Re: Realizing Good Ideas with Debian Money

2019-06-24 Thread Thomas Goirand
On 6/2/19 3:39 PM, Ben Hutchings wrote: > On Fri, 2019-05-31 at 21:04 +, Luca Filipozzi wrote: > [...] >> However, without an HPE donation or discount, we are much more likely to >> follow a less expensive approach: pairs of 2U servers with local >> storage, etc. Still not cheap but not multipl

Re: Realizing Good Ideas with Debian Money

2019-06-02 Thread Ben Hutchings
On Fri, 2019-05-31 at 21:04 +, Luca Filipozzi wrote: [...] > However, without an HPE donation or discount, we are much more likely to > follow a less expensive approach: pairs of 2U servers with local > storage, etc. Still not cheap but not multiples of 100k. > > If a hardware vendor happens t

Re: Realizing Good Ideas with Debian Money

2019-06-01 Thread Russ Allbery
"G. Branden Robinson" writes: > My two cents[4] is that DSA should make its purchasing and hardware > solicitation decisions with the architectural security issue fairly far > down the priority list. It saddens me to say that, but this new class > of exploits, what van Schaik et al. call "microa

Re: Realizing Good Ideas with Debian Money

2019-06-01 Thread G. Branden Robinson
At 2019-06-01T09:04:39+0200, Philipp Kern wrote: > Are we then looking more closely at AMD-based machines given that > those had less problems around speculative attacks? To borrow a phrase from Christopher Hitchens, this comment gives a hostage to fortune. My team at work closely follows (and pa

Re: Realizing Good Ideas with Debian Money

2019-06-01 Thread Philipp Kern
On 5/31/2019 11:04 PM, Luca Filipozzi wrote: > Before you ask: an insecure hypervisor is an insecure buildd. Are we then looking more closely at AMD-based machines given that those had less problems around speculative attacks? Kind regards Philipp Kern

Re: Realizing Good Ideas with Debian Money

2019-05-31 Thread Luca Filipozzi
On Sat, Jun 01, 2019 at 01:50:25AM +0300, Adrian Bunk wrote: > On Fri, May 31, 2019 at 09:04:24PM +, Luca Filipozzi wrote: > >... > > When we last crunched the numbers, maintaining a 5y refresh (to stay in > > warranty, etc.) would require $75k-100k/yr. We've avoided that level of > > annual ex

Re: Realizing Good Ideas with Debian Money

2019-05-31 Thread Adrian Bunk
On Fri, May 31, 2019 at 09:04:24PM +, Luca Filipozzi wrote: >... > When we last crunched the numbers, maintaining a 5y refresh (to stay in > warranty, etc.) would require $75k-100k/yr. We've avoided that level of > annual expenditure because we are keeping hardware longer than 5y and > we've ha

Re: Realizing Good Ideas with Debian Money

2019-05-31 Thread Luca Filipozzi
On Fri, May 31, 2019 at 11:32:42PM +0300, Adrian Bunk wrote: > On Wed, May 29, 2019 at 07:49:25AM -0400, Sam Hartman wrote: > > So, there were two $300k donations in the last year. > > One of these was earmarked for a DSA equipment upgrade. > > DSA has a couple of options to pursue, but it's possib

Re: Realizing Good Ideas with Debian Money

2019-05-31 Thread Adrian Bunk
On Wed, May 29, 2019 at 07:49:25AM -0400, Sam Hartman wrote: > > [moving a discussion from -devel to -project where it belongs] > > > "Mo" == Mo Zhou writes: > > Mo> Hi, > Mo> On 2019-05-29 08:38, Raphael Hertzog wrote: > >> Use the $300,000 on our bank accounts? > > So, there

Realizing Good Ideas with Debian Money

2019-05-29 Thread Sam Hartman
[moving a discussion from -devel to -project where it belongs] > "Mo" == Mo Zhou writes: Mo> Hi, Mo> On 2019-05-29 08:38, Raphael Hertzog wrote: >> Use the $300,000 on our bank accounts? So, there were two $300k donations in the last year. One of these was earmarked for a DSA