Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

M

mnordhoff@infosec.exchange

@mnordhoff@infosec.exchange
About
Posts
13
Topics
11
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • Remember the halcyon days of circa 1935 – February 2022 when you could wake up in the morning and the number of nuclear facilities that had been bombed overnight was zero
    M mnordhoff@infosec.exchange

    Remember the halcyon days of circa 1935 – February 2022 when you could wake up in the morning and the number of nuclear facilities that had been bombed overnight was zero

    Uncategorized

  • There's a Unicode codepoint for ㎓?!
    M mnordhoff@infosec.exchange

    RE: https://digipres.club/@foone/116261213671807501

    There's a Unicode codepoint for ㎓?!

    Uncategorized

  • https://en.wikipedia.org/wiki/Cats_and_the_Internet
    M mnordhoff@infosec.exchange

    Link Preview Image
    Cats and the Internet - Wikipedia

    favicon

    (en.wikipedia.org)

    "This article's lead section may be too short to adequately summarize the key points."

    Uncategorized

  • Cisco updated https://umbrella-static.s3.dualstack.us-west-1.amazonaws.com/index.html again a few hours ago!
    M mnordhoff@infosec.exchange

    Cisco updated https://umbrella-static.s3.dualstack.us-west-1.amazonaws.com/index.html again a few hours ago!

    It no longer seems generated from an out-of-date Public Suffix List, but there's a change: top-1m-TLD.csv.zip used to include a 100% complete list of TLDs, but now it trims off 263 low-traffic TLDs like .gb and .blockbuster from the bottom of the list. Valid creative decision that no one except me will care about, I guess.

    Uncategorized

  • There's a trivial landing page on https://amazontrustservices.eu/ for Amazon's EU Sovereign Cloud CA
    M mnordhoff@infosec.exchange

    There's a trivial landing page on https://amazontrustservices.eu/ for Amazon's EU Sovereign Cloud CA.
    It has a privacy policy link.
    To https://aws.amazon.com/privacy/.

    Uncategorized

  • "Team Cymru - Botnet Analysis and Reporting Service (BARS)" thinks it is a good idea to block the DoH servers of an ISP with tens of millions of customers, cool cool.
    M mnordhoff@infosec.exchange

    "Team Cymru - Botnet Analysis and Reporting Service (BARS)" thinks it is a good idea to block the DoH servers of an ISP with tens of millions of customers, cool cool.

    Uncategorized

  • I missed this yesterday, but AWS Middle East (UAE) (me-central-1) has been having issues due to the war.
    M mnordhoff@infosec.exchange

    I missed this yesterday, but AWS Middle East (UAE) (me-central-1) has been having issues due to the war.

    "At around 4:30 AM PST [2026-03-01], one of our Availability Zones (mec1-az2) was impacted by objects that struck the data center, creating sparks and fire. The fire department shut off power to the facility and generators as they worked to put out the fire."

    "Mar 01 10:46 PM PST We can confirm that a localized power issue has affected another Availability Zone in the ME-CENTRAL-1 Region (mec1-az3)."

    This might be the first time AWS has ever had separate, serious outages affecting multiple AZs simultaneously, if you exclude the many many outages where a region-level service like S3 goes down due to a software issue.

    View the overall status and health of AWS services using the AWS Health Dashboard.

    favicon

    (health.aws.amazon.com)

    Uncategorized

  • https://community.letsencrypt.org/t/blocking-some-on-demand-issuance-caused-by-internet-scanning/245553
    M mnordhoff@infosec.exchange

    Link Preview Image
    Blocking Some On-Demand Issuance Caused by Internet Scanning

    We've noticed a surge in certificate requests for very long domain names (e.g., 10 DNS labels) that we believe are the result of unintended feedback loops between Caddy or autocert and Internet scanning tools. We'll be b…

    favicon

    Let's Encrypt Community Support (community.letsencrypt.org)

    Scanners causing problems for people, lovely.

    Uncategorized

  • Meanwhile, streamers are complaining that YouTube chat is heavily censoring English.
    M mnordhoff@infosec.exchange

    Meanwhile, streamers are complaining that YouTube chat is heavily censoring English. English messages are mostly dropped, messages in other languages, or sufficiently multilingual messages, go through.

    Uncategorized

  • Let's just take a sip of coffee and catch up on my unread email.
    M mnordhoff@infosec.exchange

    Let's just take a sip of coffee and catch up on my unread email.

    From: Rsync.net Info
    Subject: IMPORTANT - Billing system unauthorized access

    Oh.

    This was a PARTIAL access and not all customers were impacted.

    [...]

    There is NO CONNECTION of ANY KIND between our billing system and your data.

    [...]

    Your exposure is as follows:

    • Your contact information
    • The TYPE of payment method that you use, but NOT the card number
    • other misc. service details such as quota and discounts applied

    That's actually pretty good?

    Uncategorized

  • Almost every object storage service: one IPv4 address per data center is enough Internet for everyone
    M mnordhoff@infosec.exchange

    Almost every object storage service: one IPv4 address per data center is enough Internet for everyone

    Amazon: let's assign another /15 to us-east-1! 💸

    Uncategorized

  • I would like to give an update on "federation" on Bluesky.
    M mnordhoff@infosec.exchange

    @mcc 4 days later Bluesky has announced an intention to establish an independent Swiss entity to manage the DID database. So there's that!

    Link Preview Image
    Creating an Independent Public Ledger of Credentials (PLC) Directory Organization | Bluesky

    The Bluesky Social app is built on an open network protocol that refers to each user by a unique Decentralized Identifier, or DID (a W3C standard). The most popular supported DID method was developed in-house by Bluesky Social, and is called "Public Ledger of Credentials", or PLC. The PLC identity system currently relies on a global directory service to distribute identity updates, and that directory service has been operated by Bluesky as well.

    favicon

    (docs.bsky.app)

    It hasn't happened yet, and it remains to be seen how it will be funded, whether it will have real independence, etc., but still?!

    Uncategorized

  • I would like to give an update on "federation" on Bluesky.
    M mnordhoff@infosec.exchange

    @mcc There's also https://plc.directory/, the did:plc: database, also run by Bluesky.

    ("plc" stands for "placeholder", because they aspire to figure out something blockchain decentralized later.)

    I think Bluesky can inconvenience people at best, or hijack their accounts at worst, especially if they were using a Bluesky PDS and Bluesky has all the keys. But I don't know/remember the exact implications.

    Uncategorized
  • Login

  • Login or register to search.
  • First post
    Last post
0
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups