HNHacker News
TopNewBestAskShowJobs

dxld

60 karma · joined July 29, 2011

Email: hn@dxld.at

Social: @dxld@pleroma.debian.social | pleroma.debian.social/dxld

Websites: dxld.at (boring), ipv6.monostack.org (interesting).

Debian: qa.debian.org/developer.php?login=dxld

Patches I sent: lists.sr.ht/~dxld/outbox

sr.ht: git.sr.ht/~dxld

Github (historical): github.com/DanielG

submissionscomments
dxld··on IPv6 Is Hard
Here's to hoping, but I agree one way or another one stack needs to go :-)

BTW: Contact info is in my profile if anyone wants the inside scoop. The project just isn't fully ready for public launch yet, but we're well into the cooking.

dxld··on IPv6 Is Hard
I would agree with you were it not for the fact that I'm personally investing my time into a FLOSS project to make sure the growth does not slow down by making “tomorrow NOT like today”, but gets a kick in the butt once we reach the 50% deployment inflection point instead. Stay tuned ;-)
dxld··on IPv6 Is Hard
Good news: it's 20 years, not 100, at the most :-)

https://labs.apnic.net/index.php/2024/10/19/the-ipv6-transit...

dxld··on Ask HN: Are you aware of a sane path to selfhosted email server?
I've been really impressed with Mox, an all-in-one monolithinc mail system written in go: https://www.xmox.nl

Trivial to setup, guides you through configuring SPF, DKIM, DMARC, MTA-STS, DANE and DNSSEC. Handles certificates by itself through ACME, comes out-of-the-box with IP/domain reputation based and bayesian spam filtering.

While I've come to appreciate how much tweaking you can do with something like exim I'm starting to see the advantage of not having to spend time doing any of that :)

Mox also has some really cool (and AFAICT) novel features stemming from the fact that it's so tightly integrated. Have a look at the "Rejects" mailbox, or the nuanced way it rejects spam at SMTP time to prevent the dilemma between causing backscatter or potentially dropping mails (like gmail likes to do). I've also never heard of REQUIRETLS before seeing it exposed right there in Mox's built-in webmail.

dxld··on Louis Rossmann – The best way to watch online video; my yearlong project is done
> And you believe that you can scare some random scammers in some random country that doesn't recognize copyright or trademarks with a US trademark?

You make my own point sir. They're not going to care about copyright either. So may as well make this proper FLOSS.

dxld··on Louis Rossmann – The best way to watch online video; my yearlong project is done
A more appropriate solution to the problem of cloned FLOSS apps is establishing a trademark.

I mean he says it right before the proprietary apologism, the problem is pointing people in the direction of the project by name only for them to find malware ridden clones. Well. The problem here isn't the software being cloned, the problem is the same name being used by the attackers.

dxld··on Louis Rossmann – The best way to watch online video; my yearlong project is done
He's calling this "Open Source" but it's under a proprietary license: https://gitlab.futo.org/videostreaming/grayjay/-/blob/master...

> [...] we grant you a [...] license to access and use the code solely for the purposes of review, compilation and non-commercial distribution.

> We may suspend, terminate or vary the terms of this license and any access to the code at any time, without notice, for any reason or no reason, in respect of any licensee, group of licensees or all licensees including as may be applicable any sub-licensees.

Bummer.

dxld··on What I wish I knew when I got my ASN
Sad to say I'm surprised the proprietary vendors are lagging behind here, but there should be no architectural reason you can't deploy a more reasonable firewall.
dxld··on What I wish I knew when I got my ASN
Well dnsmasq has --dynamic-host for this use-case. Example:

    dynamic-host=cafe.dxld.at,::cafe,lan0
Firewalls tend to support DNS, use it :)

I know for a fact nftables and pfSense allow this, worst case you need a cronjob to periodically reload your ruleset to refresh the DNS data as it's evaluated at ruleset load time (for nftables). Incidentally another TODO project of mine is a daemon to allow running scripts when RA information (such as the prefix) changes, this would come in handy here too.

For anyone interested in making IPv6 bettter come talk to me in #ipv6:ungleich.ch (Matrix).

--Daniel

dxld··on What I wish I knew when I got my ASN
You can use ip-token(8) on Linux to define a static interface-id, the part of the IP usually auto-generated based on MAC address when using SLAAC instead of making the whole IP static.

In ifupdown I usually just add something like the following

    pre-up ip token set ::cafe dev $IFACE
This way when you get a new GUA there's no need to "renumber" your network manually as everything will just happen automatically. When your router includes a new prefix in the router advertisement all hosts on the LAN generate new addresses for this prefix.

