Andree Toonk

@atoonk.bsky.social

I like Internet infrastructure engineering 🇳🇱 in Vancouver🇨🇦 https://toonk.io/

100M packets per second! or 100Gb/s at Imix. No problem, see video for demo. Wrote a a neat packet generator on top of the go-afxdp library Ive been hacking on. Check out the video! Sending packets at line rate is easy with this 🤓💯 No more DPDK + Trex needed, Just a small 14MB binary and a xdp nic

Claude Code is now regularly working on tasks for an hour at a time. That's really impressive. Ask it the right question + guidance and constraints and it will run to completion at surprisingly high quality. And with that, everything is going back to Test Driven Development 🤓

Having way too much fun with go-afxdp 😁🤓 Spun up two 100G boxes on latitude.sh with Mellanox mlx5 NICs and sent 64-byte packets between them. Result: 140M pps ~99% of 100G line rate, all using a simple Go program. Not bad 🚀🔥

Bild

Bypassing the kernel with AF_XDP means packets leave at true line rate and suddenly I'm rediscovering pacing & policers (bufferbloat's cousins). Same avg Mbps, but 128 packet line rate bursts trip token buckets that kernel-shaped traffic never touches. Always be learning. 🤓

Been geeking out on packet processing in Go lately. Result: go-afxdp, a Go library for AF_XDP. Send and receive at ~14M packets/sec (10G line rate) in just a few lines of Go. No DPDK, no C, and you don't lose your NIC. Blog toonk.io/line-rate-pa... and the code github.com/atoonk/go-af...

Line-rate packet processing in Go with AF_XDP

If you've been following my blog for a while, you know I have a soft spot for making packets go fast in software. I'm a network guy at heart, raised on routing and switching, but these days most of th...

toonk.io

Listening to infosec people freak out over Mythos is so tiring. Like, bro, your local water treatment plant runs Windows XP, your mobile provider's hardware is older than you are, and the protocol that routes internet traffic is secured by everyone just agreeing that hijacking it would be uncool.

I found a chain of vulnerabilities at RIPE NCC, one of five RPKI trust anchors. One click on an innocuous link could disconnect a network from the internet. Entry points: debugging fields in DNS and crafted TLS certificates, escalating to RPKI Dashboard and RIPE Database mxsasha.eu/posts/ripe-n...

Taking down a European network with a TLS certificate: my RIPE NCC RPKI exploit chain

One click on a malicious, but not suspicious, link. That is all it could take for a network operator to get disconnected from the internet, through a chain of …

mxsasha.eu

I'm heading to AWS re:Invent next week! 🚀 If you're attending, swing by our Booth 1768 to meet the Border0 team (and me!) in person. We're showcasing the World’s First Application-Aware VPN! Stop by for a demo, a chat, or just to say hello! 👋 📍 Find us at Booth 1768 #Reinvent2024

Bild

Was talking about exactly this yesterday with someone, a common response after an outage: “Be mindful of the knee-jerk management response: “We need more change management process!” Unless you’re a real YOLO shop, this is rarely the answer.” toonk.io/navigating-i...

a man in a suit and tie talking on a cell phone with the words big mistake written below him

ALT: a man in a suit and tie talking on a cell phone with the words big mistake written below him

media.tenor.com

Ooh man, bummed to hear Equinix Metal is shutting down. I loved the original Packet service and later the Equinix version. Ran many of my network perf testings and BGP anycast pet projects on their amazing infra. End of an era. 😔

Yesterday, while Netflix was grappling with the live streams covering Iron Mike, I got curious and decided to poke around a bit, specifically checking where my caching server was located.

Bild