HN user

pawal

541 karma

DNS and crypto stuff. [ my public key: https://keybase.io/pawal; my proof: https://keybase.io/pawal/sigs/jYJ6KJTNu3VkILzDf2ra7j0TRxYo08q8p9OSBVVkGEU ]

Posts13
Comments30
View on HN

The author merely suggests that those 29 or in someway trusted by a lot of people to handle DNS queries. Those 29 also publish information on what properties the service have. If you read the whole page, the author also lists other publi DNS resolvers worth a mention.

For the long tail of unknown open DNS resolvers, use Shodan. But I would not suggest that you use any findings from Shodan to trust your internet usage with.

Yes, SNI is a generic internet privacy problem. However, it is not a property of DNS. On the positive side, ECH has been pushed through the IETF and should slowly be available to the general user.

/ The author

Vectrex Mini 10 months ago

Interesting, but a Vectrex without a vector display is like a fish without water.

It seems like the development of SoftHSM2 has stalled quite a bit. There is still a lot of user interest, but very little action in terms of management of the project. There are many pull requests and issues raised by users, but very little in terms of taking care of those.

SoftHSM was originally developed as a PKCS#11 and HSM test platform for OpenDNSSEC, but later took on a life on itself. The reason for that is that there is a lot of need to use software that talks to Hardware Security Modules, but without actually spending the cash of buying one, mostly for development. But it has also become a cornerstone of a lot of other products, for example IBM Red Hat Identity Management.

NLNet Labs states in the GitHub issue linked: "Given the above, the current state is that development on SoftHSM v2 is dormant and not likely to pick up significantly in the near future. We are conferring as a team on how to proceed in the future, but this will likely take us until at least the summer of 2024."

So the future of SoftHSM does not look very great. Are there any organizations reading this willing to take up this challenge, and make the future of this small "insignificant" open source project great again?

Yes, export regulations were heavy back then. To have proper SSL in your Netscape, you had to import this patch file from Australia. And then we had this whole Crypto Wars thing going on. Look at Steven Levy's excellent book on the subject, or search on the Wired archives.

Tor Browser 8.5 7 years ago

Yes, I use it often. My Debian installations use Tor for installing updates. Just as an example.

You should probably be more freaked out by your phone. It collects this data by default and sends it to Google or Apple. I think that Google still has an API for querying their database.

Is there a privacy friendly analytics tool that does not set cookies and store data Forever? I don't really care about perfect user analytics, just good enough. Maybe by analysing logs. In the 90's there was s lot of good tools like this, but now everybody has gone cloud. I can't imagine the tools offered today are compatible with GDPR.

For a very long time, DNS simply has not been an identified risk for most corporations. In the risk analysis they make, DNS is not on the map at all, even though it may be a single point of complete collapse for them. Thus we see extremely large corporations depending on a single DNS provider, using a registrar that are more interested in profit rather than resilience against attacks, no DNSSEC. Etc etc. This is slowly changing. What is. Not changing fast enough is the ability to run more than one DNS provider, giving you yet another spof.

Nothing is going to happen. I have seen this several times now, and support does not lift one finger to give back the account to the original owner. Expect russian spambots to post images in a few weeks time.

Lamenet 9 years ago

Testing over really bad links should be done for a lot of sites out there.

DNS was designed so that you can have multiple operators for your authoritative name servers.

Who would have thought adding a spof to your infrastructure would ever be a problem?