I don't believe it would take too much lift to automate this with a scanner+some software.
114 karma · joined March 12, 2017
I don't believe it would take too much lift to automate this with a scanner+some software.
The centralization of email services to a handful of providers basically has led to multihoming of millions of domains that open SPF auth to the same handful. Any integrations by them or changes to existing stack can cause issues to pop up, because delegation of sending rights isn't strictly auth controlled. The same also happens with dkim delegation to saas providers who share backend keys across other customers of theirs and if their API is open to experiment (or an account gets popped) then the customer domains are possibly at risk.
Email is hard to do right. No auth no entry should be the default. But majority of domain owners aren't very good at figuring out how to secure things, or have business/product interests that are a priority, specially when delegated and authorized to third party senders on their behalf.
FWIW although this article says many had oc48s by early 90s I can tell you that wasn't a thing till much later. The fact that I have a FTTH node at home that's faster than that today a severe fraction of the cost, and consumer 2.5g switches below $200 just blows my mind. The planning required during migrations alone for all failivers required calculations back then and I can unplug a cat6 today without sweating
Then used openbsd at work. And Solaris/redhat etc.
Until Ubuntu.
It's just so darn easier for most things. And it just works. Debian++.
Still like installing freebsd once in a while on a VM to tinker on, and some services are probably still best run on it comparing to others.
But using freebsd as a desktop? .. not sure I'd go that far.
The other thing that works well with this for a life upgrade on a mac is finicky (GitHub.com/johnste/finicky )