 VMware-workstation-3.2.0-2230.tar.gz

-r--r--r-- 1 root root 21M Jul 13 2003 VMware-workstation-4.0.0-4460.tar.gz

-rw-r--r-- 1 root root 42M Mar 16 2006 VMware-workstation-4.5.2-8848.tar.gz

-rw-r--r-- 1 root root 41M Apr 10 2006 VMware-workstation-4.5.3-19414.tar.gz

Mageia 10 keeps the 32-bit Linux flame alive

Nate Amsden Silver badge

Re: old fashioned

yeah that can make sense though that sounds like a deliberate configuration change made by the admin rather than something that comes shipped out of the box? At least I don't recall ever seeing that kind of thing coming by default. I'm all for giving the user/admin options to do things how they wish..one of the nice things about OSS/Linux I suppose is there are lots of options..(even the kernel I suppose a user has the freedom to run similar/same tools on *BSD as well if they prefer).

Nate Amsden Silver badge

old fashioned

sudo bash for my ubuntu-based systems

plain ol su, or login directly as root(ssh) for debian/devuan systems. Sue me I suppose I've been doing this for 30 years. My earliest years with Linux I used root as my main account on my desktop just to get around permissions issues(and I don't recall ever having an issue).

Speaking of sudo/su, I found something I didn't like recently, I'm normally quite careful with typing commands, real mistakes are few and far between(and I don't think sudo would of had any effect on them). I can still remember at least 23-25+ years ago (I was clearing some files in my homedir and I meant to type something like "rm -rf file1*", except I had a space between "file1" and "*". Lost all of my email(several years worth, and no backups). That was as my regular account too not even root. In all of the years since, typing similar commands thousands of times I don't recall ever making that mistake again.)

Anyway, I was applying OS updates to some of my personal servers, not paying too close attention as I was doing other things too, so I switched back to one of the terminals to reboot one of my servers after applying updates, having forgot perhaps just a minute earlier I did that(?) and I typed reboot<enter> right as it disconnected me from ssh(I'm a fast typist I think), and dumped me back at my (non root) local terminal on my X11 desktop.

Until that day(16 days ago), my expectation was such a command was harmless, I am not root, so it won't reboot.

Well I was quite shocked to see my linux laptop promptly reboot(ironically would have been nice if it was like Windows reboot where if you use the CLI it counts down 60 seconds or something before rebooting, I assume you can cancel a reboot in that situation if needed), killing dozens of open applications and virtual machines(it was a long time since I last rebooted). Ugh. Fortunately nothing important was lost. I poked around more after and noticed that reboot/shutdown/etc are links to systemctl (damn you systemd! damn you to hell! haha), did many web searches and really was surprised how little results came up, the only real mention I could find of this behavior was a red hat bug report (which I couldn't read since I don't have an account they "paywall" it in their own way).

But it seems to be limited to users logged in on the local console, doesn't behave that way if I was logged in to my system via ssh. But wow was that annoying. I would like to disable that behavior, though haven't spent any time on looking how to do that yet.

I checked my devuan systems(no systemd) and reboot/shutdown/etc all regular commands of course...

OpenAI Codex bombards SSDs with needless write operations, costing millions

Nate Amsden Silver badge

largest sqlite database in the world?

Guessing if asked pretty much nobody would think of sqlite if they were asked to store 30TB+ in a database...

Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

Nate Amsden Silver badge

is this even an issue

I've used squid at home for decades. My earliest squid configuration included ad blocking. When most sites went https, this stopped working.

Most sites are https these days. At least my squid cannot see any https requests, it just shows CONNECT in the log. Looks like squid can do https intercept if configured right, one site I see mentioned several linux distros that do not have the required options enabled at compile time to use it, in which case you either have to build it yourself or use a 3rd party package. Perhaps nore recent distros have it enabled.

I suspect most installs don't use this feature(also don't forget have to distribute your custom cert to all browsers using squid) so the risk overall is quite tiny, since anything really sensitive would be over TLS, and squid can't see it.

Non-x86 servers now nearly half the market, IDC says

Nate Amsden Silver badge

Revenue and not units?

Seems they are measuring stuff based on revenue not on units shipped? Given the "AI" servers generally cost a lot more with their GPUs and stuff I would expect that would skew the revenue numbers in their favor by quite a bit on that alone.

OpenAI's agent chained decade-old DoS attacks to crash web servers in seconds

Nate Amsden Silver badge

Re: Phew

Was not aware of that, thanks. Looks interesting, I looked at this instead of the video https://i.blackhat.com/BH-USA-25/Presentations/US-25-Kettle-HTTP1-Must-Die-The-Desync-Endgame-wp.pdf

Still happy with HTTP 1.1 for now anyway, If these attacks start becoming super common then may have to worry a bit more. I certainly will never try to claim that it is more secure than HTTP/2, just simpler, and more familiar(having operated internet facing web servers for 30 years now).

I am sort of curious how full proxy load balancers handle this(maybe they just pass everything straight through as they normally would), the PDF makes a brief mention of F5 BigIP regarding HTTP/2, but no other mentions of that. For work stuff traffic goes to CDN/WAF first then to my back end origin(Netscaler), then onto the servers themselves(mixture of apache, nginx, and puma). My personal stuff is all directly exposed Apache only.

Certainly seems like smart people that found that stuff though.

Nate Amsden Silver badge

Phew

Never needed HTTP/2 on my systems anyways ..

For work stuff, HTTP/2 is offloaded to the CDN(so if their systems are vulnerable they'll fix em I suppose), origin remains HTTP 1.1, which works fine.

'It would be good for the world' to slow down AI sprints, Anthropic says

Nate Amsden Silver badge

odd

Given there's no intelligence in any of these systems, they are just pattern matching. Seems just about every week or two there's news of some other big LLM-based project/deployment failing badly, or costs exploding and people cutting back.

In any case such a pause is impossible, so pointless to even mention it, probably just trying to drive hype ahead of their IPO.

Angry devs vow to flee GitHub Copilot as metered billing takes hold

Nate Amsden Silver badge

Re: View from a distance

Same thing happened to public cloud. Just at faster rate with LLMs. I first wrote about it in 2010 then wrote more extensively about it late last year on my new website https://cultofthe.cloud/ . Dozen articles, 40,000+ words, and I've not used an LLM for anything on that site or anywhere else in my life yet anyway. Also no ads, no trackers of any kind. I haven't even looked at how many hits in my web logs for the site. I post links to the site on LinkedIn in comments on an almost daily basis since last year.

At a big scale take the Geico insurance company, after spending a decade trying to make public cloud work they started reversing course last year I think after balking at a $300 million cloud bill. Story of them and others in one of the articles on the site. Similar with SAP though it took them 5 years to realize. Problems exist on small scale too, one of the articles is about my first hand experience at multiple companies over about 2 and a half years. Moved out of public cloud 14 years ago...i even host the website on my own Dell hardware in a colo I pay for.

I made the site because there's far too much info to convey in any comment box. I have written many such comments here on el reg over the years but often people have other questions too.. so I put everything in one place.

Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures

Nate Amsden Silver badge

kind of ironic

MS treating these VS code security issues as so minor, given the recent compromise of most of their internal github repos by means of a poisoned extension in one of their own employee's VS code installation ?

California may let Linux bypass age check

Nate Amsden Silver badge

Re: what is the point of this?

In theory yes, though in practice maybe not. Perhaps that would mean the website would be assuming responsibility for the content (assuming the content is identified/classified correctly to begin with). Imagine lawsuits with the website saying this part was safe when it was not, just obfuscated enough the detection engines didn't see it as bad.. seems pretty much all systems struggle to classify things even with the latest tech, especially against folks determined to get around those detections.

I still do vaguely remember when porn was banned on the internet back in the 90s? Perhaps the ban was quite limited I don't recall but I do seem to recall Playboy's site being super censored for a short time. I was still young, new to the internet and didn't know many websites..add to that I was overseas and the internet connection at the ISP was terrible(averaged maybe 0.5kB/sec most of the time from their WAN link, local modem links were fine).

Nate Amsden Silver badge

what is the point of this?

I have thought about this on occasion, the article states the OS needs to provide a way for the user to declare their age.. then what? How does this info get transmitted/verified/etc to an application or a service? (perhaps that reserved for some future thing...)

Also for home computers, how common is it still for people just to use one shared account on their computer? Parent logs in, does some stuff, kid comes in later that day and just keeps using that same parent's session to do their stuff? Or do people often make a point have/enforce different accounts for people on the computer? Windows has had fast user switching for quite a while but unsure how widely it is used (and unsure if Mac has something similar).

Also for mobile devices same question, it seems like it is super rare to have a mobile device to recognize different identities/user accounts of people that are using the device from a device usage perspective(add to that likely would need a protection layer between identities). I have heard of some Android devices that can have work/home profiles that are isolated though have never come across that ability on any of the devices I have had(currently S24 ultra, if it has that ability I am unaware, I have looked in the past but couldn't find evidence that such ability exists on this phone).

I can certainly understand the concept behind a website/service that then ties into a 3rd party age verification service, that makes sense (for those that wish to have such services anyway). But from the computer itself...just seems pointless..

Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise

Nate Amsden Silver badge

Re: JavaScript ...

Almost two decades ago I spent a bunch of time building custom RPMs for a dozen or so Ruby gems for the 3 different platforms we supported I think (Fedora Core 4 32-bit, CentOS 4 32-bit and CentOS 4 64-bit). I like consistency and I like not having external dependencies..

A few years later at another company I faced the first request from a developer they wanted NPM stuff... they gave me a list of things, I was going to do the same thing as I had done in the past, but quickly fell into dependency hell(10x worse than Ruby Gems), so I noped out at that point and told them to deal with it themselves however they wish and haven't touched npm since. I think at one point years later someone mentioned there was something like 500 NPM packages being used in that part of the code base. Ugh. Seemed like both ruby gems and NPM nobody took the time to track versions/etc. I remember at one point there was a Newrelic gem and Newrelic's website was saying "hey that version you are using is obsolete you should update", digging in deeper it was obsolete maybe 5 years prior..but I suppose it was good that it still worked.

Never really had any issues with PHP, Java or Perl stacks by contrast. Of course all of my Ubuntu repos are hosted internally as well(using aptly).

The big AI companies are going to see their margins disappear

Nate Amsden Silver badge

AI will eat the world

If your timeframe is measured in decades. Assuming WW3 doesn't set us back too far in the meantime.

Enough with the AI FOMO, go slow-mo, says Domo CDO

Nate Amsden Silver badge

up vote

Me here wanting to upvote the article and line of thinking.

I spend more time than I should on LinkedIn but wow is the AI FOMO extreme there. Recently someone sent me a comment saying there is no bubble in AI, some companies will go under but AI is here to stay. In response to a comment where I said I believe the big Utah data center won't get built due to bubble burstintg.

I replied in part, I agree. The Internet didn't go anywhere when that bubble popped, and housing didn't disappear after that bubble popped. Then listed a bunch of signs regarding bubble behavior. Of course they did not reply. Strange how some(many?) think that if we are in a bubble then when it pops everything goes away. Nobody is saying that. The proof is in the last 2 bubbles. So they think because of that there is no bubble.

More convinced than ever at some level AI is a cult. Much like public cloud(something I wrote a full website on late last year regarding the cult of the cloud). Though the pace of this 'era' is vastly accelerated. Something I wasn't expecting. From concept to going all in, to finding out it's not working and reversing course. With cloud this took 5-10 years in some cases. With "AI" seems to be closer 1-3 years.

There are good uses I am sure (i haven't had a need to look for myself), but the attitude that it will replace everything is quite laughable at this stage. At least with the current generation of tech. Companies are frantically trying to add stuff to bring up demand or rebrand existing crap as AI..

The worst though is the infrastructure, with some companies taking stuff from citizens like power and water at massive scale. Two recent examples Iearned of in the past week lake tahoe, ca and Puget sound energy in WA. Totally unsustainable, though fortunately I believe the bubble burstintg soon will help put that to an end.

I believe there is massive demand for what people think AI can do. Problem is it can't do most of those things(properly) and the proof of that is the ever increasing articles and commentary about stuff being rolled back, re hiring, scaling down, etc etc.

Datacenters slurping up so much juice they boosted prices 75% in largest US energy market

Nate Amsden Silver badge

just be sure

That it's clean energy, especially when talking about anything over say 50MW. Should bring their own water too.

The tenants of the facility must bear the full cost of construction and operations, no tax breaks no benefits of any kind.

Though at the end of the day I still believe the bubble burstintg soon will kill off most of these before they get too far especially given shortages in components for power, cooling etc.

