Their usage of port 5000 appears compliant with IANA port designation.
Their usage of port 5000 appears compliant with IANA port designation.
I picked specifically 5000 because the IANA registration for this port was assigned to a single service, was not used and generally obscure. Whatever Apple has running on there is also unlikely to be what the IANA registration refers to.
Here's a quotation:
> Just did a bit more digging, and IANA actually assigns port 5000 to "commplex-main" - so really any other service that's using that port is violating the official assignment. Based on a quick search of what commplex-main is, it's related to UPnP for network device discoverability. I'm not sure exactly what the AirPlay Receiver service does, but I get the gist that it probably does fit somewhere into the scope of UPnP-related features. At the very least, it's probably a far more accurate usage of port 5000 than some random dev servers.
This port was actually also used back in XP and * Lion days both by Apple and Microsoft, but I have a hunch that *.local replaced these use cases and that's why it became disused until recently.
> The Commplex is a communications package for communication with the NCUBE from Sun workstations.
Wait, all roads lead to Oracle?
So, uhm, this reminds me of STMPS and port 465. Read about it, and it's a sad state of affairs because of a blunder in managing that list. Funnily, mail providers and Cisco share that port (and no, not a TCP/UDP split, both are for TCP connections).
So who suggested to use port 5000 then way back? That's a serious question that is now my homework for this conversation.
I'm not sure how this came to be to be honest. This is a very old system, but yet we still abuse the four digit range with private use ports. I mean, it's often just one digit away. Even as defaults in software packages where their developers should at least know better even if a random web developer might not.
Yeah, and while we're at it, let's burn all IETF RFCs. Who needs that?
1) To cite it in a smart hacker news comment 2) To show alarming text in "security scans" to gullible people
Seriously, google "commplex" and all you find is confused home users thinking they got a trojan of sorts. In 2021, it is purely a drain on everyones nerves.
Pretty sure those are not drains on everybody's nerves. Devs bashing standards cause they don't want to follow the rules which make things work well is a drain on everyone's nerves.
But maybe I have misunderstood the document (didn't read). Standards are nice, except when they are mostly geared towards one company. Then yeah, it would be better to have SRV records and discourage default port usage such as Apple is doing.
If we could go back in time, forcing an app layer (e.g. an ssh header) over a port might have been helpful, port conflicts might have been less common and you could have even eliminated root only ports.
At any rate let's not break the web because some lazy mofo doesn't want to get off their couch.
AFAIK that's mostly a GNOME issue, so despite it wrongly, IMO, being the default and the most popular DE of the Linux distros for some reason, I wouldn't throw mud on the whole Linux DE ecosystem because of it alone.
KDE, LXQT, LXDE and XFCE seem to have their shit together for the most part.
I'm no fanboy and have no dog in this DE fight, just curious.
Sadly, its almost certainly too late to add port numbers to DNS.
It is just a matter of specifying the use of such entries in the protocols (HTTP et al). A lot of new protocols already rely on them.
As someone who doesn't do much infra, I've encountered them when setting up the DNS for a Minecraft server. The game checks for the SRV record, or if it is missing, assumes (or reads from the user) a given port.
Do you know what the rationale is for not adding them to HTTP2 / HTTP3?