3,169 karma · joined February 24, 2012
These ones are handy:
1. What is my public IP
2. What is my DNS resolver (handy)
3. Is this a homoglyph (have your openclaw check this before blindly following a link)
4. SPF Flattener
5. DNS Twister
More to come.
He already knew about Cloudflare Tunnels. I mentioned ngrok, localtunnel, etc., and then I started thinking about what a super-lightweight tunneling client might look like if it were optimized for clawbots, MCP servers, dashboards, and random services people are increasingly running on home networks and minis.
And then I remembered I owned the tunnel.to domain name.
At that point the idea kind of lodged in my brain and refused to leave until I built the thing.
Current state:
- lightweight relay-based tunnel service
- CLI-first
- public relay nodes in North America + Europe
- TLS
- no account required for basic usage
- intended to be dead simple to expose localhost services
Right now it’s centralized. Early days, but it's entirely doable to add:
- self-hosted relays
- private relays
- agent-oriented workflows
- lightweight auth/access controls
- better relay selection/failover
Given my background I'm also in a good position to preempt abuse, so it doesn't become a timesuck. The no-registration level assigns sub-hostnames so people can't set up obvious phishing sites.
(And yes, I told my nephew about it after it was finished. He said “cool”. Hasn’t used it yet.)
If you want to get with a registrar who is actually clueful about takedowns, we can help you out.
As I posted on Krebs' article:
This is neither news nor new. There have been prior panics around this “water is wet” type issue going back at least a decade.
(Search up “Floating Domains – Taking Over 20K DigitalOcean Domains via a Lax Domain Import System” – and others).
I also wrote about this on CircleID from the DNS operator’s perspective (“Nameserver Operators Need the Ability to “Disavow” Domains”) – after this same issue was used to DDoS attack another DNS provider by delegating a domain to their DNS servers without having setup an account there, and then doing a DNS reflection attack on that domain. That was over ten years ago.
The fact that people can delegate their own domains to somebody else’s nameservers without ever properly setting up a zone on those nameservers, or ever keeping track of where THEIR OWN DOMAINS point is 100% the responsibility of the domain owner – and to varying degrees a function of their REGISTRAR – who is the only entity that has any control over it.
It’s a weird flex for corporate registrars who purport to be “high touch” and exclusive, to simply shrug their shoulders and turn a blind eye to their own clients’ obviously broken and vulnerable nameserver delegations.
For our part this is specifically one of things we actively monitor and alert our clients about.
Are you positive you didn't accidentally tick a checkbox or anything to use their nameservers?
Either the spammers haven't figured it out yet, or they realize it's a waste of time since all the messages are either mechanically processed or ignored.
Not one mention that inflation is caused by the government and central banks expanding the money supply.
I was a huge HHGTTG fan (counting Disaster Area among my top musical influences)
When I was at UWO in the early 90's Douglas Adams came on campus for a book signing - it was to last about 45 minutes, and it was scheduled right in the middle of one of my exams.
So I decided to sit the exam, thinking "I'll catch up with him at a future book signing", alas he died before I ever got the chance.
If you're just using free relays you will get inundated with spam.
I was running an open relay for awhile and closed it up because of this.
(Lightning is the magic lubricant that makes Nostr so promising).
> Non-controversial sites do not get shut down.
A.k.a "nothing to hide, nothing to fear".
Or are you asking for a source on somebody getting deplatformed for saying that, and Dr. Peter McCullough comes to mind there.
The Great Barrington Declaration was also de-indexed from Google for disputing lockdowns.
Zerohedge was kicked off Twitter for suggesting that the Wuhan Institute of Virology was a likely candidate for the origin.
We're seeing that Fauci & Ecohealth co-ordinated the paper to "debunk" the lab leak theory and now the lab leak is looking to be the most likely culprit (it is not without precedent, the 1977 Russian Flu turned out to be a lab leak from gain-on-function research).
Ivermectin, was another. Complete with "horse de-wormer" smears and deplatforming campaigns all over the place.
If you don't know of any instances where this has happened, you either did a masterful job tuning it all out, or still believe 99% of the b/s.
Because when those domains become defunct or expire, anybody recognizing what they were could grab them and inject malicious code into all the websites with the broken widgets embedded (we've seen this happen with crypto miners, etc)
This kind of a mechanism (along with domainconnect) could work - but it would also need the browsers (perhaps with a plugin?) to verify a domain on embedded components before rendering them.
That would add a lot of DNS lookups though.
Overall a good effort. Would be good to see something along these lines gather some traction.
easyDNS spokesbot here.
We take the same attitude toward our client domains regardless of political affiliation or orientation.
In the past we were the DNS provider for both BLM and Antifa, who brought in their fair share of takedown requests and are arguably left-of-centre.
When we were added as a defendant in a defamation suit because we wouldn't take the website down ahead of a court ruling, that was a legal battle between two different factions of socialists - which we're not a fan of - we still fought the lawsuit at our own expense.
Everybody seeking to deplatform an easyDNS customer because of their political ideology gets the same answer: "GFY".
(Or you could read the legislation itself, but Canadian bills are hard to read because they are these kind of Frankenstein concoctions of lines that are stricken from other acts and new lines that are added).
Those deficits are filled in by bond issues. Those bonds have been increasingly monetized by the Fed:
https://fred.stlouisfed.org/series/FDHBFRBN
This known as "Quantitative Easing" - which is printing money.