Git is unprepared for the AI coding tsunami

Nate Amsden Silver badge

double edged sword

Microsoft wanted this. Pushing, no forcing "AI" stuff on github users so much there was massive complaints. They wanted masa adoption of copilot etc. seems like many things fhey didn't think it all the way through.

I'm not a developer myself and probably spend less than 10mins of time on github a month so it doesn't really bother me.

I would think they could easily build up enough data on the abusers overloading their systems to block or throttle them pretty easily if they wanted to. Or maybe they laid those people off too.

Anthropic urges Uncle Sam to kneecap China's AI ambitions before 2028

Nate Amsden Silver badge

export controls worked?

Want to limit chips? seems they were in fact limited according to Nvidia

https://www.msn.com/en-us/money/technology/jensen-says-nvidia-now-has-zero-percent-market-share-in-china/ar-AA22hxE0?

(article is about a week old)

"Jensen says Nvidia now has 'zero percent' market share in China"

So surely that must've stopped China dead in their tracks for AI stuff right ?

It seems in many cases China(government at least) does not WANT the western chips, they want to force their citizens to make their own, (in some cases by outright banning Nvidia etc from being used at least in sensitive applications). They seem to be doing a pretty good job catching up though. They also have a huge advantage of being able to develop/deploy stuff like massive amounts of power MUCH faster than anyone in the west could dream of.

And from a manufacturing automation perspective it seems China may be a years/decade ahead of the west.

Americans would rather have a nuclear plant in their backyard than a datacenter

Nate Amsden Silver badge

wonder who could be in favor

with 27% being in favor maybe just have to say that is out of pure ignorance perhaps (not understanding the effects of the facility).

I love data centers myself but these super massive ones are just beyond stupid. There was an article recently saying ~50,000 residents of Lake Tahoe, CA (resort town on the border with Nevada) are having to find a new source of power as their power company says they will cut them off and send their power to data centers instead. I can only hope/assume that is a NV-based utility(and they get their power from over the border), can't imagine California regulators allowing that to happen to a local utility(but anything is possible).

Pop this bubble please...damnit. It will pop I have no doubt just want it to pop today.

Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits

Nate Amsden Silver badge

curious

if this is mostly a "one time boost" from using the new tech, or will it get (significantly) better? have read some claims that many of the issues being found are memory related which are an easier kind of issue to detect? Also have read claims (unrelated to security scanning) where LLMs are hitting a wall as far as how much better they can get (in part due to they've already consumed the world's data), and that another "breakthrough" is needed(who knows how close/far off that may be). Also seen claims that some of the non frontier models get similar results.

In a previous el reg article on the Firefox bugs I think it was there that I saw it mentioned many of the bugs were detected by disabling the Firefox sandbox stuff, and the sandbox would have otherwise prevented exploitation, which has me a bit curious maybe humans were less interested in poking at those specific kinds of bugs because they felt the sandbox was good enough(at least enough to make them a lower priority).

I suppose time will tell.

Dissatisfied: Three-fourths of AI customer service rollouts are a letdown

Nate Amsden Silver badge

terrible

A recent support experience with Citrix(Netscaler customer for 15 years) was quite terrible with their stupid "AI" bot. Apparently can't call them on the phone anymore(unsure when that changed, I don't need to open cases often), but their bot said I can wait on the line for a live agent so I waited that day for 90 minutes. Nobody live came on, the bot ignored all queries once I was in the queue, never gave another update what position in line I was(initially I was #22).

I tried again a week later and waited THREE HOURS in chat, THAT time the bot didn't even tell me what position I was in and again never gave an update when I may get a live agent.

Citrix was apparently being hammered by 2 things at the same time, a security update issue as well as pending licensing changes. So they were slammed. I can understand being slammed.

I can't understand a simple AI bot not being able to tell me something as simple as what position in line I am in at regularly scheduled intervals (phone systems have done that for decades). And even worse, ignore ALL queries from me while I was waiting. I should be able to ask it at any time what position I am in, how long can I expect to wait etc. It should know all that stuff(average wait times today etc). But it knew nothing. I can only imagine perhaps there was more than 1000 people in line on those days, maybe that overflowed a counter or something in the bot. But if a bot tells me there are 1000 people in line and you may have to wait here for 3 days to get support, then I will know to give up. Many phone support systems in the past offer an option to call the customer back automatically when it's their turn, but with this AI bot at least, no option for that, have to look at the screen and wait to see if anyone types something.

