#oarc40 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #oarc40, aggregated by home.social.
-
I've just published a new version of my #DNS TTL extension for #EPP. I've asked to present it to the #regext working group at the next #IETF meeting in Yokohama to request WG adoption. Apparently it was mentioned during last week's #OARC40 meeting so there's evidently still interest! https://www.ietf.org/archive/id/draft-regext-brown-epp-ttl-04.html
-
The Internet Last Week
* Microsoft patch Tuesday
https://msrc.microsoft.com/update-guide/releaseNote/2023-Feb
https://www.akamai.com/blog/security-research/akamai-perspective-patch-tuesday-february-2023
* US T-Mobile outage
https://www.reuters.com/business/media-telecom/t-mobile-down-thousands-users-us-downdetector-2023-02-14/
https://puck.nether.net/pipermail/outages/2023-February/014641.html
* NANOG 87 / OARC 40
https://www.nanog.org/events/nanog-87/
https://indico.dns-oarc.net/event/46/
* Superbowl traffic trends
https://blog.cloudflare.com/super-bowl-lvii/
#Microsoft #TMobile #NANOG87 #OARC40 #Superbowl -
"Realtime DNS Exfiltration Detection in Recursive Resolvers" by David Rodriguez
There are many free software to create a #DNS tunnel (for instance iodine). (Nice Perl code to illustrate.)
-
-
It created a huge discussion, both on Zoom and on Mattermost. People love RFC and care about them, so it is always passionate. There are even people who criticize the fact that some people comment on RFC.
-
"Measuring TTL Violation of DNS Resolvers at scale" by Tijay Chung
Measuring is not obvious (there is more than one resolver between the Web browser and the authoritative server.)
Almost 10 % of the resolvers increase the very short TTLs (one minute).
-
-
"Guaranteeing the integrity of DNS records using PKIX Certificates" by Hyeonmin Lee
Still less than 1 % SLD signed.
Solution : use PKIK certificates because everyone has one.
-
Preparing to speak remotely at #OARC40.
On Ubuntu, screen sharing in Zoom does not work with the default Wayland, but works with Xorg. But it is the opposite for virtual background :-) -
-
-
"DareShark: Detecting and Measuring Security Risks of Hosting-Based Dangling Domains" by Xiang Li, at #OARC40.
It's about domain name hijacking (I like his "use-after-free", it's basically the "subdomain attack").
-
-
-
"Operational Experience with DNSSEC signed zones" by Shumon Huque : his experience at Salesforce (which also owns Heroku, Slack, etc)
-
"Research Agenda for a Post-Quantum DNSSEC" by Andrew Fregly
I cannot find Schrödinger's cat on the first slide.
-
-
#OARC40 starting in a few minutes.
https://indico.dns-oarc.net/event/46/
#LoveDNS #DNS