Canonical’s Ubuntu Infrastructure Got DDoS’d — Here’s What We Can Actually Learn From It

What Actually Happened to Canonical’s Infrastructure The attack surface Canonical operates is genuinely unusual — ubuntu.com isn’t just a homepage, it’s load-bearing infrastructure for millions of automated processes running 24/7. Every apt update, every CI runner pulling fresh package indexes, every snap daemon phoning home on a timer, every PPA pipeline in Launchpad — they … Read more

How Search Engines Shrink Inverted Indexes Without Killing Query Speed: Adaptive Compression in Practice

The Problem: Your Index Is Eating Your RAM and Your Queries Are Still Slow The thing that catches most people off guard is the sheer scale of a common word’s postings list. Take a 50-million-document corpus — not unusual if you’re indexing a news archive or a mid-sized e-commerce catalog. The posting list for the … Read more

The Tiny UDP Cannon: How QUIC Optimization Bypasses Android VPN Tunnels (And What To Do About It)

The Problem That Bit Me in Production My WireGuard setup was textbook. Full-tunnel mode, kill switch via DISALLOW_BYPASS, all traffic routed through 0.0.0.0/0 and ::/0. I’d tested it with a packet capture, confirmed DNS was resolving through the tunnel, and shipped the app. Then a colleague ran a more thorough session with Charles Proxy and … Read more

The Three Durable Function Forms in F#: What Each One Actually Does and When to Reach for It

Why I Kept Confusing These Three Forms (Until I Got Burned) The bug that finally made this click for me: I had an orchestrator function doing a direct HTTP call using axios.get() inside the orchestrator body. Not inside an activity — inside the orchestrator itself. Local testing? Flawless. Deployed it, threw some load at it, … Read more

Stackless Coroutines in C++ for Games: I Rewrote Our AI System Using Them and Here’s What I Learned

The Problem That Made Me Look at Stackless Coroutines The callback hell wasn’t obvious at first. We had 400+ NPCs each running layered AI behaviors — patrol, investigate, combat, flee, idle chatter — and every transition between states lived in a different callback registered somewhere across six files. Debugging a report like “guard gets stuck … Read more

Linux Kernel Vulnerabilities Are Scarier Than You Think — Here’s What Actually Happens to Your Distro

The Moment I Started Taking Kernel CVEs Seriously The thing that woke me up wasn’t a breach. It was doing a post-incident audit and realizing our production API server had been running a 6-month-old kernel with three unfixed privilege escalation CVEs — two of which had public PoC exploits on GitHub. We hadn’t been hit. … Read more