Netgear switches? In an environment like this? I’ll give them the benefit of the doubt that that is maybe a provider-owned thing, and that they have an 'enterprise' line, but, really... Netgear. The firewall brand isn’t revealed in the network diagram, but what is it, a $100 sonicwall? Should I be concerned keeping all my email, business and personal, there about what other parts of their infrastructure they are cheaping out on?
When you are running a service like this, redundancy among transit providers is the most basic, table-stakes thing you can do. It's almost negligent to not have that.
Netgear do some half decent fully managed switches. It’s not all blue crap off Amazon.
The worst switches I ever used were HPE ones in the old C5000 blade chassis. Absolute turds. Packet loss, constant port failures and complete hangs. HPE’s solution was to tell us to buy new ones.
The worst switches I've ever used would probably be various 'Cisco' switches from their small business line, usually ones that ran the same OS used when they were sold under different names like 3Com or Linksys.
oh god, when I worked for a small telecom in the midwest they heavily used the 3Com switches. They were the bane of my existance, things would power loop, or my favorite, continue to work but prevent any sort of access to them.
To be honest, those little blue unmanaged Netgear switches aren’t bad at all. We have dozens of them in our lab at work running 24/7 for like decades and have never had a failure that I remember.
They aren’t terrible as long as you have a supply of wall warts available. I ended up powering mine off a little Meanwell switching supply in the end as they don’t blow up as often.
I am aware, I deploy white box gear, what concerns me is the software, some is better, some is worse, less so than the merchant silicon the system is based on.
To be fair, broadcasting your hardware via topology isn't what I consider a safe practice.
As to the netgear switches, I would figure they'd have hot spares considering the cost savings. I'm not entirely sold on a specific vendor for the end-all-be-all for switching needs, support for most is less than stellar, and the need for hot spares grows every quarter report from the big name vendors as they continue to push for larger margins.
In environments like this, it's less about the vendor specific product, and more about the redundancy setup (which appears they lacked but are transparent regarding it).
You're not wrong but considering all of the recent 0-day exploits, I would argue that it's a better practice than the wack-a-mole response from vendors like Fortinet & Barracuda.
When the vendors you're buying from aren't taking security seriously, I suppose you take any necessary step in limiting exposure. I'd also argue that outside of the big boys like Cloudflare, no one else is displaying their topology via their own website.
In an ideal world everyone would share their architecture, stack and so on and we as an industry we could learn between each other and everyone would have a net gain out of this information sharing.
In reality at the time that you share something in good faith you will always have someone trying to exploit it.
One example: I’ve worked in a CV production API to recognise certain documents. More than 900 days with no spikes and only real users in the system.
Then the CTO went to a conference to talk about how our performance was great and made a very large advertisement about our system. End result? 1800% spike, and tons of frauds and adversarial stuff coming.
Not being cynical, but I do not think that we’re entitled to have any disclosure from any private company in that regard.
When you are running a service like this, redundancy among transit providers is the most basic, table-stakes thing you can do. It's almost negligent to not have that.