I eventually solved the issues myself(two of them being real bugs, but I found workarounds), though still need to open another case for my original issue now that telemetry is flowing for the first time(originally was rejected to be allowed to open ANY case because I didn't have telemetry setup, something I've never had to do until that point).

Utah mega datacenter could dump 23 atomic bombs worth of energy per day

Nate Amsden Silver badge

Almost certainly

the bursting of the bubble will kill this, or perhaps at least dramatically scale it way down(~80%+ smaller perhaps).

Sovereign cloud is only possible if you’re Chinese or American: Gartner

Nate Amsden Silver badge

openstack?

Openstack has been open source since it's beginnings. I am sure it is rough around the edges but it's what many larger clouds are built on top of. Their website lists 26 public clouds built on the tech in Europe: https://www.openstack.org/marketplace/public-clouds/

I downloaded a picture recently titled "European Alternatives to US Big Tech", I posted a copy here http://elreg.nateamsden.com/euro-tech.jpg

In the "cloud" section it mentions names:

Outscale, Scaleway, Cloudscale, Gridscale, OVHCloud, Exoscale and others

Lots of opportunities ...

Myself am not a fan of IaaS at all, on prem for me.

GNOME may rule Ubuntu Resolute Raccoon, but X.org isn't roadkill yet

Nate Amsden Silver badge

Re: Just for curious

I was wondering the same thing about Ubuntu Mate vs Mint Mate. I switched to Mint+Mate after Ubuntu 10.04 LTS went EOL (til that point I hadn't even heard of Mint but I hadn't looked into switching distros in eons). Wondering what the difference is, is there an advantage to one over the other, given that Mint is based on Ubuntu as well. For me I stuck to Mint because that is what I have been using since ~2012-ish, as far as I recall there was no Ubuntu-based Mate otherwise(at least not as easy to install maybe).

Currently on Mint 22 which has support til 2029, though I assume I can subscribe to Ubuntu pro and get core updates beyond that date(wouldn't include Mint stuff), and I already maintain the most security sensitive thing on the system manually(firefox ESR), so not depending on the distro for that anyway. I don't plan to make any changes before 2030, so not sure what the world will look like at that point.

My main sticking point has been my dependence on a two-decade old tool called brightside (last shipped with Ubuntu 16), which gives me virtual desktop edge flipping (move mouse to edge of desktop up/down/left/right and it changes to the adjacent desktop). Been a central part of my workflow since I first used AfterStep in 1999(switched to Ubuntu/Gnome around 2006 I think). I managed to compile it cleanly on both Mint 20 and 22, was super worried I wouldn't be able to get it working but I did(along with ~16 other dependencies), and it works flawlessly. I am sure that will not work in Wayland. I checked a few weeks ago for edge flipping on Gnome just with web searches and couldn't find anything more recent than ~2014 or so. Maybe it is available (or maybe it is in KDE) using a different term, not sure.

I had an exchange with someone who seemed super knowledgeable about Wayland on LinkedIn a month or so ago and they implied there was no such support for edge flipping in Wayland(yet anyway, maybe in the future).

So, for the most part I bury my head in the sand and hope I don't have to face that reality(same as I did for Mint 20/22 but that worked out OK, no changes required), changing workflows that I have had in place for 31 years (in 2030) is going to really be a terrible experience. If I have to switch to KDE or something to get this functionality I suppose that is doable. I haven't run KDE regularly since 1998 (I have screenshots running KDE snapshots, and beta builds, one of which showing my ncftp downloading kdebase-981003.tar.bz2 !), my screenshots starting 9/1999 are AfterStep.

No high DPI for me, last year I upgraded from 1080p to 1440p and don't see a need to go any higher for my stuff. I recall the laptop I got a decade ago had a 4K screen and I had to run it in 1080 mode as so many important things didn't scale right. My newer laptop from 2023 came with a 1080 screen(which I was fine with), both Lenovo P-series.

Also worried that perhaps apps like Firefox drop X11 support at some point too, can't believe I didn't notice it till last month but I was surprised to actually notice that Firefox does not ship anything that is not Windows/Linux/Mac. I expected something like FreeBSD in there but no(am aware there is another way to get it, just not direct from Mozilla), given that there is a increased chance of losing X11 as well(certainly not before 2030 I imagine) vs other apps. I'm sure some folks could fork it(Palemoon) or something to keep it going but it wouldn't be easy.

Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down

Nate Amsden Silver badge

archive was down

Unsure for how long but for me at least a couple of hours yesterday, I was assuming due to lots of folks trying to patch the kernel bug. It stabilized eventually well enough to get my aptly mirror to fully sync. Stumbled upon the Ubuntu status page and saw all the red, last I noticed last night they had 16 sites in major outage still.

During the 2 or 3 hours I noticed it, aptly was saying timeout for http headers, manually testing showed it taking about 30 seconds to process a request.

Another similar situation a few months back again a kernel package thing, though in that case I think it was just somehow that one package, which was a huge file was timing out for hours.

Legacy TLS tour continues with Exchange Online blocking old versions from July 2026

Nate Amsden Silver badge

Re: Good. It was time.

You say that if the biggest risk to these systems is the encryption used. Who's doing MITM? Really the biggest risk by a factor of 1000x is phishing/social engineering/etc. Gain access to the account the easy way.

Not that this change affects me I host my own email. The org I work for uses office365 but I use OWA(Linux) and Classic Outlook(Win).

Anthropic's super-scary bug hunting model Mythos is shaping up to be a nothingburger

Nate Amsden Silver badge

"one of misinformation and hype."

Hype especially, sums up the entire "AI" movement. Not saying there is no value there but OMG is the hype turned up so high, (saying "to 11" or something doesn't do it justice, I don't have words..). The cracks are continuing to grow in the whole system though, more and more are realizing(and making it to press in various forms) that the hype is not living up to reality in most cases. I'm sure some of that has to do with the customers themselves not being "prepared" or being "willing" to change their systems/processes/etc to adapt to "AI's" limitations to effectively use the tech, but really who expected everyone to do that at all? The sales pitch seems to have always been you don't have to do much work just install this thing, connect it to your stuff and watch the magic..(smoke).

One of my former managers who is all in on the AI hype bandwagon himself(even written a book on the topic) said once something like "AI amplifies", so if you have some dysfunction then it will amplify that and you won't get good results. My response to him was yeah well pretty much every org has dysfunction, so what do you expect? He didn't respond.

Users complain that UK Azure is having capacity problems

Nate Amsden Silver badge

blaming "AI"?

Thought that was mostly specialized hardware with GPUs and stuff...

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

Nate Amsden Silver badge

Would be interesting

to know the breakdown of these exposed instances, specifically how many are deployed to a cloud provider vs "on prem" (can just look at who owns(WHOIS) the IP spaces of each exposed instance). I'm sort of assuming at least 95-98% are cloud, because I really can't think of a reason why anyone on prem would open a hole in their firewall to an ActiveMQ server(most on prem deployments would be using private IP space internally so would have a NAT/firewall device which you'd have to specifically configure to forward that traffic inbound on). Cloud by contrast is often on a public IP and ignorant users may not enable firewall at all(because they think "who will find this? I'm not an important system"), or they may open it up to the world because they have something else in perhaps another region or AZ or something that needs access and they are too lazy to lock it down more. Or perhaps worse yet opening it to the world so their home computer(on a dynamic IP) can connect to the system directly instead of using a VPN or even a SSH tunnel.

If you are connecting two facilities on prem you're likely using a site to site VPN(you probably could with cloud as well but is less common I am sure) so again no need to expose ActiveMQ to the internet.

I was at an org back in 2009 where we briefly used ActiveMQ for some small things, past decade or so has been RabbitMQ though (all on prem, and of course not exposed externally).

QUIC will soon be as important as TCP – but it's vastly different

Nate Amsden Silver badge

Re: The problem is not TCP - is HTTP

I wouldn't really consider those efforts stupid. The efforts were likely primarily driven by the fact that port 80 and 443 are generally open, and HTTP especially comes with built in compatibility with things like proxies(whether forward or reverse proxies). So if you want maximum compatibility and ease of use you really need to run on top of HTTP. Certainly are downsides to it, but major upsides as well.

I certainly agree though that QUIC really won't matter for the vast majority of folks outside of super duper scaled companies like Google. If anything, likely most websites(at least) won't even bother using it, instead offloading that responsibility to their CDN(like many probably do for IPv6 today and HTTP/3 today).

