home.social

#ripe84 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ripe84, aggregated by home.social.

  1. #ipv6
    #avm
    #ripe84
    stadt-bremerhaven.de/fritzos-7
    ripe.net/community/wg/active-w
    ripe84.ripe.net/wp-content/upl

    Change log:
    Internet: Übertragung von IPv6-Daten über einen Wireguard VPN-Tunnel
    Verbesserung Zufällige Berechnung der Unique Local Address (ULA, IPv6) nach RFC 4193
    Verbesserung Kommunikation zu allen AVM-Diensten über IPv6 mit Fallback auf IPv4

  2. Et pour bien finir le #RIPE84, une notification du RIPE que deux participant·es ont signalé qu'ils avaient été testés positifs au retour :-(

    #testons

  3. Taking the first of my two planned post #RIPE84 #covid tests to make sure I'm still negative.

    Status: still negative.

  4. And that's the end of #RIPE84 for me. Back at home, gonna relax and recover from a week of socializing. Saw more people this week than I did in the last two years.

    #NapTime

  5. Cool, cool, cool. Time to make a report about a CoC violation. Way to end the meeting.

    #RIPE84

  6. Technical report on #RIPE84 : we had two 10 G/s uplinks (Deutsche Telecom), typically 120 Mb/s used (a maximum at 721 M/s, 600 being IPv6).

    45 WiFi access points.

  7. The test: setting up a HTTPS site, asking a certificate and revoking it. Then, running a paid ad on it and see how many clients connect.

    Answer: around 80 % of clients happily accept the revoked certificate.

    #RIPE84

  8. Now, Geoff Huston tests certificate revocation. In March, many russian certificates were revoked by CAs, as sanctions. Did it work?

    Spoiler: no. Revocation does not work.

    #RIPE84

  9. Beim RIPE84-Treffen gab es viel Anerkennung dafür, wie Netzwerker in der Ukraine ihr Netz behüten. Ein großer Vorteil ist die ausgeprägte Dezentralität.
    Weitgehend stabil: Ausgeprägte Dezentralität schützt das Internet in der Ukraine
  10. About the "Insufficient identity data for matching" slide, I'm thinking that the mess of online identities (and the country-specific variations) is the last protection we have for our personal data in the EU.

    (As usual, Estonia, the digital paradise, is the worst, privacy-wise.)

    #RIPE84 #eIDAS

  11. The european directive NIS2 may force this ID checking by domain name registries. #RIPE84

  12. The Web site of the project (checking domain name registrants with #eIDAS) regeid.eu/

    #RIPE84

  13. The speaker criticizes Germany for being the only country in the EU choosing the most privacy-protecting provisions of #eIDAS, complicating the sevice.

    May be the Germans have some historical experience about the risk of identity controls?

    #RIPE84

  14. Good morning, Berlin !
    Fifth and last day of #RIPE84.

    First talk this morning, about #eIDAS (european regulation about online identity): the european authorities want domain name registries to double-check the state identity of the registrants.

  15. Morning after the #RIPE84 gala dinner, doing my final selftest during the meeting.

    (CW: #selfie, eye contact)

  16. In the EU, 71 to 87 % #DNS queries go through the same AS (probably the ISP resolver). 4 to 26 % (depending on the exact way you measure) go through Google. As you can see, the actual answer varies a lot depending on the design of the experiment. (Big difference enterprise networks vs. consumer)

    #RIPE84

  17. Measurement of the "market" share of #DNS resolvers (the European Commission's call for proposals for the #DNS4EU project lies when claiming that the US public resolvers have the majority of traffic).

    #RIPE84

  18. Ugh! Surprise (and unrelated) cat picts.

    Please don't do that!

    #RIPE84 #DNS WG

  19. Remote presenter, remote questioner in the #DNS Working Group session. Room is still pretty full with onsite attendees. Nice setup!

    #RIPE84

  20. If you examine your network traffic, #DoQ runs by default over port 853 (like DNS over DTLS, which nobody ever used).

    #RIPE84

  21. And now #DNS working group. Let's start with Sara Dickinson presenting (remotely) #DoQ (DNS over #QUIC). DNS over TLS is boring, DNS over HTTPS is too mainstream, let's do it over QUIC. The world needs more protocols for encrypted DNS :-)

    #RIPE84

  22. Job Snijders teaches us how to debug #RPKI issues at #RIPE84. I'm afraid it wll be complicated.

    #BGP

  23. Now, Ignas Bagdonas benchmarks #BGPsec performance. On his lab setup, it is awfully slow.

    Interesting explanations about software optimisation. BGPsec uses SHA-2 (hard for memory, cool for the CPU) and ECDSA (the opposite): do them in parallel (but the BGPsec format of data does not make it easy).

    #RIPE84 #BGP