HN user

hstrauss

5 karma
Posts0
Comments6
View on HN
No posts found.

And setup reporting and forensic reporting. I have a domain that seems to be the default for a botnet, so my daily reports from GMail and Yahoo! always include at least a few IP addresses attempting to submit as admin@[domain].

The reporting sets my mind at ease that those big guys are blocking it and that the (low) legitimate volume of mail to those guys is reasonable.

It's also interesting to note that with DNSSEC, DKIM, SPF and DMARC, the pattern seems to be that some large Chinese mail providers drop DNS responses to try to overcome the "-all" token in the SPF record and "p=reject" token in DMARC. At least the reports show that the authentication (by SPF/DKIM) failed, so that makes me sleep a little better.

Par for the course, I guess. :P

*edit: grammar

For .ZA, I've only really seen native IPv6 at jupiter.is and on the TEnet (NREN) network. My university campus doesn't even have native IPv6 available for servers I maintain.

From what I've seen running an HE tunnel through London, Youtube and Facebook make up the bulk of IPv6 traffic (as expected). At least those networks are the only thing routinely dedicating 10%+ of the total inbound traffic to IPv6 according to my home network flow analysis (I think it's about 18% IPv6 usage on a monthly basis).

South African here.

There's the electricity issue (we call the rolling blackouts "load-shedding") which affects the cellular base-stations and telco exchanges as much as anything, but also another more obvious issue for content delivery: the local loop.

For the past 15+ years (as long as I've had Internet access), the incumbent telco (TelkomSA) has not been forthcoming with upgrading or maintaining the ADSL infrastructure. Finally, there seems to be traction with FTTx providers, but this seems limited to affluent pockets of a few thousand people in the country. All the new fibre offerings serve the same locations.

While it's hopeful this will improve the situation in the medium-term, the backhaul from ISP to eyeball is oversubscribed at least 30:1 for ADSL, with equipment being replaced by (IMO) inferior network equipment. Additionally, there are reports of automated line-conditioning software which should improve local loop connectivity, but I've seen DSL sync issues only since the software has been implemented.

The (ex-public, privatised under Telkom) Exchanges have been neglected and have recently been divided into three groups: Earners, Maintainers and "Lost Causes". The latter two will not receive upgrades from ADSL1 and the Earners will likely migrate to newer technologies. This is largely due to copper-theft and vandalism of exchanges/cellular base-stations (which are oversubscribed enough that wireless technologies routinely sustain 3000-20000ms latencies). The oligopoly running cellular networks have no incentive to improve this, since the Regulatory Authorities don't really seem to push competition as well as we'd like.

TL;DR: There are issues, but rose-tinted glasses make me hopeful in the medium term. Claims are that wireless will fix everything seem bleak, since base stations become oversubscribed faster than they can be built/upgraded (and the backhaul from them is measured in megabits/s, rather than gigabits/s charged at ~US$0.15/MB).

Facebook and PGP 11 years ago

I think the nicest part of this is that account recovery e-mails are encrypted. I wish we'd see more of this.

While I'm cautious about facebook in general, it is (in essence) a repository for public data. A public key falls into that category, so they gain nothing more than the association of user and key. And in return, the PRISM databank has more superbly useless information to store and eventually 'collect' for 1EF communication.

And I gain immunity from account hijacking unless I mess up Key Management.

For Windows XP and Server 2003, there is a hotfix: http://support.microsoft.com/kb/968730

This enables SHA-2 certificates. Deployment of the patch is another problem, since it's a HotFix (which may have enterprise-QA issues) and not intended for general use, AFAIK. Still, I've been using it since WS2008 originally came out.