home.social

#ietf119 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ietf119, aggregated by home.social.

fetched live
  1. Members of the @intarchboard the Internet Engineering Steering Group, the IETF Administration LLC Board of Directors, and the IETF Trust were announced just before the recent #IETF119 meeting, where several of the groups met in-person for the first time: ietf.org/blog/nomcom-announcem

  2. Members of the @intarchboard the Internet Engineering Steering Group, the IETF Administration LLC Board of Directors, and the IETF Trust were announced just before the recent #IETF119 meeting, where several of the groups met in-person for the first time: ietf.org/blog/nomcom-announcem

  3. And this is the end of #IETF119, you may now drink beers and cuddle koalas.

    #Brisbane

  4. And this is the end of #IETF119, you may now drink beers and cuddle koalas.

    #Brisbane

  5. Also, proposal to make #DNSSEC configuration easier. The difficulty is how to do it easier for the good guys without makeing it also easier for an attacker.

    #IETF119

  6. Also, proposal to make #DNSSEC configuration easier. The difficulty is how to do it easier for the good guys without makeing it also easier for an attacker.

    #IETF119

  7. Analysis of existing CDS/CDNSKEY records in the wild. They are sometimes broken, sometimes in funny ways (authortative name servers not returning the samed CDS...)

    Why would a domain in .com publish a CDS (.com does not handle CDS) and a broken one (does not match the keys)?

    #DNS #DNSSEC #IETF119

  8. Analysis of existing CDS/CDNSKEY records in the wild. They are sometimes broken, sometimes in funny ways (authortative name servers not returning the samed CDS...)

    Why would a domain in .com publish a CDS (.com does not handle CDS) and a broken one (does not match the keys)?

    #DNS #DNSSEC #IETF119

  9. Not all #DNS data were created equal. A project for a new ranking of DNS data credibility.Top: DNSSEC-signed data. Bottom: glue.

    #IETF119

  10. Not all #DNS data were created equal. A project for a new ranking of DNS data credibility.Top: DNSSEC-signed data. Bottom: glue.

    #IETF119

  11. Possible change in the process for crypto recommendations (the current one is too slow).
    The proposal will require more RFCs, but smaller.
    (PQ algorithms are ready to pounce.)

    #IETF119 #DNS

  12. Possible change in the process for crypto recommendations (the current one is too slow).
    The proposal will require more RFCs, but smaller.
    (PQ algorithms are ready to pounce.)

    #IETF119 #DNS

  13. Discussion post-BoF about the DELEG (or DD) project, "the most significant change in the #DNS since DNSSEC"

    #braceYourself #IETF119

  14. Discussion post-BoF about the DELEG (or DD) project, "the most significant change in the #DNS since DNSSEC"

    #braceYourself #IETF119

  15. OK, now, we talk about using CBOR in BGP messages and signing them with PQ algorithms.

    #ThatEscalatedQuickly #IETF119

  16. OK, now, we talk about using CBOR in BGP messages and signing them with PQ algorithms.

    #ThatEscalatedQuickly #IETF119

  17. Protocol design: what is the difference between a good feature and a bad feature?

    A good feature is something I want. A bad feature is something you want.

    #IETF119

  18. Protocol design: what is the difference between a good feature and a bad feature?

    A good feature is something I want. A bad feature is something you want.

    #IETF119

  19. "I don't say it is impossible, just that it is harder than changing the engines of the plane during the flight."

    #IETF119

  20. "I don't say it is impossible, just that it is harder than changing the engines of the plane during the flight."

    #IETF119

  21. There is a BGPsec, signing the AS all along the path. But it is not widely deployed (cryptography is hard).

    #IETF119

  22. There is a BGPsec, signing the AS all along the path. But it is not widely deployed (cryptography is hard).

    #IETF119

  23. As everyone one (and his dog) knows, BGP has a security issue: how to be sure the peer announcing a route is right?

    Your neighbor may lie!

    But improving the security requires a way to know the truth: can AS X announce prefix Y? This can be very hard to tell.

    #IETF119

  24. As everyone one (and his dog) knows, BGP has a security issue: how to be sure the peer announcing a route is right?

    Your neighbor may lie!

    But improving the security requires a way to know the truth: can AS X announce prefix Y? This can be very hard to tell.

    #IETF119

  25. You can add new attributes to carry between BGP routers, with interesting possibilities and some possibilities of (imperfect) control over their propagation.

    And a problem may appear in routers downsream (since routers may have forwarded incorrect messages). Remember "attribute 99".

    Because BGP is stateful, things you send to a peer may be remembered, may be for ever.

    #IETF119

  26. You can add new attributes to carry between BGP routers, with interesting possibilities and some possibilities of (imperfect) control over their propagation.