Microsoft cuts cloudy desktop prices by 20 percent, warns they’ll wake up slowly

Nate Amsden Silver badge

Re: Overpriced

Still going to need an entry level desktop(or thin client+monitor) or laptop to connect to the cloud PC... thin clients/VDI/etc from what I've read are rarely if ever about the cost of the hardware and more the ease of centralized control. Such solutions often cost more than standalone boxes but don't offer the same level of control.

'Uncle Larry’s biggest fan' cut by email in early morning Oracle layoff spree

Nate Amsden Silver badge

kind of gross

to see some posts on linkedin from some ex-Oracle folks saying glowing things about their Oracle experience and how they are so positive and happy etc, as someone commented there is probably something in their severance that says they can't say bad things or something.

But still I'd certainly be pissed at this kind of situation. The two times I was laid off in my career I've always been treated with respect, and the layoff was justified as the company had been struggling for some time. 5 of the 9 companies I have worked for in my career going back to 1998 are dead (last real layoff was in 2002). Two more shrunk by probably 90%+, and another got acquired. I've never worked for a big company, and never wanted to for reasons like this Oracle situation.

But posting super huge profits and axing tons of folks because they are doubling or tripling down on a stupid plan to build out this "AI" stuff(every passing day the credit markets are deteriorating further) well that's about as disrespectful as you can be to the employees and also to your existing customer base.

SoftBank to build massive AI datacenter on former US nuclear weapons site

Nate Amsden Silver badge

would be pretty shocked

if this even gets to 10% of it's intended capacity before they surrender due to high costs/lack of investor money to throw at it.

AI still doesn't work very well, businesses are faking it, and a reckoning is coming

Nate Amsden Silver badge

bring it on

Get us back to normal infrastructure costs. Pop that bubble already, the longer it goes the worse it'll be. These AI things are wrecking havok on the tech world and beyond.

I can't help but wonder how much of a role the sycophant nature of the chat bots contribute to talse confidence in deploying the tech(even if the tech is from another vendor). I've not found a use case for myself to need LLM anything just yet. Fortunately my wife doesn't care about it either though she has at least one extended family member who is obsessed with it. Scary stuff.

For some it really seems like a mental illness of some kind to be totally brainwashed like that. I've seen similar from some(not all) people pushing public cloud over the past 15 years, like a cult.

I was thinking not too long ago Elon himself was railing against all this, only to completely reverse course. Sort of how Oracle was completely against cloud, until they reversed course (Oracle's case was they felt they could get more money out of customers by renting the infrastructure). I read claims a while back that Elon eas obsessed himself with a chatbot(s).

Side note I totally misread the word shop as slop when reading the article

"global consultancy PwC and have set up their own shop to help shepherd organizations toward an AI strategy."

Salesforce stock buyback to saddle company with debt until 2066

Nate Amsden Silver badge

so sad

That stock buybacks aren't illegal still. Was illegal for decades till about 1982. Corporate greed really has ramped up since.

RAM is getting expensive, so squeeze the most from it

Nate Amsden Silver badge

fortunately my system has plenty

My primary "desktop" is a Lenovo P15 workstation laptop from 2022 with a 8 core Xeon and 128G of ECC ram. No swap, usually 100G of ram available. Didn't really need more than 32 to 48GG, just wanted to max it out at the time wasn't too expensive in early 2023. I expect this to last me till 2030.

Laptop before that was a Lenovo P50 which I got in 2016. I specifically recall the kernel being terrible with swap at the time because it came with 16G of ram, and it would grind to a halt for a minute or more doing basic stuff because of swap. I ran the same workload (just newer OS/kernel) as my previous Toshiba Tecra A11 from 2011 which maxed out at 8G. The 16G laptop had plenty of ram but still swapped at times like crazy, so much the mouse cursor would stall and the system would freeze for many seconds at a time. "Swapiness" settings did nothing. A co worker said he had seen similar issues with Linux for years. I had not till that point.

16G ran worse than 8G just with a newer kernel/software. So crazy. I quickly had to upgrade to 32G which fixed it. Later upgraded again to 48G for no reason.(Max is 64G for that P15)

All 3 laptops are on my desk still with their lids closed stacked neatly on shelves with dedicated laptop coolers below each one.

later ran into linux slab memory leaks(resulting in swapping) at work on Ubuntu 20 which I spent about a year in investigating, that was super annoying, onky fix is to reboot. Newer kernels helped a bit and it seems maybe totally resolved in Ubuntu 24.

