I look forward to reading that as a fellow DNS Engineer that works at large scale and has a passion for security.
HN user
devnull42
Sooo they are running RPZ and calling it a product....?
I saw a company asking for 10 years OpenStack development experience.
The initial release of OpenStack was 7 years ago.
Cant make this shit up.
.IO is historically terrible and seem to have no idea what they are doing. Being it downtime, security or general DNS policy.
nice but dig +trace would be really really nice to add since dig alone doesnt help much with troubleshooting.
Correct the actual key change isn’t until next month however yesterday there was a change in response size from the root servers.
It appears that the issue at first impacted all servers in the anycast pool however eventually it only impacted servers ns-a2 and ns-a4. Those servers started returning NXDOMAINs. I am wondering if this was related to the root server key change yesterday. .IO seems to struggle with basic DNS engineering. We are seeing stabilization except for minor issues still on one of the gTLD servers.
It appears that the issue at first impacted all servers in the anycast pool however eventually it only impacted servers ns-a2 and ns-a4. Those servers started returning NXDOMAINs. I am wondering if this was related to the root server key change yesterday. .IO seems to struggle with basic DNS engineering.
This is a fantastic guide. Thanks for putting it up!
Whats the issue with that statement. It is early and I haven't had my coffee yet but I am a security researcher and while I have my questions about his past many of my counter parts in the UK have raised some very very valid questions about the legitimacy of the allegations against him. So unless I am missing a grammatical or syntactical error whats the issue with that statement?
Probably wouldn’t be terribly hard to generate that data.
It would still just be ANY queries for cpsc.gov.
That isn't how the data sales work at all.
I ordered a System76 laptop about 4 years ago for work as my day to day machine. Almost immediately the HDMI port broke and I was pretty bummed out. I emailed their support hoping to get it repaired but they never actually fixed it. Since then I have never gone back to them. I want them to be great so badly but that just hasn’t been my experience.
Amazon is directly selling these not acting as a third party. They are the counterfeiters in this case totally different than buying something from someone on ebay and ebay facilitating the deal.
Although Cloudflare recently suffered from a widely-reported security incident, their response was impressively fast and transparent.
Really....seemed like they massively downplayed to me.
Yeah pretty much.
got her salary adjusted to median position salary because she was a woman
>Really?
Yes really. She said that there was a meeting where a manager actually made a comment about underpaying her because she was a women then they immediately freaked out.
>anyone not a cis-male only gets there to meet the criteria of a diversity program.
As far as this goes there was a specific initiative that was in place to cater linux to women and we were told to interview and hire them. After hiring many of these candidates and having pretty bad results we had to stop giving that program preferential treatment.
Also for the record my friend who I referred to with the pay discrepancy was a fantastic engineer who was not hired through that program and she hated the program because it tried to make linux all girlie which she found offensive and demeaning.
Wow this has been the opposite of my experience. I have seen many cases where women are fast tracked or given more opportunities as engineers because of diversity programs. There was one case where a female engineer got her salary adjusted to median position salary because she was a woman and they didn’t want the appearance of underpaying a female engineer, meanwhile I am 16% below company median for my position.
As a former support racker I can tell you that while those might have fall outside our offical spheres of support you would have had no issues getting support for cPanel or WHM. CloudLinux support is a different story.
I was recruited and almost joined up with them but didn't for this exact reason. Too much uncertainty and potential for it to be cut right after I joined.
Dyn reporting another attack started at 15:52 UTC.
This seems like a bad idea. It seems to be solving for a problem that doesn’t exist while introducing the potential for issues. If you want to prevent latency or lookups localhost should just live in the hosts file.
Or fibre that isnt on maps because it belongs to the government. At this point it has so many different meanings what is one more /s
THe DefCon talk on this two years ago was pretty good.
http://www.computerworld.com/article/2966130/cybercrime-hack...
Video of this talk: https://www.youtube.com/watch?v=9FdHq3WfJgs
Their quick install method makes me very sad.
Never ever, ever curl redirect to bash.
Absolutely. Yeah that is kind of silly.
We use them all over my office because each team has their own metrics portal and we can just plug one into a big screen TV and have it run that portal. Cheaper than a full computer and just as effective.
This is pretty much the only part. The code from the live demo. I will try and find a place to get the slides up in the next few days if there is any interest:
The attackers used multiple interesting and unusual techniques, including:
Data exfiltration and real-time status reporting using DNS requests.
Sorry to be more specific we spoke on DNS Base Exfil using base64 encoded strings in DNS Lookups and also how to use DNS records to control botnets.
So not exact and only part of their method.