netim.com has been reliable over the years for me
HN user
new23d
Making network egress filtering effective, reliable and usable. Founder & Chief Engineer at https://chasersystems.com/
Our report seeks to answer some of our questions for seven of the most popular agentic code editors and plugins. By intercepting and analysing their network flows across a set of standardised tasks, we aim to gain insight into the behaviour, privacy implications, and telemetry patterns of these tools in real-world scenarios. Incidentally, a side-effect was running into OWASP LLM07:2025 System Prompt Leakage for three of the chosen coding agents. You can see the system prompts in the appendix.
Obfuscation via egress firewalls and evasive binary development with an iterative LLM agent.
Use AWS Route53?
Making a dynamic DNS client with aws and jq CLI, with a least-privilege IAM role and a SystemD service.
Exactly the same happened with me. Picking up the phone and responding to email (in weeks, not hours or days) didn't lower my bills. This sort of marketing is perhaps deflection.
We'll be working on that in the coming days. Thought the data at this point was a good start.
Some initial observations:
• Google's CRLs from the same intermediate CA (same public key) have different URLs and different content when pulled from different hosts (google.com, youtube.com).
• DigiCert has sharded according to 'assurance' class, algorithm, year and acquisition's name.
• Sectigo also has sharded according to 'assurance' class [1].
• GlobalSign has sharded by the yearly quarter presumably.
• HTTP Cache-Control maxage (or s-maxage), 'Expires' and 'Next Update' within the CRL file are not in sync.
• Some CAs other than Let's Encrypt also do not publish CRL URLs in the leaf certificates.
[1] https://www.sectigo.com/knowledge-base/detail/Sectigo-Interm...
We collected some data [1] on the viability of only CRLs as the future (phasing out OCSP) - motivated by Let's Encrypt's announcement today [2].
Data is on CRL availability, number of entries, expiry & refresh times, etc. from various x509 leaf server SSL certificates.
[1] https://news.ycombinator.com/item?id=41058138 [2] https://news.ycombinator.com/item?id=41046956
We collected some data on the viability of only CRLs as the future (phasing out OCSP) - motivated by Let's Encrypt's announcement today [1].
Data is on CRL availability, number of entries, expiry & refresh times, etc. from various x509 leaf server SSL certificates.
TLS 1.3 and ESNI (now called Encrypted Client Hello - ECH) are separate standards, although you'll see ECH only enabled in bleeding edge stacks. In fact, ECH is still in IETF draft phase [1].
It can be disabled if an organisation wishes to. I wrote about how to do this in Chrome [2,3], and will write about Firefox when I get a chance.
[1] https://datatracker.ietf.org/doc/draft-ietf-tls-esni/ [2] https://chasersystems.com/blog/disabling-encrypted-clienthel... [3] https://news.ycombinator.com/item?id=37823262
Product appears to be an ID Tent from Evi-Paq. It has inches on the front 'leg' and cms on the rear.
https://forensicssource.com/collections/evidence-markers/pro...
Stay near a transport hub so you can connect with your prospects and customers regularly, by travelling. Working along side other founders in the B2B space would be extremely beneficial too.
Wait till they get to the part where it can be easily bypassed. I spoke about it [1] at the fwd:cloudsec conference [2] in July 2022. Others have raised concerns about discovery of these bypasses too [3].
[1] https://www.youtube.com/watch?v=DKSa32qWiRw [2] https://fwdcloudsec.org/ [3] https://canglad.com/blog/2023/aws-network-firewall-egress-fi...
This is the FlightRadar24 playback of the flight: https://www.flightradar24.com/data/flights/la800#34506b53
At time ~02:27, a dip in the altitude can be seen in the flight data chart.
No.
+1 for 14"
My interest in Framework is the DIY repairability. Not interested in modular upgrades but hot swappable ports on the side and should something need replacing, can be done in a relatively shorter and more predictable timespan than with ThinkPads and EliteBooks these days. Have had terrible experience with those in the last few years.
Sorry for the plug but DiscrimiNAT Firewall actively prevents ECH [1] from flowing through and cannot be bypassed with SNI forging either [2]. Also has a great 'discovery' mode and CLI tooling to figure out that allowlist on an on-going basis.
[1] https://chasersystems.com/blog/disabling-encrypted-clienthel... [2] https://chasersystems.com/discriminat/comparison/aws-network...
Google Chrome v117 turned on TLS Encrypted ClientHello by default (on 27 Sep?) This will impact the effectiveness and accuracy of outbound traffic filtering* - for those who've implemented it (regardless of vendor.) We've written a short blog post on disabling it with PowerShell, Windows Registry and Google Chrome UI for those who may need to roll this out ASAP and regain visibility. (Disclosure: we are a vendor of an outbound filtering solution and this has impacted our customers already.)
