logoalt Hacker News

qmryesterday at 5:07 PM6 repliesview on HN

Gah, just when you think you can trust time.nist.gov

Suggestions from the community for more reliable alternatives?


Replies

evanrileyyesterday at 6:38 PM

> Gah, just when you think you can trust time.nist.gov

You still can...

If you're that considered about 5 microseconds: Build your own Stratum 1 time server https://github.com/geerlingguy/time-pi

or just use ntppool https://www.ntppool.org/en/

show 2 replies
ianburrellyesterday at 6:56 PM

Most places that need accurate time get it from GPS. That is 10-100 ns.

Also, you can use multiple NIST servers. They have ones in Fort Collins, CO and Gaithersburg, MD. Most places shouldn't use NIST directly but Stratum 1 name servers.

Finally, NTP isn't accurate enough, 10-100 ms, for microsecond error to matter.

ssl-3yesterday at 9:32 PM

Yes.

Use NTP with ≥4 diverse time sources, just as RFC 5905 suggests doing. And use GPS.

(If you're reliant upon only one source of a thing, and that thing is important to you in some valuable way, then you're doing it wrong. In other words: Backups, backups, backups.)

ajkjkyesterday at 6:55 PM

their handling it responsibly seems like more evidence for trusting them, not less?

vel0cityyesterday at 8:24 PM

Use the other servers as well: https://tf.nist.gov/tf-cgi/servers.cgi

For instance, time-a-wwv.nist.gov.

One should configure a number of different NTP sources instead of just a single host.

monster_truckyesterday at 6:45 PM

I'm more concerned about what you think they did to earn your trust in the first place