<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems.]]></title><description><![CDATA[<p>I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.</p><p>I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl</p><p>384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:<br />-----BEGIN RSA PRIVATE KEY-----<br />MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK<br />j0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP<br />LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa<br />9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09<br />AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj<br />7ez94w==<br />-----END RSA PRIVATE KEY-----</p>]]></description><link>https://board.circlewithadot.net/topic/4d504187-f61f-40f4-b4b1-f3dd74a4e0d8/i-reported-an-insecure-dkim-key-to-deutsche-telekom-t-systems.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 00:56:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4d504187-f61f-40f4-b4b1-f3dd74a4e0d8.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 15 Apr 2026 07:34:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 17:42:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> i didn't know anything below rsa-1024 even existed!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.calitabby.net/users/crispycat/statuses/116415615781241751</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.calitabby.net/users/crispycat/statuses/116415615781241751</guid><dc:creator><![CDATA[crispycat@mastodon.calitabby.net]]></dc:creator><pubDate>Thu, 16 Apr 2026 17:42:04 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 17:41:20 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.sdf.org/@stellated">@<span>stellated</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Bit more discussion in German to be found here: <a href="https://borncity.com/blog/2025/02/25/merkwuerdige-vorschriften-bei-der-telekom-fuer-e-mail-versand/" rel="nofollow noopener"><span>https://</span><span>borncity.com/blog/2025/02/25/m</span><span>erkwuerdige-vorschriften-bei-der-telekom-fuer-e-mail-versand/</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Bebef/statuses/116415612893272867</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Bebef/statuses/116415612893272867</guid><dc:creator><![CDATA[bebef@mastodon.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 17:41:20 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 17:38:14 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.sdf.org/@stellated">@<span>stellated</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> It works like this: send an email to a Telekom recipient. Mail bounces with </p><p>&lt;xxxxx@t-online.de&gt;: host mx03.t-online.de[194.25.134.73] refused to talk to</p><p>    me: 554 IP=1.2.3.4 - None/bad reputation. Ask your postmaster for help</p><p>    or to contact tobr@rx.t-online.de for reset. (NOWL)</p><p>Send an email to tobr@rx.t-online.de, hilarity ensues.</p><p>(They send a reply pointing you to <a href="https://postmaster.t-online.de/#t4.1" rel="nofollow noopener"><span>https://</span><span>postmaster.t-online.de/#t4.1</span><span></span></a>)</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/Bebef/statuses/116415600674477867</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/Bebef/statuses/116415600674477867</guid><dc:creator><![CDATA[bebef@mastodon.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 17:38:14 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 17:24:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/bebef%40mastodon.social">@<span>Bebef</span></a></span> <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span><br />Do y'all have any docs on this you could link? Is it a blanket automated check a la DKIM and SPF or is it something that's reviewed when appealing an anti-spam listing? My search queries aren't turning up much.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.sdf.org/users/stellated/statuses/116415544831718977</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.sdf.org/users/stellated/statuses/116415544831718977</guid><dc:creator><![CDATA[stellated@mastodon.sdf.org]]></dc:creator><pubDate>Thu, 16 Apr 2026 17:24:02 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 14:45:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/j_r%40social.jugendhacker.de">@<span>j_r</span></a></span><br />War bei mir ähnlich. Wer seinen Mailkram dann bei der Telekom hatte, hatte halt Pech. Zwischendrin hatte ich deren ASN im Spamfilter geblockt, weil ja, dann halt auch in beide Richtungen. Dann schlug aber der WAF Alarm und da blieb mir keine Wahl mehr... ich hab aber dann wohl beim Support-Lotto das falsche Ticket, gezogen.</p><p>(WAF= Wife Acceptance Factor)<br /><span><a href="/user/bekopharm%40indieweb.social">@<span>bekopharm</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://social.linux.pizza/users/momo/statuses/116414919553994446</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.linux.pizza/users/momo/statuses/116414919553994446</guid><dc:creator><![CDATA[momo@social.linux.pizza]]></dc:creator><pubDate>Thu, 16 Apr 2026 14:45:01 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 14:38:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/momo%40social.linux.pizza" rel="nofollow noreferrer noopener">@<span>momo</span></a></span> <span><a href="/user/bekopharm%40indieweb.social" rel="nofollow noreferrer noopener">@<span>bekopharm</span></a></span> das dreisteste ist es hängt scheinbar stark davon ab welchen Support Mitarbeiter man erreicht. Hab Jahre lang damit gelebt einfach keine E-Mails an t-online senden zu können. Wurde irgendwann dann aber doch zu nervig und ich habe sie nochmal kontaktiert. Dann haben sie ohne große Nachfrage einfach meine IP freigeschaltet <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f937.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--shrug" style="height:23px;width:auto;vertical-align:middle" title="🤷" alt="🤷" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.jugendhacker.de/users/j_r/statuses/01KPBBN6FPFY6K6RZVMW3S0DYH</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.jugendhacker.de/users/j_r/statuses/01KPBBN6FPFY6K6RZVMW3S0DYH</guid><dc:creator><![CDATA[j_r@social.jugendhacker.de]]></dc:creator><pubDate>Thu, 16 Apr 2026 14:38:24 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 14:10:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/varx%40infosec.exchange">@<span>varx</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Im not arguing with internet strangers. Go dive off a bridge mate <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title="👍" alt="👍" /></p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116414784154258126</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116414784154258126</guid><dc:creator><![CDATA[yama@tech.lgbt]]></dc:creator><pubDate>Thu, 16 Apr 2026 14:10:35 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 14:06:58 GMT]]></title><description><![CDATA[<p><span><a href="/user/yama%40tech.lgbt">@<span>yama</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Out of curiosity, what year are you posting from?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/varx/statuses/116414769966077446</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/varx/statuses/116414769966077446</guid><dc:creator><![CDATA[varx@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 14:06:58 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 12:22:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/16af93%40wetdry.world">@<span>16af93</span></a></span> <span><a href="/user/q%40glauca.space">@<span>q</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> iirc BSA recommends at least 3000bits</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/trpalesz/statuses/116414360154926193</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/trpalesz/statuses/116414360154926193</guid><dc:creator><![CDATA[trpalesz@mastodon.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 12:22:45 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 12:09:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Way to go Telekom! Last time I found a 320 bit RSA key it was “protecting” people’s private information (<a href="https://palant.info/2023/01/25/ipinside-koreas-mandatory-spyware/#how-is-this-data-protected" rel="nofollow noopener"><span>https://</span><span>palant.info/2023/01/25/ipinsid</span><span>e-koreas-mandatory-spyware/#how-is-this-data-protected</span></a>) and I even had a little difficulty finding a cryptography library that wouldn’t refuse working with a key so short.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/WPalant/statuses/116414308964515711</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/WPalant/statuses/116414308964515711</guid><dc:creator><![CDATA[wpalant@infosec.exchange]]></dc:creator><pubDate>Thu, 16 Apr 2026 12:09:44 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 11:13:53 GMT]]></title><description><![CDATA[<span><a href="/user/badkeys%40infosec.exchange" rel="ugc">@<span>badkeys</span></a></span> hot take: dkim does not matter anyway]]></description><link>https://board.circlewithadot.net/post/https://fe.disroot.org/objects/a7b75b74-c449-480e-b13b-f50738cd1524</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fe.disroot.org/objects/a7b75b74-c449-480e-b13b-f50738cd1524</guid><dc:creator><![CDATA[woffs@fe.disroot.org]]></dc:creator><pubDate>Thu, 16 Apr 2026 11:13:53 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 10:54:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Modern DKIM implementations should not accept signatures made with RSA keys smaller than 1024 bits, nowadays, so it seems unlikely to me that you could do anything nefarious with a key this weak. The verifier would be equally faulty if it accepts weak keys.</p><p>See also: <a href="https://www.rfc-editor.org/rfc/rfc8301#section-3.2" rel="nofollow noopener"><span>https://www.</span><span>rfc-editor.org/rfc/rfc8301#sec</span><span>tion-3.2</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mamot.fr/users/x0r/statuses/116414012625989196</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mamot.fr/users/x0r/statuses/116414012625989196</guid><dc:creator><![CDATA[x0r@mamot.fr]]></dc:creator><pubDate>Thu, 16 Apr 2026 10:54:22 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 10:17:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/badrihippo%40fosstodon.org">@<span>badrihippo</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> Yes.</p><p>Everyone should be doing the same (rotating DKIM keys and publishing the old private keys).  Here's my blog post on the subject:</p><p><a href="https://diziet.dreamwidth.org/16025.html" rel="nofollow noopener"><span>https://</span><span>diziet.dreamwidth.org/16025.ht</span><span>ml</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.me.uk/users/Diziet/statuses/116413868823366231</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.me.uk/users/Diziet/statuses/116413868823366231</guid><dc:creator><![CDATA[diziet@mastodon.me.uk]]></dc:creator><pubDate>Thu, 16 Apr 2026 10:17:48 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 08:54:22 GMT]]></title><description><![CDATA[<p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> RSA ?<br />You can literally get an API key for your python script to access a literal quantum computer. And someone already made shors alg. implementation exclusively for RSA cracking</p><p>If it were over 4096 bits its still Not Secure and crackable within seconds. <br />Literally Any modern post quantum algorirthm is orders of magnitude better...</p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116413540785622288</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116413540785622288</guid><dc:creator><![CDATA[yama@tech.lgbt]]></dc:creator><pubDate>Thu, 16 Apr 2026 08:54:22 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 08:52:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/lunareclipse%40snug.moe">@<span>lunareclipse</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> "bad companies", so most of them by nature ?</p>]]></description><link>https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116413531578147696</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://tech.lgbt/users/yama/statuses/116413531578147696</guid><dc:creator><![CDATA[yama@tech.lgbt]]></dc:creator><pubDate>Thu, 16 Apr 2026 08:52:02 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:56:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/oscherler%40tooting.ch">@<span>oscherler</span></a></span> <span><a href="/user/tanja%40mastodon.catgirl.cloud">@<span>tanja</span></a></span> </p><p>Or they did not understand the problem?