#ietf119 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ietf119, aggregated by home.social.
-
-
Members of the @intarchboard the Internet Engineering Steering Group, the IETF Administration LLC Board of Directors, and the IETF Trust were announced just before the recent #IETF119 meeting, where several of the groups met in-person for the first time: https://www.ietf.org/blog/nomcom-announcement-2024/
-
Members of the @intarchboard the Internet Engineering Steering Group, the IETF Administration LLC Board of Directors, and the IETF Trust were announced just before the recent #IETF119 meeting, where several of the groups met in-person for the first time: https://www.ietf.org/blog/nomcom-announcement-2024/
-
Weekend Reads
* DNS at IETF 119 https://www.potaroo.net/ispcol/2024-03/dns119.html
* DNS HTTPS RR ecosystem https://arxiv.org/abs/2403.15672
* US cyber force proposal https://www.fdd.org/analysis/2024/03/25/united-states-cyber-force/
* Port forwarding service risks https://arxiv.org/abs/2403.16060
* US DHS incident reporting proposal https://public-inspection.federalregister.gov/2024-06526.pdf -
Weekend Reads
* DNS at IETF 119 https://www.potaroo.net/ispcol/2024-03/dns119.html
* DNS HTTPS RR ecosystem https://arxiv.org/abs/2403.15672
* US cyber force proposal https://www.fdd.org/analysis/2024/03/25/united-states-cyber-force/
* Port forwarding service risks https://arxiv.org/abs/2403.16060
* US DHS incident reporting proposal https://public-inspection.federalregister.gov/2024-06526.pdf -
The Internet Last Week
* IETF meeting 119
https://www.ietf.org/how/meetings/119/
* DataDock Strasbourg water leak outage
https://status.plusserver.com/incidents/s6lzkwsc3tbj
https://www.server4you.com/
https://status.racknerd.com/incident/1848
* Redis licensing change
https://redis.com/blog/redis-adopts-dual-source-available-licensing/
https://redict.io/posts/2024-03-22-redict-is-an-independent-fork/
* Threads joins the fediverse
https://engineering.fb.com/2024/03/21/networking-traffic/threads-has-entered-the-fediverse/ -
-
-
Also, proposal to make #DNSSEC configuration easier. The difficulty is how to do it easier for the good guys without makeing it also easier for an attacker.
-
Also, proposal to make #DNSSEC configuration easier. The difficulty is how to do it easier for the good guys without makeing it also easier for an attacker.
-
Not all #DNS data were created equal. A project for a new ranking of DNS data credibility.Top: DNSSEC-signed data. Bottom: glue.
-
Not all #DNS data were created equal. A project for a new ranking of DNS data credibility.Top: DNSSEC-signed data. Bottom: glue.
-
Possible change in the process for crypto recommendations (the current one is too slow).
The proposal will require more RFCs, but smaller.
(PQ algorithms are ready to pounce.) -
Possible change in the process for crypto recommendations (the current one is too slow).
The proposal will require more RFCs, but smaller.
(PQ algorithms are ready to pounce.) -
Discussion post-BoF about the DELEG (or DD) project, "the most significant change in the #DNS since DNSSEC"
-
Discussion post-BoF about the DELEG (or DD) project, "the most significant change in the #DNS since DNSSEC"
-
OK, now, we talk about using CBOR in BGP messages and signing them with PQ algorithms.
-
OK, now, we talk about using CBOR in BGP messages and signing them with PQ algorithms.
-
Protocol design: what is the difference between a good feature and a bad feature?
A good feature is something I want. A bad feature is something you want.
-
Protocol design: what is the difference between a good feature and a bad feature?
A good feature is something I want. A bad feature is something you want.
-
"I don't say it is impossible, just that it is harder than changing the engines of the plane during the flight."
-
"I don't say it is impossible, just that it is harder than changing the engines of the plane during the flight."
-
There is a BGPsec, signing the AS all along the path. But it is not widely deployed (cryptography is hard).
-
There is a BGPsec, signing the AS all along the path. But it is not widely deployed (cryptography is hard).
-
As everyone one (and his dog) knows, BGP has a security issue: how to be sure the peer announcing a route is right?
Your neighbor may lie!
But improving the security requires a way to know the truth: can AS X announce prefix Y? This can be very hard to tell.
-
As everyone one (and his dog) knows, BGP has a security issue: how to be sure the peer announcing a route is right?
Your neighbor may lie!
But improving the security requires a way to know the truth: can AS X announce prefix Y? This can be very hard to tell.
-
You can add new attributes to carry between BGP routers, with interesting possibilities and some possibilities of (imperfect) control over their propagation.
