Remember the halcyon days of circa 1935 – February 2022 when you could wake up in the morning and the number of nuclear facilities that had been bombed overnight was zero
mnordhoff@infosec.exchange
Posts
-
Remember the halcyon days of circa 1935 – February 2022 when you could wake up in the morning and the number of nuclear facilities that had been bombed overnight was zero -
There's a Unicode codepoint for ㎓?!RE: https://digipres.club/@foone/116261213671807501
There's a Unicode codepoint for ㎓?!
-
https://en.wikipedia.org/wiki/Cats_and_the_Internet"This article's lead section may be too short to adequately summarize the key points."
-
Cisco updated https://umbrella-static.s3.dualstack.us-west-1.amazonaws.com/index.html again a few hours ago!Cisco updated https://umbrella-static.s3.dualstack.us-west-1.amazonaws.com/index.html again a few hours ago!
It no longer seems generated from an out-of-date Public Suffix List, but there's a change:
top-1m-TLD.csv.zipused to include a 100% complete list of TLDs, but now it trims off 263 low-traffic TLDs like.gband.blockbusterfrom the bottom of the list. Valid creative decision that no one except me will care about, I guess. -
There's a trivial landing page on https://amazontrustservices.eu/ for Amazon's EU Sovereign Cloud CAThere's a trivial landing page on https://amazontrustservices.eu/ for Amazon's EU Sovereign Cloud CA.
It has a privacy policy link.
To https://aws.amazon.com/privacy/. -
"Team Cymru - Botnet Analysis and Reporting Service (BARS)" thinks it is a good idea to block the DoH servers of an ISP with tens of millions of customers, cool cool."Team Cymru - Botnet Analysis and Reporting Service (BARS)" thinks it is a good idea to block the DoH servers of an ISP with tens of millions of customers, cool cool.
-
I missed this yesterday, but AWS Middle East (UAE) (me-central-1) has been having issues due to the war.I missed this yesterday, but AWS Middle East (UAE) (me-central-1) has been having issues due to the war.
"At around 4:30 AM PST [2026-03-01], one of our Availability Zones (mec1-az2) was impacted by objects that struck the data center, creating sparks and fire. The fire department shut off power to the facility and generators as they worked to put out the fire."
"Mar 01 10:46 PM PST We can confirm that a localized power issue has affected another Availability Zone in the ME-CENTRAL-1 Region (mec1-az3)."
This might be the first time AWS has ever had separate, serious outages affecting multiple AZs simultaneously, if you exclude the many many outages where a region-level service like S3 goes down due to a software issue.
-
https://community.letsencrypt.org/t/blocking-some-on-demand-issuance-caused-by-internet-scanning/245553
Blocking Some On-Demand Issuance Caused by Internet Scanning
We've noticed a surge in certificate requests for very long domain names (e.g., 10 DNS labels) that we believe are the result of unintended feedback loops between Caddy or autocert and Internet scanning tools. We'll be b…
Let's Encrypt Community Support (community.letsencrypt.org)
Scanners causing problems for people, lovely.
-
Meanwhile, streamers are complaining that YouTube chat is heavily censoring English.Meanwhile, streamers are complaining that YouTube chat is heavily censoring English. English messages are mostly dropped, messages in other languages, or sufficiently multilingual messages, go through.
-
Let's just take a sip of coffee and catch up on my unread email.Let's just take a sip of coffee and catch up on my unread email.
From: Rsync.net Info
Subject: IMPORTANT - Billing system unauthorized accessOh.
This was a PARTIAL access and not all customers were impacted.
[...]
There is NO CONNECTION of ANY KIND between our billing system and your data.
[...]
Your exposure is as follows:
- Your contact information
- The TYPE of payment method that you use, but NOT the card number
- other misc. service details such as quota and discounts applied
That's actually pretty good?
-
Almost every object storage service: one IPv4 address per data center is enough Internet for everyoneAlmost every object storage service: one IPv4 address per data center is enough Internet for everyone
Amazon: let's assign another /15 to us-east-1!

-
I would like to give an update on "federation" on Bluesky.@mcc 4 days later Bluesky has announced an intention to establish an independent Swiss entity to manage the DID database. So there's that!
Creating an Independent Public Ledger of Credentials (PLC) Directory Organization | Bluesky
The Bluesky Social app is built on an open network protocol that refers to each user by a unique Decentralized Identifier, or DID (a W3C standard). The most popular supported DID method was developed in-house by Bluesky Social, and is called "Public Ledger of Credentials", or PLC. The PLC identity system currently relies on a global directory service to distribute identity updates, and that directory service has been operated by Bluesky as well.
(docs.bsky.app)
It hasn't happened yet, and it remains to be seen how it will be funded, whether it will have real independence, etc., but still?!
-
I would like to give an update on "federation" on Bluesky.@mcc There's also https://plc.directory/, the
did:plc:database, also run by Bluesky.("
plc" stands for "placeholder", because they aspire to figure out something blockchain decentralized later.)I think Bluesky can inconvenience people at best, or hijack their accounts at worst, especially if they were using a Bluesky PDS and Bluesky has all the keys. But I don't know/remember the exact implications.