*for many websites, the domain name visibility during an HTTPS handshake will no longer be available to firewalls/proxies (unless they were terminating.)
Your comments are a reflection of life in Tower Hamlets, where PanP etc. are. London otherwise in the N, NE and SW parts has clean air with plenty of green spaces for kids.
As an end-user, not competing with HashiCorp, this change doesn't worry me. According to their FAQ [1]:
10. What are the usage limitations for HashiCorp’s products under BSL?
All non-production uses are permitted. All production uses are allowed other than hosting or embedding the software in an offering competitive with HashiCorp commercial products, hosted or self-managed.
24. Can I host the HashiCorp products as a service internal to my organization?
Yes. The terms of the BSL allow for all non-production and production usage, except for providing competitive offerings to third parties that embed or host our software. Hosting the products for your internal use of your organization is permitted.
[1] https://www.hashicorp.com/license-faqYep. But the replies are all about users wanting credits.
log4j 2.16.0 was released at 13 Dec 22:28 GMT with the following note [1]:
Removed Message Lookups. This is a hardening related to changes made to prevent CVE-2021-44228. While this change is recommended, it is NOT required to fix CVE-2021-44228.
[1] https://lists.apache.org/thread/d6v4r6nosxysyq9rvnr779336yf0...A relevant and a fascinating read is this recent paper by Barry M. O’Reilly titled The Machine in the Ghost: Autonomy, Hyperconnectivity, and Residual Causality [1].
This article will examine the unnamed and potentially devastating constraining effect of software on human autonomy. I call this concept residual causality, where software design decisions made long ago in different circumstances for different reasons constrain human action in an unknown future. The less aware the designers of software systems are of complexity in social systems, the more likely they are to introduce residual causality."
Key features in this release include:
1. TLS inspection: Azure Firewall Premium terminates outbound and east-west transport layer security (TLS) connections. Inbound TLS inspection is supported in conjunction with Azure Application Gateway allowing end-to-end encryption. Azure Firewall performs the required value-added security functions and re-encrypts the traffic which is sent to the original destination.
2. IDPS: Azure Firewall Premium provides signature-based intrusion detection and prevention system (IDPS) to allow rapid detection of attacks by looking for specific patterns, such as byte sequences in network traffic or known malicious instruction sequences used by malware.
3. Web categories: Allows administrators to filter outbound user access to the internet based on categories (for example, social networking, search engines, gambling, and so on), reducing the time spent on managing individual fully qualified domain names (FQDNs) and URLs. This capability is also available for Azure Firewall Standard based on FQDNs only.
4. URL filtering: Allow administrators to filter outbound access to specific URLs, not just FQDNs. This capability works for both plain text and encrypted traffic if TLS inspection is enabled.
FWIW, a few months ago we had a prospect ask, and I partially quote, "We don't see any reviews on the AWS marketplace,".
We can see too that most of competitors' reviews are clearly inauthentic. Also, in the B2B space, a public endorsement is infrequently given for various reasons. Being in cybersecurity makes it an awkward ask too - especially after SolarWinds got a lot of flack for publishing their client list on the website [1].
However, it would have to be done - as that prospect has made it clear. We are sticking by our guns though and will get there eventually with genuine reviews. But TBH, the path is not clear.
[1] https://www.theverge.com/2020/12/15/22176053/solarwinds-hack...
Tomorrow Never Dies
So, it can happen.
Perhaps buyforlifeproducts.com? See submissions about it: https://news.ycombinator.com/from?site=buyforlifeproducts.co...
As Prof Bill Buchanan OBE on LinkedIn points out, the Brexit Trade Agreement [1] on Page 921 goes:
The underlying certificate used by the s/MIME mechanism has to be in compliance with X.509 standard. In order to ensure common standards and procedures with other Prüm applications, the processing rules for s/MIME encryption operations or to be applied under various Commercial Product of the Shelves (COTS) environments, are as follows:
– the sequence of the operations is: first encryption and then signing,
– the encryption algorithm AES (Advanced Encryption Standard) with 256 bit key length and RSA with 1024 bit key length shall be applied for symmetric and asymmetric encryption respectively,
– the hash algorithm SHA-1 shall be applied.
s/MIME functionality is built into the vast majority of modern e-mail software packages including Outlook, Mozilla Mail as well as Netscape Communicator 4.x and inter-operates among all major email software packages.
[1]https://assets.publishing.service.gov.uk/government/uploads/...