Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hmm, in the spirit of thinking of worst-case scenarios, most of the engineering talent for Amazon and Microsoft is in Seattle and Redmond, respectively. There's even a sizable percentage of Google cloud platform in Fremont and Kirkland.

Even if most of the employees live, it's likely basic infrastructure will be a disaster for quite a while. Maybe Google would be able to offload ops work to Mountain View, but it seems likely Amazon.com, AWS and Azure would go down, possibly for months. I wonder what the effect would be on the global economy.



Google runs a company-wide disaster recovery testing event every year. Earthquakes are among the numerous scenarios simulated.

https://queue.acm.org/detail.cfm?id=2371516



The problem is that you can't really simulate the systemic effects of a really major quake (like a scenario where Mountain View is out of power for weeks).


The DiRT drills include the simultaneous loss of whole offices, including the complete obliteration of the Bay Area. Participants are instructed to pretend that they've been eaten by zombies and not communicate with anyone in a remote office, and that's backed up (as described in the article) by cutting the network links to & from the Mountain View corporate office.

Now, there may certainly be larger systemic effects over long time periods caused by eg. the death of the company CEO, the loss of new product development, or the complete destruction of the company's market (in, for example, a global thermonuclear apocalypse that sets us back to the stone age). But the tests absolutely do simulate the simultaneous death of 15,000+ employees, destruction of the Mountain View headquarters, and loss of all datacenters, data, and power in the Bay Area, and verify that remote teams can continue the day-to-day operations in such an event.


What happens if Google goes down for a while? Is it really that bad? Yes, Gmail and Drive may cause all kinds of chaos but I think I can survive quite a while without the search engine and YouTube.


The data could be lost. Part of DiRT is ensuring that the result of losing N data centers is not "oops we lost 20% of GMail users data permanently".

On the scale of devastation this article is describing, none of Google's servicing being obliterated really matters but I'm personally pretty glad Google is prepared for multiple, massive scale disasters to happen at once.


The financial disaster would be horrendous. Look at the number of companies using google for email.

When the towers went down in 2001, the first business priority of many companies was getting email back online. It's an incredibly important part of a business.


Reminds me of when I was doing some consultancy for large oil/energy trading company in London. There was huge DR initiative going on at the time, and one thing they realized after surveying the business is that, if worst came to worst, they could still conduct business if they lost every other business system, as long as e-mail was available.


If Google App Engine goes down many sites will stop working. OAuth services will also start to fail. So will custom search provided to 3rd party sites (ok that may not sound too bad but you never now). Then there is cloud storage which in many cases is used as a backup mechanism. And how about the gazillion of sites that load js libraries from Google's CDN? Sure, a day or two is bearable, but make it a week and then the shit hits the fan.

The one thing you should bear in mind about earthquakes is that in many cases the aftershocks make more damage than the main one, because damage accumulates. Which means that critical infrastructure could take weeks to become fully operational.


>I think I can survive quite a while without the search engine

The search engine that holds the vast majority of the worlds traffic? The search engine that everyone is going to call on minutes after the earthquake to get news, but isn't going to be there so all the other search engines slow to a crawl. If Google search just disappeared for a week there would be a considerable number of businesses go out of business. You see it now in one off cases where a site is delisted and its traffic drops 99%.

That said, Google has datacenters around the nation and the world so that scenario is unlikely.


I wonder how it would play out if all the major search engines went down. I think people would start communicating on whatever sites they knew the URL for that were still up. Probably some ad-hoc manually curated indexes would pop up in comment threads on various sites and then a few people would probably aggregate these and host them on their local boxes.


> Yes, Gmail and Drive may cause all kinds of chaos but I think I can survive quite a while without the search engine and YouTube.

Perhaps you can, but how many companies are now wholly dependent on Google for their groupware functionality? What happens if you're one of the gaggle of people who make a living off YouTube?


In the grand scheme of things, not a lot of businesses use Apps for their email, but I'd hazard a guess that you're still looking at hundreds of millions of dollars in losses if that were to suddenly disappear.