And a problem may appear in routers downsream (since routers may have forwarded incorrect messages). Remember "attribute 99".
Because BGP is stateful, things you send to a peer may be remembered, may be for ever.
-
You can add new attributes to carry between BGP routers, with interesting possibilities and some possibilities of (imperfect) control over their propagation.
And a problem may appear in routers downsream (since routers may have forwarded incorrect messages). Remember "attribute 99".
Because BGP is stateful, things you send to a peer may be remembered, may be for ever.
-
And BGP is *the* backbone of the Internet. If it breaks, everything breaks. Hence the sensitivity of BGP people with respect to new proposals.
Some even suggest to *stop* adding things to BGP.
(Is BGP Turing-complete? Can you do arbitrary computations with a set of BGP routers?)
-
And BGP is *the* backbone of the Internet. If it breaks, everything breaks. Hence the sensitivity of BGP people with respect to new proposals.
Some even suggest to *stop* adding things to BGP.
(Is BGP Turing-complete? Can you do arbitrary computations with a set of BGP routers?)
-
BGP carries routes (obviously) but also VPN config, firewall rules ("a terrifying way to blow up your network"), link state, etc.
Unlike the DNS, which uses the camel metaphor, BGP people use the "dump truck" metaphor: too many things on BGP.
-
BGP carries routes (obviously) but also VPN config, firewall rules ("a terrifying way to blow up your network"), link state, etc.
Unlike the DNS, which uses the camel metaphor, BGP people use the "dump truck" metaphor: too many things on BGP.
-
Because of its success, like DNS, BGP is sometimes abused. "It works, so let's use BGP. to distribute stuff"
-
Because of its success, like DNS, BGP is sometimes abused. "It works, so let's use BGP. to distribute stuff"
-
Talk about "local-first" software. Funny that it has a name since all software should be like that (but the Power of the Cloud is so Strong that, when you don't depend on the cloud, you need a catchy name to describe that).
-
Talk about "local-first" software. Funny that it has a name since all software should be like that (but the Power of the Cloud is so Strong that, when you don't depend on the cloud, you need a catchy name to describe that).
-
A meeting about Internet decentralization starting with an analysis of Internet regulation in China???
-
A meeting about Internet decentralization starting with an analysis of Internet regulation in China???
-
-
-
OK, let's decentralize the Internet at #IETF119. Meeting of the DIN research group https://datatracker.ietf.org/meeting/119/materials/agenda-119-dinrg-05
-
OK, let's decentralize the Internet at #IETF119. Meeting of the DIN research group https://datatracker.ietf.org/meeting/119/materials/agenda-119-dinrg-05
-
My experimental authoritative name server deployed on the IETF network for the #IETF119 hackathon receives requests for sl/ANY (it rejects them).
I was wondering why someone is interested in Sierra Leone but it turns out its authoritative name servers accept QTYPE=ANY and return > 5 kB of data, with several keys, signatures and even NSEC records to prove that they have returned everything they know. -
My experimental authoritative name server deployed on the IETF network for the #IETF119 hackathon receives requests for sl/ANY (it rejects them).
I was wondering why someone is interested in Sierra Leone but it turns out its authoritative name servers accept QTYPE=ANY and return > 5 kB of data, with several keys, signatures and even NSEC records to prove that they have returned everything they know. -
Good morning, Brisbane! Fourth day of #IETF119. Let's go to work by boat.
-
Good morning, Brisbane! Fourth day of #IETF119. Let's go to work by boat.
-
For instance, long talk about "use cases" which are just "AI could do that [path optimisation, configuration creation, user assistance, etc] intelligently" without any explanation on how, and without experiments to see if it really can do that.
"Use cases" are not an excuse to stay at the "I want a pony" level. -
For instance, long talk about "use cases" which are just "AI could do that [path optimisation, configuration creation, user assistance, etc] intelligently" without any explanation on how, and without experiments to see if it really can do that.
"Use cases" are not an excuse to stay at the "I want a pony" level. -
Lots of hand waving "AI can do this" "LLM can do that" "AI will make the system smarter" but few actual results.
Not really the expected level of an IETF meeting.
-
Lots of hand waving "AI can do this" "LLM can do that" "AI will make the system smarter" but few actual results.
Not really the expected level of an IETF meeting.
-
"LLM and security"
"LLM have a high level of decision-making ability"
Challenges:
* no data available to train the LLM (or the humans, may I say)
* training does not help against 0-day attacks
* time and ressources for the training -
Disturbed by a talk about structured data (flows in a dDoS attack) turned into something looking like natural language so the guy could use natural language processing to process it...