Oracle moves to assure MySQL community it really does care

Nate Amsden Silver badge

Re: Why would....

I remember being part of an Oracle DB audit at the company I was at back in 2007. We had already failed an audit in 2006 (about a month after I was hired). I suggested some easy changes to fix things going forward but management rejected them, saying everything was handled we don't have to worry about it.

Had another audit the next year and we failed that one too. I don't recall the fines but I think it was between $100-200k (it was a small company). I suggested again we move off of Oracle EE onto SE, this time they listened and I led that initiative to migrate, optimize hardware configs for single socket quad core(which was new at the time) away from dual socket dual core(faster clockspeed). Their original purchase of Oracle(before I was hired was for "Oracle SE One", the bottom barrel DB product with massive limitations. However their DB consultants apparently weren't aware of this and they deployed Oracle EE on everything as their "standard". We got burned more by using the "partitioning" option in Oracle EE, something our company did not use, but the DB consultant's monitoring package did use it, so they enabled it.

They fixed their monitoring stuff to make it work fine with Oracle SE.

I mention it because I specifically recall the Oracle reps being clueless on how Oracle SE licensing worked (unlimited cores per socket, I think max of 4 sockets in a system or in a RAC at the time). I told them multiple times they didn't believe me at first, but later checked and confirmed I was right.

No other audits before I left the company in 2008, and the company went out of business not too long after that.

I had a tiny amount of Oracle at my next employer, I used Oracle DB with per user licensing on top of a Oracle Linux system as the database for vCenter 5.x(only options were MSSQL, Oracle and DB2 I believe, and I wanted a Linux-based DB server). It was super cheap(I can only find the support renewal fee which was ~$1500/year) and worked well. I had several queries from Oracle during those years perhaps probing if an audit would be worth their time, but after I explained what I was using it for they never batted an eye. Of course when the Linux VCSA came around that came with Postgres embedded so Oracle was abandoned when I moved from vCenter 5.5 to 6.5(fresh install no migration) about a decade ago.

Nate Amsden Silver badge

MySQL has short term concerns

Apparently Oracle is about to layoff thousands more, some say as much as 30,000 as their banking deals for AI are falling through.

I'm sure the remaining mysql team are anxious about that so any statements before that next event doesn't mean a whole lot.

Not that it matters to me having moved to mariadb a decade ago, was effortless, every app before and since has not had any issues "requiring" mysql that I have used either internally developed or external.

HPE tweaks T&Cs so the price it quotes may not be the price you pay

Nate Amsden Silver badge

doesn't matter

HPE DDR5 server memory costs were 10.6x higher a couple of weeks ago vs Oct 2025.

For me that ruled out refreshes this year as it meant overall per server cost went up 400% for a system with 768G of ram(64G chips). Original cost for whole server was 28k, new cost memory ONLY was 82k(total server cost a bit over 100k i assume for a single socket 24 core box). I didn't bother to get a full new quote.

If you can eat 10x cost increase then you probably don't care if it's 12 or 13x.

At least my existing HPE gear has no capacity or performance issues and is super reliable. Wanted to replace at least my 10-12 year old stuff with Gen12, maybe next year or later perhaps...

Memory scalpers hunt scarce DRAM with bot blitz

Nate Amsden Silver badge

damage done already

Got a price estimate back from HPE last week memory that I quoted in October is 10.6X more last week with a 2 week expiration time on the cost. For me at least that just means not buying anything DDR5 related this year(I have nothing that uses DDR5 today). Can stick with my old servers/storage for another year, no capacity issues at all. I really wanted to upgrade some of my older systems(oldest in service servers just entered their 12th year of operation), after waiting years to get budget I finally got some this year...guess I will use what I can to refresh network gear, some of which is 10-11 years old.

At least everything is on 3rd party HW support, and the reliability of all of my gear has been outstanding.

Founder ditches AWS for Euro stack, finds sovereignty isn't plug-and-play

Nate Amsden Silver badge

not self hosting

"Compute ended up running on Hetzner, with Scaleway filling in gaps like email and container registries. Bunny.net handled CDN and edge duties, Nebius provided GPU capacity for AI inference, and German identity outfit Hanko took care of authentication. "

I don't see any self hosting there. That is using SaaS and IaaS.

Self hosting is you have servers/storage/network in a data center and you run it end to end(with some exceptions perhaps like CDN).