It's the cascading service failures and related economic costs that would be the most damaging (and hardest to really quantify until a scenario really happens).


As with most people who reason about Google, you are off by at least two orders of magnitude in your estimate.


Wow, I had no idea that Google Apps were about 15% of Google's revenue. That is a way bigger than I would have guessed. (Hundreds of millions x 2 orders of magnitude is >= 10B, total revenue in 2014, 66B)


I'm not referring to Google revenue, I'm referring to productivity/revenue for the businesses using Apps day to day.


Maybe Google is distributed enough to stay up, but I'm pretty sure Microsoft and Amazon are not, and I doubt Google has the spare capacity to handle Azure load, much less Amazon load.


Try us :)


If Google utilization is really only 10% of capacity, that's pretty surprising and worrying for a host of other reasons.


Utilization and availability are not directly related. Much of their utilization is probably not super time critical and could be proportionately shed or suspended in an emergency situation like the one in question.

I bet Google could absorb 100% of the emergency evacuation of AWS in a pinch. Remember also that not 100% of services will be moved, and those that are will not be running at 100% capacity - everyone would be suspending their batch/analytics/warehousing jobs that week (or month).

EDIT: Also, lock in would stop all the redshift/dynamo/etc users from migrating, and would limit people to just what they could throw up on GCE/GAE.


Most large companies do/have done exactly that. Arguably 9/11 was the big catalyst for DR planning.

There were Wall St firms that literally had to get the military to escort them into Lower Manhattan in the days after to rescue servers, tapes, etc and cobble something together in a satellite office.

No one wants a repeat of that, and you'll notice subsequent disasters like Sandy have barely been a blip for most as a result of policy changes.

At this point basically any major company will/should have procedures in place for "perfect" DR, the ability for everyone to work from home indefinitely (and alternate offices/infrastructure waiting for the few people who need something special, like the special needs of a trading desk), as well as obviously having back up data centers with full replication.


Sure you can. Just look for the keys to the main breakers to those buildings. Of course, paying for that amount of vacation for 15 days is probably not entirely feasible for any company.


By 'systemic' I mean not confined to one company.


tsunami monkey?


The Microsoft campus in Redmond would most likely not be knocked over by the tsunami: a rather hilly Seattle is in the way, then there's the large Lake Washington, and then Redmond is another ~40 feet above the lake on the far side, plus another ~2 miles inland. A fair amount of the energy of the tsunami is going to be expended by the time the Microsoft campus gets salted. (Kirkland is west of Redmond, adjacent to Lake Washington, so it's a similar-but-somewhat-less-optimistic story there. Fremont is adjacent to Seattle and slightly inland, so it will be worse there.)

Of course, the infrastructure of the greater Seattle area is going to be trashed, but chances are good that the Redmond and Kirkland campuses of Microsoft and Google respectively would be intact.

Link to the inundation zone predicted for a magnitude 7.3 earthquake on Seattle: http://wa-dnr.s3.amazonaws.com/Publications/ger_ofr2003-14_t... This isn't even "the big one" as the OP describes, much less "the really big one", but it's a rough description of where the flooding will happen. Downtown Seattle (up and left of the word SEATTLE on the map, with streets in a dense diagonal grid) won't be strongly affected, because downtown Seattle is a hill. With an 8.5 or 9.0 earthquake, of course, Seattle will be much worse off, but there's still some hope that Redmond and Kirkland won't get too damaged.


Not only would there be significant downtime of major internet services, but lots of people would die as well!


Downtime of major internet services could also cause deaths elsewhere, as more industries become reliant on cloud services.

I could imagine hospitals losing access to health records, emergency responders losing access to mapping or route planning software, people losing access to Uber and not being able to get to the hospital because the taxi companies have gone out of business.