Couple of gotchas. 1) The ip-token call has to happen before the interface is marked up (as in ip link set dev $IFACE up, not link presence) so if you want to change it you have to take it down first. 2) If your ISP's router doesn't cleanly announce the old prefix to be deprecated (due to a reboot say) it may remain in use by hosts until it's lifetime expires. See RFC4192 for how renumbering is supposed to work.

FYI: I'm working on a small daemon that will monitor RA and deprecated the prefix to handle broken ISP routers.

--Daniel

dxld··on Introduction to Linux interfaces for virtual networking (2018)
I found networking/switchdev.txt very approachable. It documents all those different bridge+vlan (aware/unaware) configs you can do: https://docs.kernel.org/networking/switchdev.html

In particular I've learned from that doc that there's special handling for putting a vlan device on top of a bridge (br0.123) even if the bridge is vlan unaware.

DSA might also be relevant if you're working with hardware that supports it: https://docs.kernel.org/networking/dsa/dsa.html

dxld··on Hacking the LG Monitor's EDID
OP's approach looks cool but a bit baroque. I'm also hacking around EDID issues and it turns out there's a nice GUI program to decode and (lightly) patch it: https://packages.debian.org/unstable/utils/wxedid

I have to do more involved full EDID reconstruction surgery tho since I need to add DTD entries rather than just change existing ones. So I'm looking at [edid-generator] together with [cvt12]. The latter can calculate xrandr modelines for VESA standard timings that all seem to work with my TV. cvt12 adds the option to calculate NTSC (1/1.001) timings over regular cvt which is already in Debian.

[cvt12]: https://github.com/kevinlekiller/cvt_modeline_calculator_12

[edid-generator]: https://github.com/akatrevorjay/edid-generator (thanks Kodi wiki)

dxld··on Hacking my “smart” toothbrush
Hacking the NFC comms is fun and all, but it turns out you can just rip out the orange flatflex PCB under that metal ring with a screwdriver and the brush doesn't care :)

Stops it from beeping at you when your allotted product lifetime is up though.

dxld··on Ask HN: What is the coolest thing you have seen done with a bash script?
Sounds interesting, could you elaborate on the details? :)
dxld··on tcpcp - passing TCP connections between hosts (2005)
I was looking into this some years back when I was considering building a high-availability IRC bouncer that can pass the TLS IRC connections around with this.

There isn't anything out of the box that I could find, but there was some discussion/prototyping around adding an API for exporting all the necessary key material and metadata to the mbedtls API. With that it would have been "relatively" "easy" to do the TLS bits :)

See https://github.com/Mbed-TLS/mbedtls/issues/3141 and linked ML posts.

dxld··on Ask HN: Do you still monitor your SSL certificate validity?
I just use a cron job that calls openssl s_client. The trick is to use faketime to check if the certificate would be valid in the future, like so:

  check_tls () {
          # Check two weeks in the future to give us time to fix certs
          faketime +14days \
                  openssl s_client -showcerts -verify_return_error "$@" \
                  </dev/null || exit 1
  }
The -verify_return_error option makes s_client return an exit code on cert validation failure. Then just loop over the hosts/ports you want to check, wrap the whole script in cronic/chronic to ignore output when it doesn't fail and bam no need for a service to do this. Just have to be able to interpert s_client output ;)

An example with dual stack IPv4/v6 https/smtp/imap support:

  for af in -4 -6; do
          for connect in \
                  www.example.org:443 \
                  \
                  mail.example.org:465 \
                  mail.example.org:993 \
                  ;
          do
                  check_tls $af -connect $connect
          done
  
          check_tls $af -starttls smtp -connect mail.example.org:25
          check_tls $af -starttls smtp -connect mail.example.org:587
          check_tls $af -starttls imap -connect mail.example.org:143
  done
Note that s_client doesn't check if the hostname passed is correct for the certificate it receives by default. To turn this on use the -verify_hostname option (https://www.openssl.org/docs/man3.0/man1/openssl-verificatio...)
dxld··on My cheapskate commenting system
I use maildrop with a .mailfilter file, works fine but it's not exactly new either :)
dxld··on My cheapskate commenting system
> Art. 2 GDPR: This Regulation does not apply to the processing of personal data: [...] (c) by a natural person in the course of a purely personal or household activity
dxld··on Hetzner announcement: Price changes for servers ordered via the Server Auction
I got one too, only for one of my two servers though:

    The monthly prices will change for the following servers you use:
    
    Server name             new price      old price      Starting on
    SB42 #xxxxxx            43.20 Euro     40.31 Euro     2022-03-15
Doesn't seem so bad to me.
dxld··on Rewatch: Stargate SG-1 (2019)
The SG:U story you mean? FYI there is a comic that continues right where the show left of: Stargate Universe: Back to Destiny.
dxld··on Hetzner now provides IPv6 only dedicated servers
You can actually request a /56 per-server for a one-time fee of, IIRC, 60 EUR or so. Just talk to support since it's not listed anywhere in their docs for some reason.
dxld··on Sign in with Matrix
Ah you're right that would be pretty dangerous. I was hoping it'd be possible to avoid sending an OTP token the user has to paste but I suppose that's necessary to bind the two contexts together.

Then I guess I'd have the backend send the user a link with an auth token after joining, that way at least no pasting needs to happen.

dxld··on Sign in with Matrix
Crazy idea: what if you use a random room ID as an OTP and recognize the user as signed-in as soon as they join that room via an invite or matrix.to link? I'm not sure if this fits within your constraints since it would need a backend but I think it'd be pretty neat :)
dxld··on Password Managers
Could you share a link to your thesis?
dxld··on Power-cycling a USB port should be simple, right? (2017)
Took me a while to find this again, but here you go: https://www.yepkit.com/product/300110/YKUSH3, a 3-port USB 3.1 Hub with switchable Vbus that doesn't cost an arm and a leg.
dxld··on RansomEXX Trojan attacks Linux systems
I've been thinking about this problem for a while now. Personally I use restic[1] and B2 with a dedicated API key that can't delete anything.

[1]: Patched slightly to make it work, https://github.com/restic/restic/pull/2398 (hope this will get merged eventually)

How one goes about not accumulating backups forever is a problem with this setup. My basic plan is manually switching to another bucket and verifying the newly backed-up data before deleting the old bucket.

You can also enable a time-based deprecation of hidden files on B2 then you don't have to actively do anything, but in theory if the malware bides its time it could still delete/overwrite everything without you noticing.

If you want to self-host the restic/rest-server also has a --append-only flag that would have a similar effect, but if you use that you'll have to make sure the malware can't hop onto your backup machine via ssh.

dxld··on IPv6 Is a Nightmare
I think this statement should be considered more as a criticism of pfSense and not of IPv6 in general. In fact there are a number of RFCs around how IPv6 firewalling should be implemented on _consumer_ routers but since pfSense seems to be mostly aimed at enterprise customers my guess is they don't necessarily follow all that.

Specifically I'm referring to:

- RFC4864 | Local Network Protection for IPv6,

- RFC6092 | Recommended Simple Security Capabilities in Customer Premises Equipment (CPE) for Providing Residential IPv6 Internet Service and

- RFC7084 | Basic Requirements for IPv6 Customer Edge Routers, which pulls in the other two by reference.

In fact RFC4864 is specifically about this "Perceived Benefit of NAT" and how to preserve the security benefits in the v6 world.

[RFC4864]: https://tools.ietf.org/html/rfc4864

[RFC6092]: https://tools.ietf.org/html/rfc6092

[RFC7084]: https://tools.ietf.org/html/rfc7084

Just as an example, OpenWrt, a more consumer focused router distribution follows RFC7084 and provides the default deny behaviour on IPv6 ingress from WAN much like IPv4-NAT would do.

Also note that IMO the author is simply conflating NAT as known in the IPv4 world with it's usual implementation of actual Address Translation plus Stateful firewalling. In fact prefix translation which he's going on about here isn't necessary at all to be exposed to this security problem.

Just plugging a IPv6 (and DHCPv6-PD) capable router into a WAN would do if it weren't for the stateful firewall.

dxld··on More than 1/3 of all access to Google is now over IPv6
You might be interested in this service: https://no-ipv4-here.ungleich.ch/
dxld··on Terminal Server on a Budget
> One small disadvantage not addressed is that neither of the two motherboards support BIOS access via COM1, which is a bummer.

I've always wondered if you could burn SGABIOS (https://code.google.com/archive/p/sgabios/) to a PCI(e) card ROM to get this working on real hardware instead of just in QEMU.

Apparently someone did try this, so it might just work: https://www.flashrom.org/User:GNUtoo/Howto_flash_sgabios_on_...

Maybe I should dig up some old flashrom supported NIC card or something.

dxld··on Choosing a template for a geek's website. Did I do it right?
Mine looks like that: https://darkboxed.org/
Page 1 of 2Next →