chez  ·   jad   ·  tsurc   ·  cat   ·  tarquin  ·  cryptoboy Weird People    
journal.terryfroy.com
PhotosWritings
 
admin

post to journal
edit journal entry

archives

june 2004
july 2004
august 2004
september 2004
october 2004
december 2004
  january 2005
february 2005
may 2005
june 2005
november 2005
  january 2006
february 2006
april 2006
may 2006
july 2006
august 2006
september 2006
october 2006
november 2006
  february 2007
april 2007
may 2007
june 2007
july 2007
august 2007
september 2007
october 2007
november 2007
december 2007
  january 2008
march 2008
april 2008
july 2008
november 2008
december 2008
  march 2009
july 2009
august 2009
september 2009
october 2009
november 2009
december 2009
  january 2010
march 2010
may 2010
august 2010
november 2010
  march 2013

contact me

e-mail [pgp key]
homepage
icq

daily news

bbc radio 1
bbc news worldwide

fun stuff

ntk
fuckedcompany.com
bofh archives
the onion

internet oracles

google [usenet]

pc entertainment

c64 radio
project ay
world of spectrum
mame [unix] [wip]
id software
unreal tournament

network stuff

iana
6bone
rfc editor
arin whois
apnic whois
ripe whois

essential software

fedora core
courier mta
pureftpd
user mode linux

seo fun

uk tv abroad
live uk tv
website design lincolnshire
sticky labels

 
Thursday, November 19, 2009

DomainKeys support in progress...
(posted at 07:36PM GMT)

I have been very very busy working on rolling out a usable DKIM implementation for both authenticated SMTP users (allowing them to sign mails from their domain using DKIM without making any changes to their own systems) and allowing for our border mailservers to validate the signatures of incoming mail for other DKIM users.

Currently signing all outbound spilsby.net mail just to see if anything important breaks... if all goes well, expect another announcement shortly!

Thursday, November 5, 2009

DNSSEC gotcha...
(posted at 09:07AM GMT)

It seems that all DNSSEC-signed records that are returned in a single batch (i.e. MX records) must have the same TTL as each other otherwise the TTL on the RRSIG won't match and therefore the data is marked as 'bogus' by any DNSSEC-compliant resolver.

A quick check of all zones served by us reveals that spilsby.net and spilsby.net.uk were the only zones affected; so no customers were affected but we did manage to break our own incoming mail for anyone who has deployed DNSSEC on their own resolvers and ISC's lookaside service.

It was probably all spam anyway :-P

Wednesday, November 4, 2009

Time to officially launch DNSSEC support!
(posted at 11:09PM GMT)

Since 10pm this evening, both spilsby.net resolvers are now validating all customer DNS against ISC's DLV lookaside service using DNSSEC; this provides full protection against DNS hijacking or spoofing attacks for those zones which have been registered with the service.

Naturally, we are also signing copies of all zones published on ns1/ns2/ns3.spilsby.net and have registered our own zones (spilsby.net/spilsby.net.uk) with ISC's DLV lookaside service.

We will be publishing DS resource records with all gTLD and ccTLD operators as and when they officially announce support for DNSSEC.

Nominet (.uk) plan to launch in early 2010 with Verisign (.com) planning to launch in 2012; as always, we are ahead of the pack :-)

UKFast
(posted at 12:44PM GMT)

Please put your hands up if you have heard of UKFast or do business with UKFast.

Yep, this is yet another SEO experiment!

Sunday, November 1, 2009

So many standards, so little time...
(posted at 09:52PM GMT)

One of my side projects at the moment is building an OpenWRT-based replacement firmware for the Netgear DG834G v2/v4/v5 routers which is what Spilsby Internet Solutions currently ships to end users.

The primary motivation behind this is to provide a software-based upgrade path to our users in order for them to easily adopt IPv6 which we currently support on our ADSL/WBC platform; it wouldn't surprise me if Netgear, the proponents of 'open source routers' but distributors of 'closed source binary blobs', decide not to release their own IPv6-enabled firmware for these routers and will require users to purchase new hardware.

Some additional features are also on the roadmap which will benefit us; primarily the logging and reporting of ADSL line stats (attenuation, noise, etc, etc) which should make diagnosing and reporting faults to BT Wholesale so much easier.

The other reason why I'm working on this is because there is still some confusion about how IPv6 addresses/prefixes/nameservers are going to be propogated to the end-users' CPE via PPP - the general consensus to obtain an IPv6 address on the WAN interface is for the remote server to advertise a prefix via IPv6 Router Advertisement but this allows for IPv6 address spoofing as this address can be chosen by the client.

Prefixes/nameservers can only be passed via DHCPv6 as there are no LCP messages in the current PPP RFCs that cater for IPv6 prefixes/nameservers; the end result being that this needs to be implemented on both client and server ends - with no reference implementation for either currently endorsed or sponsored by the IETF.

The problem with DHCPv6 is that it works based on the link-local address which is assigned to the end-user and provides prefix delegation, nameservers and all other information based solely on the value of that link-local address; according to the author of MPD, it is the preferred way of assigning global IPv6 addresses and other information.