Of course all this stuff is supposed to have clean failover, but not all of it has had its mettle tested.


like Uber, but for once-in-an-epoch natural disasters


Man. In times like these—the northwest falling into the ocean or whatever—it's unimaginable to think about the sheer amount of data loss that could occur. I'd probably be really worried about that loss of data or, worse, the loss of services if millions of people suddenly died.


Isn't it the case that there is replication across data centers which are geologically spread apart?


Only if you had the foresight to set that up.


Well, I live here, so, yeah. I think the people who live here understand we're screwed, the point is what the larger effect will be.


I believe the parent comment was referring to the numerous hospitals or other critical services who rely on these infrastructures.



It's almost like you didn't read the article.


I read the whole thing in gripping detail with Mt St Helens out my office window... I was imagining the horror of not being able to blog about my death as the Tsunami was approaching...


Then you'll realise the human impact was mentioned repeatedly in the article - population in the affected regions, elderly people, school children, estimated death counts by different organizations. That was one main focus of the article - how many people such an event would kill.

Why is it necessary to prefix/suffix a comment on the article, with an "of course, people will die and that's obviously bad, we don't want people to die, is this enough mentioning of the people dying that we can say something else without you passive aggressively implying I don't care about the people dying?"


Just seemed like horrific lack of perspective. The infrastructure supporting transient internet technologies is way way down the list of importance if the Cascadia Subduction Zone slips.

I grew up in Central Oregon which is surrounded by fresh (geologically speaking) lava fields. I wonder if the Native Americans that were around when Mt Mazama was turned into Crater Lake worried about the disruption of their Obsidian tool making business.


I think the human toll goes without saying (well, until you said it). The technical impact is naturally of interest specifically to HN readers.


Especially since we know HN readers are sociopaths


Shh, nobody is supposed to know that.


That would be absolutely horrific, a loss that I can't even comprehend.

The loss of life would be sad too. /s


I believe you are giving reasons why our computational infrastructure needs to be further distributed. We should not be dependent on a small number of companies who wish to locate their resources in continental subduction zones.


That does seem likely, though as far as I know, AWS's biggest zone is located in Northern Virginia. And, I'm sure the AWS people have planned as much as they can for this eventuality. (Um, I hope.)


I doubt the datacenter's locations matter. The services at the bottom of the stack need constant ops to stay alive. With most of the engineers out, I expect barely a few days to go by before one of the essential services needs servicing.


For companies that size, the really important services probably have a distributed ops team, with a team in Europe/Asia alternating 12 hour oncall shifts with a team in North America. In an emergency, the non-North American team could take 24 hour shifts to keep the infrastructure alive.

Though of course if headquarters was really wiped off the map, there'd be huge problems with communication, tribal knowledge that only existed in the heads of senior engineers in Seattle, and so forth.


When supporting a service on the scale of say, EC2 and the rest of AWS, one would typically expect follow-the-sun support.


AWS West in Oregon are somewhat further inland from I-5. It would probably be impacted, but not to the same degree as the datacenters in other cities like Tukwila.


The loss of datacenters is irrelevant; the loss of people to keep the services running is the issue.


i think the datacenters will get soon to the status of national strategic infrastructure objects similar to bridges, power plants, etc... Given the distributed nature of the services i'd suppose the main threat though isn't from physical effect like earthquake, instead i think the main threat is introduction of something like StuxNet into say AWS (or highjacking the backdoor access that services like NSA already have there)


Sure, the AWS us-west datacenters would go down (Oregon and NorCal), but us-east (VA) is still the largest of all AWS regions. While Amazon is headquartered on the west coast, I sincerely doubt a failure of even both us-west regions would take out the others.

Ultimately it's up to the user: if they're going to put all their eggs in a us-west basket, they're out of luck if the west coast ends up under water.


People talk and talk about how The Cloud is about decentralizing things but really at the end of the day it's about centralizing everything with about a dozen vendors. And of course when price sensitivity causes attrition that will turn into 4 or 5 vendors.

I'm not sure I see how that really counts as 'more robust'.


There is an entire mountain range between Seattle and the ocean. I am curious how the Sound would affect the tsunami.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: