HN user

pjf

3,095 karma

www.foremski.pl doing www.bgpipe.org etc.

Posts292
Comments104
View on HN
github.com 2mo ago

Audit: Vuln-discovery agent reimplementing the Cloudflare Project Glasswing

pjf
1pts0
labs.watchtowr.com 2mo ago

CPanel and WHM Authentication Bypass Affecting 70M Domains

pjf
6pts0
twitter.com 3mo ago

Golang Constmap by Daniel Lemire

pjf
4pts1
twitter.com 5mo ago

Coursera prompt injection on copy and paste

pjf
4pts1
www.labs.greynoise.io 5mo ago

The Day the Telnet Died

pjf
499pts385
bgpipe.org 5mo ago

Show HN: Bgpipe – pipe live BGP sessions through Python, add RPKI, etc.

pjf
2pts0
www.koi.security 10mo ago

SpyVPN: The Google-Featured VPN That Captures Your Screen (FreeVPN.One)

pjf
4pts0
lists.nanog.org 11mo ago

Google 8.8.8.8 is getting 27M ping requests per second

pjf
8pts2
blog.sigplan.org 1y ago

The Flash Fill Feature in Excel (2021)

pjf
1pts0
blog.min.io 1y ago

MinLZ Compression Algorithm

pjf
1pts0
github.com 1y ago

Zstandard v1.5.7 brings performance enhancements

pjf
4pts1
blogs.vultr.com 1y ago

Vultr Secures $3.5B Valuation in Financing from LuminArx and AMD Ventures

pjf
2pts0
blog.coffinsec.com 1y ago

Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

pjf
259pts103
www.wired.com 1y ago

Apple Prototypes and Corporate Secrets Are for Sale Online

pjf
3pts1
www.spamhaus.org 1y ago

Too big to care? Our disappointment with Cloudflare anti-abuse posture

pjf
45pts7
dl.acm.org 2y ago

Air-Bus Hijacking: Silently Taking over Avionics Systems

pjf
63pts62
twitter.com 2y ago

Gymnastics is the Turing test of video generation models

pjf
3pts0
github.com 2y ago

X-Ray-TLS: Generic and transparent TLS inspection for local programs

pjf
1pts0
blog.ovhcloud.com 2y ago

The Rise of Packet Rate Attacks: When Core Routers Turn Evil

pjf
37pts5
kirin-attack.github.io 2y ago

Kirin: Hitting the Internet with Distributed BGP Announcements

pjf
3pts0
lcamtuf.coredump.cx 2y ago

JPEG DCT Text Lossifizer

pjf
1pts1
www.pcmag.com 2y ago

Starlink's Laser System Is Beaming 42M GB of Data per Day

pjf
12pts11
www.reuters.com 2y ago

HP to acquire Juniper Networks for $13B

pjf
1pts0
old.reddit.com 2y ago

Withings Android battery drain issue with watches

pjf
1pts0
tip.golang.org 3y ago

Golang 1.20rc1 released, deprecates rand.Seed()

pjf
1pts0
github.com 3y ago

CnC Hunter: fully automatic analyzer of IoT malware to find live CnC servers

pjf
1pts0
github.com 3y ago

Sift: Scalable architecture to extract data from Google Trends

pjf
2pts0
twitter.com 3y ago

“The owner of this iPhone was in a severe car crash” amusement park fail

pjf
3pts1
twitter.com 4y ago

Museum of Failure Highlights

pjf
2pts0
twitter.com 4y ago

Starlink Works in Ukraine

pjf
11pts0

There are situations [1] where you could reliably BGP-hijack the IP prefix of the target domain authoritative nameserver, and obtain your own domain-validated cert for the target (by effectively controlling the zone file contents). And yeah, CAs do have their BGP protections, but still there's at least partial assumption BGP is secure enough to run DNS-based validation for new SSL certs, in our world where DNSSEC is still rare.

  [1] https://www.ietf.org/proceedings/104/slides/slides-104-maprg-dns-observatory-monitoring-global-dns-for-performance-and-security-pawel-foremski-and-oliver-gasser-00.pdf (see slide 15; yeah, it's already a bit old, yet still the case from my practice)

NB: this is not "IPv6 traffic crosses the 50% mark" but "availability of IPv6 connectivity among Google users", which is a very important difference. This means roughly half of Google users have IPv6 capability, which does not 1:1 correspond how much traffic is actually transferred over IPv6, which is what this submission says in the title.

great post! key points for me:

1. 100 IXes alone would get 56% IPv4 and 61% IPv6 prefixes, but ~14% reachability

2. little uniqueness between exchanges: not many new prefixes after the top 5

3. for outbound-heavy networks IXes are great, but to attract traffic they are not (edit: applies to automatic peering via route servers)

One reason is there already was exabgp, written in Python, which in my experience is slow and resource hungry. Golang is much faster, easily portable, and produces static binaries (easy to deploy).

Another thing is bgpipe speaks JSON to background (or even remote) packet processors, so basically you can use whatever language you want with it to drive your BGP routers.

Do you know - and can share - how this compares vs the Onyx Boox Tab Ultra C Pro?

I guess it might be a very competitive alternative to your product, yet it can't reach 60+fps and is sketchy in terms of security, imho.

Quote:

  - math/rand
  The math/rand package now automatically seeds the global 
  random number generator (used by top-level functions like 
  Float64 and Int) with a random value, and the top-level 
  Seed function has been deprecated. Programs that need a 
  reproducible sequence of random numbers should prefer to 
  allocate their own random source, using 
  rand.New(rand.NewSource(seed)).
  (...)

Cloudflare’s unique advantages in a world where the Internet is increasingly fragmented

Wait, it's the opposite, at least on the infrastructure side. The Internet is increasingly centralized, due to Cloudflare and other big players.

...and you think the sequence and timing of IP addresses your machine connects to alone can't be used to easily infer the website you're browsing? Neither DoH nor ESNI will make you more secure/private, but DoH will definitely make some companies more powerful. That's not the Internet as we knew it until now.

In practice I found new certs being available for download from CT logs hours after they've been issued. This is more than enough to perform an attack.

Another point is that CTs alone won't prevent the attacks nor inform you about a problem - they need a monitoring system.

(yes I know that's not the problem with CT - it's great, just trying to justify a strong opinion of "it doesn't work")

Farsight Security, Inc. | Sr Software Engineer | C, Python, Golang, more | US, Worldwide | Full-Time, REMOTE

Farsight Security, lead by Paul Vixie, is all about DNS and security. We provide the world’s largest real-time actionable threat intelligence information on how the Internet is changing, seeing more than 200,000 DNS-related observations per second.

We are looking for a Senior Distributed Systems Engineer to join our development team distributed around the world.

Details at https://www.farsightsecurity.com/about-farsight-security/job...