    And a problem may appear in routers downsream (since routers may have forwarded incorrect messages). Remember "attribute 99".

    Because BGP is stateful, things you send to a peer may be remembered, may be for ever.

    #IETF119

  27. And BGP is *the* backbone of the Internet. If it breaks, everything breaks. Hence the sensitivity of BGP people with respect to new proposals.

    Some even suggest to *stop* adding things to BGP.

    (Is BGP Turing-complete? Can you do arbitrary computations with a set of BGP routers?)

    #IETF119

  28. And BGP is *the* backbone of the Internet. If it breaks, everything breaks. Hence the sensitivity of BGP people with respect to new proposals.

    Some even suggest to *stop* adding things to BGP.

    (Is BGP Turing-complete? Can you do arbitrary computations with a set of BGP routers?)

    #IETF119

  29. BGP carries routes (obviously) but also VPN config, firewall rules ("a terrifying way to blow up your network"), link state, etc.

    Unlike the DNS, which uses the camel metaphor, BGP people use the "dump truck" metaphor: too many things on BGP.

    #IETF119

  30. BGP carries routes (obviously) but also VPN config, firewall rules ("a terrifying way to blow up your network"), link state, etc.

    Unlike the DNS, which uses the camel metaphor, BGP people use the "dump truck" metaphor: too many things on BGP.

    #IETF119

  31. Because of its success, like DNS, BGP is sometimes abused. "It works, so let's use BGP. to distribute stuff"

    #IETF119

  32. Because of its success, like DNS, BGP is sometimes abused. "It works, so let's use BGP. to distribute stuff"

    #IETF119

  33. Deep Dive in #BGP at #IETF119 : "reviewing the past and exploring the future"

    (The current version of BGP was deployed in 1994. It received many extensions since.)

  34. Deep Dive in #BGP at #IETF119 : "reviewing the past and exploring the future"

    (The current version of BGP was deployed in 1994. It received many extensions since.)

  35. Talk about "local-first" software. Funny that it has a name since all software should be like that (but the Power of the Cloud is so Strong that, when you don't depend on the cloud, you need a catchy name to describe that).

    #IETF119

  36. Talk about "local-first" software. Funny that it has a name since all software should be like that (but the Power of the Cloud is so Strong that, when you don't depend on the cloud, you need a catchy name to describe that).

    #IETF119

  37. A meeting about Internet decentralization starting with an analysis of Internet regulation in China???

    #IETF119

  38. A meeting about Internet decentralization starting with an analysis of Internet regulation in China???

    #IETF119

  39. My experimental authoritative name server deployed on the IETF network for the #IETF119 hackathon receives requests for sl/ANY (it rejects them).
    I was wondering why someone is interested in Sierra Leone but it turns out its authoritative name servers accept QTYPE=ANY and return > 5 kB of data, with several keys, signatures and even NSEC records to prove that they have returned everything they know.

    #DNS

  40. My experimental authoritative name server deployed on the IETF network for the #IETF119 hackathon receives requests for sl/ANY (it rejects them).
    I was wondering why someone is interested in Sierra Leone but it turns out its authoritative name servers accept QTYPE=ANY and return > 5 kB of data, with several keys, signatures and even NSEC records to prove that they have returned everything they know.

    #DNS

  41. Good morning, Brisbane! Fourth day of #IETF119. Let's go to work by boat.

  42. Good morning, Brisbane! Fourth day of #IETF119. Let's go to work by boat.

  43. For instance, long talk about "use cases" which are just "AI could do that [path optimisation, configuration creation, user assistance, etc] intelligently" without any explanation on how, and without experiments to see if it really can do that.
    "Use cases" are not an excuse to stay at the "I want a pony" level.

    #IETF119

  44. For instance, long talk about "use cases" which are just "AI could do that [path optimisation, configuration creation, user assistance, etc] intelligently" without any explanation on how, and without experiments to see if it really can do that.
    "Use cases" are not an excuse to stay at the "I want a pony" level.

    #IETF119

  45. Lots of hand waving "AI can do this" "LLM can do that" "AI will make the system smarter" but few actual results.

    Not really the expected level of an IETF meeting.

    #IETF119

  46. Lots of hand waving "AI can do this" "LLM can do that" "AI will make the system smarter" but few actual results.

    Not really the expected level of an IETF meeting.

    #IETF119

  47. "LLM and security"

    "LLM have a high level of decision-making ability"

    Challenges:
    * no data available to train the LLM (or the humans, may I say)
    * training does not help against 0-day attacks
    * time and ressources for the training

    #IETF119

  48. Disturbed by a talk about structured data (flows in a dDoS attack) turned into something looking like natural language so the guy could use natural language processing to process it...

    #IETF119