HNHacker News
TopNewBestAskShowJobs

pawal

544 karma · joined October 26, 2015

DNS and crypto stuff. [ my public key: https://keybase.io/pawal; my proof: https://keybase.io/pawal/sigs/jYJ6KJTNu3VkILzDf2ra7j0TRxYo08q8p9OSBVVkGEU ]
submissionscomments
pawal··on deSEC – Free Secure DNS
Also have a look at gonemaster, the modern replacement: https://gonemaster.evilbit.de/
pawal··on Tracking the BitTorrent Tracker Infrastructure
This is a continuation of work I started 14 years ago. Now I can track the BitTorrent trackers DNS changes, IP addresses, and ASN, and see how and where they are hosted.
pawal··on Gonemaster checks the DNS health of a domain
gonemaster checks the DNS health of a domain by running it through a series of testcases grouped into modules. Each testcase emits log messages that are scored into a numeric result and a letter grade.
pawal··on Choosing a Public DNS Resolver
The author merely suggests that those 29 or in someway trusted by a lot of people to handle DNS queries. Those 29 also publish information on what properties the service have. If you read the whole page, the author also lists other publi DNS resolvers worth a mention.

For the long tail of unknown open DNS resolvers, use Shodan. But I would not suggest that you use any findings from Shodan to trust your internet usage with.

Yes, SNI is a generic internet privacy problem. However, it is not a property of DNS. On the positive side, ECH has been pushed through the IETF and should slowly be available to the general user.

/ The author

pawal··on Choosing a Public DNS Resolver
Done, enjoy: https://evilbit.de/dns-resolver-guide.html#speedtest (DoH only)
pawal··on Choosing a Public DNS Resolver
Author here: Because of their continuing work on privacy, https://blog.cloudflare.com/1111-privacy-examination-2026/ However, as a EU citizen, I would not trust them anyway because of FISA 702.
pawal··on Choosing a Public DNS Resolver
Author here, I added this now: https://evilbit.de/dns-resolver-guide2.html#speedtest Only works for DoH though.
pawal··on Vectrex Mini
Interesting, but a Vectrex without a vector display is like a fish without water.
pawal··on SoftHSM2 Maintainer Needed
It seems like the development of SoftHSM2 has stalled quite a bit. There is still a lot of user interest, but very little action in terms of management of the project. There are many pull requests and issues raised by users, but very little in terms of taking care of those.

SoftHSM was originally developed as a PKCS#11 and HSM test platform for OpenDNSSEC, but later took on a life on itself. The reason for that is that there is a lot of need to use software that talks to Hardware Security Modules, but without actually spending the cash of buying one, mostly for development. But it has also become a cornerstone of a lot of other products, for example IBM Red Hat Identity Management.

NLNet Labs states in the GitHub issue linked: "Given the above, the current state is that development on SoftHSM v2 is dormant and not likely to pick up significantly in the near future. We are conferring as a team on how to proceed in the future, but this will likely take us until at least the summer of 2024."

So the future of SoftHSM does not look very great. Are there any organizations reading this willing to take up this challenge, and make the future of this small "insignificant" open source project great again?

pawal··on DKIM: Rotate and publish your keys
Not if you want to deliver e-mail to Google, they recently added this as a requirement.
pawal··on Jackson structured programming
Me too. Still have a couple of books (in Swedish) on the subject. I don't have the heart to throw them away.
pawal··on Why I Wrote PGP (1999)
Yes, export regulations were heavy back then. To have proper SSL in your Netscape, you had to import this patch file from Australia. And then we had this whole Crypto Wars thing going on. Look at Steven Levy's excellent book on the subject, or search on the Wired archives.
pawal··on New UUID Formats – IETF Draft
There are a number of different tools for writing internet-drafts. See here: https://tools.ietf.org/tools/
pawal··on What's Inside the EU Green Pass QR Code?
The downside of this is that the lookup is done online, and every use of an individual is tracked per service. This is not something that I am comfortable with.
pawal··on Tor Browser 8.5
Yes, I use it often. My Debian installations use Tor for installing updates. Just as an example.
pawal··on Using Let's Encrypt for Internal Servers (2018)
In practice internal only DNS names will always leak to external resolvers in one way or another. Pretending otherwise is very naive.
pawal··on I'm still not using GUIs in 2019: A guide to the terminal
The problem I have with ^B is that the b is too far away from ctrl. A is much closer, which makes it a much faster one-hand press.
pawal··on WiGLE: Huge WiFi Networks Geolocation Map
You should probably be more freaked out by your phone. It collects this data by default and sends it to Google or Apple. I think that Google still has an API for querying their database.
pawal··on Migrating from Google Analytics
Is there a privacy friendly analytics tool that does not set cookies and store data Forever? I don't really care about perfect user analytics, just good enough. Maybe by analysing logs. In the 90's there was s lot of good tools like this, but now everybody has gone cloud. I can't imagine the tools offered today are compatible with GDPR.
pawal··on IPv6 xmas display uses 75 Internet's worth of addresses
Please go ahead and Read RFC4941.
pawal··on Keystone – Open-source Secure Hardware Enclave
A related project is https://cryptech.is, an open hardware HSM.
pawal··on How I recorded user behaviour on my competitor’s websites
You bought a TLD when learning web development? That seems extreme.
pawal··on How Does Mastodon Work?
Would you say the same thing about e-mail and SMTP?
pawal··on Ask HN: What are the things that you have automated in your personal life?
Does this make you avoid reading very long books?
pawal··on How a domain registrar can kill your business
For a very long time, DNS simply has not been an identified risk for most corporations. In the risk analysis they make, DNS is not on the map at all, even though it may be a single point of complete collapse for them. Thus we see extremely large corporations depending on a single DNS provider, using a registrar that are more interested in profit rather than resilience against attacks, no DNSSEC. Etc etc. This is slowly changing. What is. Not changing fast enough is the ability to run more than one DNS provider, giving you yet another spof.
pawal··on Hijack of Amazon’s domain service used to reroute web traffic for two hours
We should not "give up on BGP". What we should do is to improve security in all layers. This includes BGP, and as you mention DNS. DNSSEC should be mandatory, just as TLS, for any business that take themselves seriously.
pawal··on Google Workers Urge C.E.O. To Pull Out of Pentagon A.I. Project
Anybody looking forward to the captchas asking us to identify drone targets?
pawal··on Someone stole my Instagram username
Nothing is going to happen. I have seen this several times now, and support does not lift one finger to give back the account to the original owner. Expect russian spambots to post images in a few weeks time.
pawal··on iOS 11 Security [pdf]
Sony.
pawal··on Introducing Token
This reminds me of the Java Ring, that was almost 20 years ago.
Page 1 of 2Next →