</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/m_berberich/statuses/116413313611555677</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/m_berberich/statuses/116413313611555677</guid><dc:creator><![CDATA[m_berberich@chaos.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:56:36 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:55:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/bekopharm%40indieweb.social">@<span>bekopharm</span></a></span><br />Ich konnte sie auf ein Kontaktformular runterhandeln, musste aber versichern, dass der Transport dann nicht per eMail erfolgt. Ich habe ne ntfy-Instanz auf einem meiner Server laufen, das Webformular generiert jetzt eine Notification auf mein Smartphone.</p><p>Eigentlich wollte ich den Zugriff per Firewall auf die Admin-Netzwerke der Telekom zumachen, aber das war für sie absolut inakzeptabel.</p><p>Aber bei jeder Gelegenheit seine eigenen Kunden in Geiselhaft nehmen und rumprotzen, dass sie der größte Provider Deutschlands sind und damit eigene Regeln festlegen können, an die sich jeder zu halten hat.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.linux.pizza/users/momo/statuses/116413307868163614</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.linux.pizza/users/momo/statuses/116413307868163614</guid><dc:creator><![CDATA[momo@social.linux.pizza]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:55:08 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:40:31 GMT]]></title><description><![CDATA[<a href="/user/badkeys%40infosec.exchange">@badkeys@infosec.exchange</a> the yafu help describes using siqs for this, which would take that server 2 to 3 hours, but using nfs it took only minutes]]></description><link>https://board.circlewithadot.net/post/https://nya.social/notes/819d953c038a36d740e84c3e</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://nya.social/notes/819d953c038a36d740e84c3e</guid><dc:creator><![CDATA[linear@nya.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:40:31 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:40:00 GMT]]></title><description><![CDATA[<a href="/user/badkeys%40infosec.exchange">@badkeys@infosec.exchange</a> just a few days ago i broke an rsa384 key using yafu on my home server (a ~6 year old dell poweredge, fairly decent spec) as a practice run for something, and it took under 5 minutes]]></description><link>https://board.circlewithadot.net/post/https://nya.social/notes/819d953b88fe879abe0a1c51</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://nya.social/notes/819d953b88fe879abe0a1c51</guid><dc:creator><![CDATA[linear@nya.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:40:00 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:38:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/diziet%40mastodon.me.uk">@<span>Diziet</span></a></span> <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f62e.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--open_mouth" style="height:23px;width:auto;vertical-align:middle" title="😮" alt="😮" /> never even thought this could be a thing!</p><p>So you're basically making it impossible to prove through DKIM signatures that a given email was actually sent from your server?</p><p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/badrihippo/statuses/116413240783609971</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/badrihippo/statuses/116413240783609971</guid><dc:creator><![CDATA[badrihippo@fosstodon.org]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:38:05 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:37:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place">@<span>buherator</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> <span><a href="/user/mcr314%40todon.nl">@<span>mcr314</span></a></span> probably done by an apprentice anyway</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/users/janet_catcus/statuses/116413240144003313</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/users/janet_catcus/statuses/116413240144003313</guid><dc:creator><![CDATA[janet_catcus@hachyderm.io]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:37:55 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:29:39 GMT]]></title><description><![CDATA[<p><span><a href="https://social.linux.pizza/@selea">@<span>selea</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> </p><p>no, sounds like they stayed for tooo long on a short length that could be cracked quickly.</p><p>they should upgrade to more bits, and re-roll their keys</p>]]></description><link>https://board.circlewithadot.net/post/https://helvede.net/users/kramse/statuses/116413207635083615</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://helvede.net/users/kramse/statuses/116413207635083615</guid><dc:creator><![CDATA[kramse@helvede.net]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:29:39 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:27:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> Hab mich damit auch schon herum geärgert und mit einem "Musterbrief" frei gekauft: <a href="https://beko.famkos.net/2023/06/02/%c2%b7t%c2%b7%c2%b7%c2%b7error/" rel="nofollow noopener"><span>https://</span><span>beko.famkos.net/2023/06/02/%c2</span><span>%b7t%c2%b7%c2%b7%c2%b7error/</span></a></p><p>Die haben doch echt nicht mehr alle Latten am Zaun o0</p>]]></description><link>https://board.circlewithadot.net/post/https://indieweb.social/users/bekopharm/statuses/116413198864958767</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://indieweb.social/users/bekopharm/statuses/116413198864958767</guid><dc:creator><![CDATA[bekopharm@indieweb.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:27:25 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:09:19 GMT]]></title><description><![CDATA[<span><a href="/user/badkeys%40infosec.exchange" rel="ugc">@<span>badkeys</span></a></span> <br /><br />I don't remember have ever seen lower RSA keys size than 512 bits... We have a winner here !]]></description><link>https://board.circlewithadot.net/post/https://agora.l0g.eu/objects/97af061c-88f6-4d31-b2f6-3bb0e1176337</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://agora.l0g.eu/objects/97af061c-88f6-4d31-b2f6-3bb0e1176337</guid><dc:creator><![CDATA[artlog@agora.l0g.eu]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:09:19 GMT</pubDate></item></channel></rss>