Unfortunately, this Daily WTF article highlights what is wrong with this approach - if the end-user can spoof their MAC address, they will obtain a different link-local address from the IPv6CP negotiation, which in turn, will result in them obtaining a different global IPv6 address from DHCPv6 - what happens if the user spoofs the MAC address of an existing user who is currently not connected ?

The only way this is going to work is if the link-local address is assigned by the server rather than being chosen by the client - the server can override a client preference but it is 'discouraged' by the RFCs.

This always makes me question myself; RFC documents are written by groups of very intelligent people who know their subject intimately - therefore, when I find myself disagreeing with an RFC, I almost always accuse myself of not knowing enough about the subject and sit down and read the RFC again.

Unfortunately, I have done this several times with this RFC over the last six weeks or so and I keep coming to the conclusion that the authors did not consider the possibility of 'spoofing' as per the Daily WTF article above - an attack which seems highly probable given that if it works with IPv4, it will work with IPv6 as well.

It is my honest opinion that the OSS world is in for a world of hurt when it realizes that its' IPv6 'support' is next to useless in so many ways; with commercial software being just as bad.

 
slashdot

EPA Will Make Polluters Pay To Clean Up Two 'Forever Chemicals'

Linus Torvalds on 'Hilarious' AI Hype

Microsoft's VASA-1 Can Deepfake a Person With One Photo and One Audio Track

Indian IT Outsourcing Firms Cut 60,000 Jobs in First Layoffs in 20 Years

Porn Sites Face Strict EU Rules, Commission Says

Meta's Not Telling Where It Got Its AI Training Data

Microsoft Does Not Want You To Use iPerf3 To Measure Network Performance on Windows

Google To Employees: 'We Are a Workplace'

Samsung Shifts To Emergency Mode With 6-day Work Week for Executives

Windows 10 Will Start Pushing Users To Use Microsoft Accounts

Apple Removes WhatsApp, Threads and Telegram From China App Store

Chinese Cities Are Sinking Rapidly

FBI Says Chinese Hackers Preparing To Attack US Infrastructure

Northrop Grumman Working With SpaceX On US Spy Satellite System

Reddit Is Taking Over Google

the register

Sacramento airport goes no-fly after AT&T internet cable snipped

NASA solar sail to be Siriusly visible in orbit from Earth

Qt Ubuntu 24.04 betas show that there's room to innovate

AI energy draw from Chicago datacenters to rise ninefold

WhatsApp, Threads, more banished from Apple App Store in China

Unintended acceleration leads to recall of every Cybertruck produced so far

A quarter of 5-7 year olds now use smartphones, says regulator

Cybercriminals threaten to leak all 5 million records from stolen database of high-risk individuals

Germany cuffs alleged Russian spies over plot to bomb industrial and military targets

Wing Commander III changed how the copy hotkey works in Windows 95

Some smart meters won't be smart at all once 2/3G networks mothballed

Your trainee just took down our business and has no idea how or why

UK unions publish AI bill to protect workers from 'risks and harms' of tech

Huawei's latest flagship smartphone contains no world-shaking silicon surprises

Oracle scores big win with Fujitsu Japan for its Alloy partner cloud

Meta lets Llama 3 LLM out to graze, claims it can give Google and Anthropic a kicking

US Air Force says AI-controlled F-16 fighter jet has been dogfighting with humans

Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ centers

Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims

Stability AI decimates staff just weeks after CEO's exit

IBM accused of cheating its own executive assistants out of overtime pay

Google fires 28 staff after sit-in protest against Israeli cloud deal ends in arrests

Feds hit coding boot camp with big fine for allegedly conning students

Microsoft aims to triple datacenter capacity to fuel AI boom

House passes bill banning Uncle Sam from snooping on citizens via data brokers

October 2025 will be a support massacre for a bunch of Microsoft products

Fraudsters abused Apple Stores' third-party pickup policy to phish for profits

911 goes MIA across multiple US states, cause unclear

TSMC expects customers to pay more for chips fabbed overseas

NASA will send astronauts to patch up leaky ISS telescope

185K people's sensitive data in the pits after ransomware raid on Cherry Health

Microsoft claims it didn't mean to inject Copilot into Windows Server 2022 this week

Micron scores $6.1B CHIPS Act cash for New York and Idaho fabs

Google laying off staff again and moving some roles to 'hubs,' freeing up cash for AI investments

EU tells Meta it can't paywall privacy

Novelty flip phone strips out almost every feature possible to be as boring as possible

Prolific phishing-made-easy emporium LabHost knocked offline in cyber-cop op

Debian spices up APT package manager with a dash of color, squishes ancient bug

AI PCs are here but a killer application for biz users? Nope

Valkey publishes release candidate and attracts new backer

Cisco creates architecture to improve security and sell you new switches

Europe gives TikTok 24 hours to explain 'addictive and toxic' new app

Singapore infosec boss warns China/West tech split will be bad for interoperability

Mars helicopter sends final message, but will keep collecting data

Taiwanese film studio snaps up Chinese surveillance camera specialist Dahua

Software glitch saw Aussie casino give away millions in cash

HPE sues China's Inspur Group over server patents

Hugely expanded Section 702 surveillance powers set for US Senate vote

Snowmobile, Amazon's truck-powered migration service, reaches the end of the road

Uncle Sam earmarks $54M of CHIPS funding for small-biz semiconductor boffinry

 

Linux

Apache

PHP