Hacker Newsnew | past | comments | ask | show | jobs | submit | kv3's commentslogin

It doesn't stop ssh or my web traffic. Why should I care?


It absolutely does stop SSH or Web traffic, if the network path goes through a link with MTU < 1500 and the connection comes in with MSS > PMTU - 40. But only, as the post says, once you start sending a lot of data in one TCP segment.


I thought MTU of ~1500 was (realistically) the minimum nowadays?


you thought wrong. RFC 791, p. 24, "Every internet module must be able to forward a datagram of 68 octets without further fragmentation."


I've had more than a few cases where I couldn't SSH into a system at a hospital or clinic because the VPN/firewall/whatever that their connection went over rejected packets with too high of an MTU. Generally you'll get your SSH connection and it'll hang in the middle of the MOTD.


Because people like AGL, CPercival, and me do care, i.e., we develop network applications, care about users, and prefer to avoid rather than troubleshoot random brokenness.

From today:

http://news.ycombinator.com/item?id=4840330 http://news.ycombinator.com/item?id=4844121 http://stackoverflow.com/questions/13596019/openssl-1-0-1-ha...


Because it stops traffic for some of your users as mentioned in TFA?


Realistically it's probably <0.01% of users.


My advice:

Publicly expound on how you don't care about those users and they are SOL because they are in the minority. It won't matter because it doesn't affect the rest of your userbase, right?

</sarcasm>


You could say the same about IE6 users.


When working on a packet analysis system for a VoIP company, I found that around 1% of incoming UDP traffic was fragmented, the size being around 576 bytes.

I don't know how representative that was (10s of thousands of users, but large users generating more traffic than smaller ones), but < 0.01% is probably on the low side.


If you have a million users that's 100 pissed off people.


And this is EC2, so yeah, millions of users is not unrealistic!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: