Tootfinder

Opt-in global Mastodon full text search. Join the index!

@adrianco@mastodon.social
2025-10-20 11:36:39

I write up some of my advice on surviving DNS outages as it seems timely #AWS #DNS adrianco.medium.com…

@jamesthebard@social.linux.pizza
2025-12-22 07:46:41

The standalone Proxmox server is basically done at this point, all three DNS servers are online and secure, the Tailscale VM is online after completely forgetting that it was running on one of the Raspberry Pis, and the `authentik` instance that I'm gonna need to work on tomorrow.
#proxmox #dns

A screenshot of a Proxmox virtualization server with 5 VMs on it running on an 8C/16T AMD CPU with 32GiB of RAM.
@x_cli@infosec.exchange
2025-12-22 12:56:32

@… Hey, it is me again 😅
Just to let you know that I receive some 400 Bad Request errors from some DoH servers (dns.quad9.net and ns0.fdn.fr for instance) while some others accept my queries (dns.google and Cloudflare 1.1.1.1).
I am not sure yet if the error is on my use of the library or within the library itself.
Here is the code to run the query:

@fanf@mendeddrum.org
2025-12-19 21:42:01

from my link log —
The disappearing Windows DNS debug log.
nxlog.co/disappearing-windows-
saved 2019-01-10

@kubikpixel@chaos.social
2025-10-20 14:45:31

»Amazon Web #Service's — DNS-Problem legte zahlreiche #Online-Dienste lahm:
Wenn es einmal bei einem der großen #Cloud Service #Provider

@Erikmitk@mastodon.gamedev.place
2025-10-23 06:48:47

I switched away from GitHub to host my (so far) boring ass website somewhere else and obviously had DNS issues!
Adjusted DNS records and it worked smoothly everywhere except on my own machine where they could not be found *at all* (not even outdated ones). But waiting it out obviously fixed it in the end. I’m no AWS so nobody noticed or cared. 😵‍💫

@grifferz@social.bitfolk.com
2025-11-19 10:55:08

"Self-hosting DNS for no fun, but a little profit!" – Morten Linderud
linderud.dev/blog/self-hosting

@ELLIOTTCABLE@functional.cafe
2025-10-21 07:14:50

regarding AWS' outages yesterady

stylized oriental greeting-card with the haiku:

it's not DNS
there's no way it's DNS
it was DNS.
@losttourist@social.chatty.monster
2025-10-23 09:04:29

If it's not DNS, it's usually a race condition.
AWS: wheeeeee, we had both!
#AWS #AWSoutage

@tinoeberl@mastodon.online
2025-10-21 15:17:33

Heute hat die Welt mal wieder gemerkt, wie das so ist, wenn man von US-amerikanischer IT abhängig ist, oder?
Wie hoch ist die Chance, dass die Welt nach diesem zichsten Ausfall von großen Anbietern endlich mal etwas lernt?
#Cloud #DNS

@EarthOrgUK@mastodon.energy
2025-12-21 19:51:02

On Website Technicals (2025-10) - Tech updates: Sitebulb AdSense fails, RSS description, lite ads, ISSN lookup, micro-opts, DNS broke intensity, SVG inline URL-encoded, CO2 pcm, flock. - m.earth.org.uk/note-on-site-te

@kubikpixel@chaos.social
2025-10-20 05:50:05

»DNS0 ist abgeschaltet. Ein Rückblick auf das kurze Leben des EU-finanzierten DNS-Resolvers.
DNS0 ist Geschichte. Betreiber war eine französische Non-Profit-Organisation, 2022 gegründet von Romain Cointepas und Olivier Poitrey.«
Das in Europa ein freier & offener DNS Dienst was wichtiges ist nimmt so gut wie niemensch ernst. Selbst IT-Techniker ist es mMn dem nicht wirklich bewusst.
🔌

@groupnebula563@mastodon.social
2025-10-23 09:20:21

@… hey, just reaching out to let you know that b.diasp.org seems to go to some spam blog now (i assume DNS records were never updated)
side note: is there an activitypub plu…

@GroupNebula563@mastodon.social
2025-10-23 09:20:21

@… hey, just reaching out to let you know that b.diasp.org seems to go to some spam blog now (i assume DNS records were never updated)
side note: is there an activitypub plu…

@jtk@infosec.exchange
2025-10-20 11:59:18

Have you noticed that when the blame #DNS meme starts flying the root is perfectly operational, there is rarely a mention of the big registry operators, BIND, Unbound, Knot, and PowerDNS are absent the conversation, and many who can craft a reasonable dig query are getting responses from local and public resolvers to debug?
Even with all the misconfiguration, added complexity on top of it, a…

@jamesthebard@social.linux.pizza
2025-12-21 22:11:30

Started migrating services off of the RPis and onto the new #Proxmox server. The initial install went fairly smoothly, got the VLANs configured, and then setup the new primary DNS server. That took longer than it should have, but I will say this: the VM is so much more snappy than the Pi. Next up is the secondary DNS server.

The new DNS server `fastfetch` output showing it running Debian 13 on 2 vCPU and 1 GiB of RAM.
@heiseonline@social.heise.de
2025-12-09 18:31:00

Beschwerde: Karlsruhe stoppt umstrittene DNS-Überwachung einstweilig
Das Verfassungsgericht hat die Anordnung eines Amtsgerichts zur Überwachung von DNS-Anfragen auf eine bestimmte Domain nach Beschwerde des Providers ausgesetzt.

@fanf@mendeddrum.org
2025-10-23 11:23:32

how to use standard DNS UPDATE in a manner that avoids causing outages like AWS us-east-1 lobste.rs/s/mw0pus/summary_ama

@stsquad@mastodon.org.uk
2025-10-20 10:52:56

It's never a good sign when your Monday morning feed is full of #dns and #aws memes. Monday's eh? 🤷

@skaverat@skaverat.net
2025-10-20 09:28:01

It's always DNS.
If it isn't, it's BGP. Which is just fancy DNS.
#awsdown #aws

@Techmeme@techhub.social
2025-10-20 14:04:04

AWS says "the underlying DNS issue" is mitigated and most "operations are succeeding normally" after a huge US-EAST-1 outage; some services are still "impacted" (Jess Weatherbed/The Verge)
theverge.com/news/802486/aws-o

@cyrevolt@mastodon.social
2025-10-21 23:31:06

ASRock Rack giving me some 500 in a popup... funny.
Edit: That was on my laptop, but fine on my phone, and also not occurring to someone else on the same Wi-Fi. It may have been one of those DNS whoopsies.

@x_cli@infosec.exchange
2025-12-22 13:35:16

Many #Terraform providers using SSH do not check the SSH host key... they just run with ssh.InsecureIgnoreHostKey...
And to be honest, it is partly the fault of the SSH standard library which makes it super easy to ignore the host key and does not provide any useful builtin key verification function. People are lazy. ssh.FixedHostKey is niche.
So I implemented a small library to v…

@grifferz@social.bitfolk.com
2025-12-21 04:30:53

3 days ago the RSS feed of planet.ubuntu.com stopped working due to a TLS cert error.
I THINK it's due to them overhauling & moving it to a github-hosted replacement, but as this was done just by redirecting DNS the new host doesn't have a TLS cert with the correct name. If so, this means that people following the old RSS feed can't do so any more and they got no notice that this was going to happen.
I don't know for sure though because my query remains unansw…

@gwire@mastodon.social
2025-10-20 20:42:57

> The underlying problem today was a malfunction at Amazon Web Services, where something called "DNS resolution" was not working
BBC putting quotes around "DNS resolution" there, like it's indecipherable Gen-Z slang.
bbc.co.uk/news/live/c5y8k7k6v1

@dawid@social.craftknight.com
2025-10-21 08:25:50
@… Mam na samym routerze zainstalowany AdGuard Home, jak się podpinam pod WiFi u znajomych to mam taki mindfuck jak wygląda teraz internet zawsze - bez adblockera na DNS nie da się go używać.
@almad@fosstodon.org
2025-10-21 14:18:18

Maybe all of those people that were laid off were doing some work?
theregister.com/2025/10/20/aws

@peterhoneyman@a2mi.social
2025-10-21 01:29:24
Content warning: MacOS Tahoe nerditry

$ sudo dns-sd -O
XPC service returns error, description: State dump is currently disabled due to system privacy settings. To enable it, install the [mDNSResponder Logging Profile](developer.apple.com/bug-report) and res…

@usul@piaille.fr
2025-10-16 09:21:40

NetBSD mail server with Postfix, BIND (for DNS), Dovecot, Pigeonhole (Sieve), SSL, DKIM and SPF
#email

@fanf@mendeddrum.org
2025-11-15 18:42:03

from my link log —
Behind the complaints: investigating the suspicious pressure against archive.today.
adguard-dns.io/en/blog/archive
saved 2025-11-15

@hanno@mastodon.social
2025-12-10 08:25:24

German ministry renames itself, domain expires, is bought by SEO-spammer, expires again, is bought by domain grabber, then later bought by itsec company who now learns that apparently plenty of internal systems of the ministry still try to connect to the domain...
I don't even know where to start how terrible that is and what it tells us about government IT security practices...

@Stomata@social.linux.pizza
2025-10-20 16:53:31

No, it's not DNS! It can't be!

@whitequark@mastodon.social
2025-11-18 18:18:41

you can bring down 20% of the internet with a single-character typo in a regex, but you can also destroy a nearly 50 year old bridge with a single incorrectly placed piece of heatshrink
isn't technology beautiful
blog.cloudflare.com/details-of

@axbom@axbom.me
2025-10-18 09:58:53

Jag kanske inte ska ropa hej. Något verkar ha ändrats i deras DNS den här morgonen. Jag snubblade över det av en slump(!), tro det eller ej. Kanske har de bara tillfälligt klantat till det så att det kommer tillbaka om några timmar.

Spännande ändå. Och faktiskt helt galet att jag upptäckte det. Satt och pillade med ett eget verktyg för att visa kortlänks-destinationer utan att behöva klicka på kortlänken. Kom ihåg QR-kodlänken och testade med den. Fick felmeddelande direkt. Trodde verk…

@fanf@mendeddrum.org
2025-11-19 21:42:01

from my link log —
trustydns: DNS Over HTTPS proxy, server and query programs.
github.com/markdingo/trustydns
saved 2019-06-28 do…

@arXiv_csCR_bot@mastoxiv.page
2025-09-30 12:07:01

LLUAD: Low-Latency User-Anonymized DNS
Philip Sj\"osv\"ard, Hongyu Jin, Panos Papadimitratos
arxiv.org/abs/2509.24174 arxiv.org/p…

@mlncn@social.coop
2025-12-19 01:30:28

defend612.com has been blocked at the domain name level for me and at least two other people over T-Mobile networks (which includes GoogleFi, MetroPCS, and… wait for it… Trump Mobile). For at least all day today.
Seems unlikely to be a technical problem but instead to be Actual Censorship (unless its not …

Screenshot of a smartphone browser with defend612.com in the address bar and a sketch of a sad piece of paper followed by the text:

This site can't be reached.

Check if there is a typo in defend612.com

DNS_PROBE_FINISHED_NXDOMAIN
@Adam@social.lein.us
2025-11-18 14:00:49

Looks like Cloudflare DNS is still fine but the proxy that's supposed to protect against DDoS stuff is what's causing everything to be down.

@fanf@mendeddrum.org
2025-11-14 21:42:02

from my link log —
Fuzzing DNS zone parsers.
cambus.net/fuzzing-dns-zone-pa
saved 2019-07-12 dotat.at…

@selea@social.linux.pizza
2025-12-15 14:06:40

I find it really amuzing that IT-departments around the world is just plainly copying the example DNS-records in my blog-posts about DMARC.
Resulting in me getting reports about their domain to my inbox
#dmarc #email

@hynek@mastodon.social
2025-09-26 09:07:07

TIL my beloved `dog` DNS client has been unmaintained for a few years and there's a community-based fork called `doge` (the name was chosen before it became a synonym for chainsaw politics): dog.ramfield.net

@usul@piaille.fr
2025-10-17 09:03:30

In the recent ICANN Registrations Operation Workshop 30th September 2025, the
following data was shared about DNSSEC Validation Rates
- Region / Rate / Increase since 2023
- Asia 32% 4%
- Oceania 54% 11%
- Africa 46% 15%
- Americas 37% 4%
- Europe 48% 8%
#dns #dnssec

@ian@phpc.social
2025-12-17 01:53:06

The penultimate talk at #12Clouds is Akshay M talking about Agent Name Service (ANS), a DNS-like trust layer for AI agent deployments

@shaun@mastodon.xyz
2025-12-17 04:27:23

Wrong.
#google #ai #slop

A Google search results page for an IP address in 4.2.96.0/24. Google's extremely artificial and totally unintelligent "ai" overview claims that IP somehow falls within 4.2.2.1 - 4.2.2.6 and is one of the level3 DNS servers. All wrong.
@marcus@hachyderm.io
2025-11-17 07:09:44

Our friends at tinfoil-factory recently made the initial release of netfoil - a severely hardended minimal filtering dns proxy written in #golang - Seems very useful for reducing the attack surface of your services. #security github.com/tinfoil-factory/net

@x_cli@infosec.exchange
2025-12-19 13:56:55

@… This is me again 😅
Using DoH, I get a weird EOF error during the dnshttp.Response conversion of the HTTP response.
The response was sent using the dnshttp.ResponseWriter implementation.
Digging into the implementation of the ResponseWriter, I see that you truncate the two leading bytes (response size) of TCP answers:

@newsie@darktundra.xyz
2025-11-19 10:04:00

China-aligned threat actor is conducting widespread cyberespionage campaigns therecord.media/china-aligned-

@whitequark@mastodon.social
2025-10-17 08:00:28

i should put some weird shit into DNS. no, weirder than that

@Stomata@social.linux.pizza
2025-11-12 18:43:08

Run DNS speed tests and compare different DNS resolvers in your browser.
codeberg.org/Stomata/DNSspeedt
Forked from:

@jtk@infosec.exchange
2025-11-27 15:58:43

I can help but feel this "feature" should raise more concerns than it does alleviate them.
"Accelerated recovery for managing public DNS records addresses this need by targeting DNS changes that customers can make within 60 minutes of a service disruption in the US East (N. Virginia) Region."

@bthalpin@mastodon.social
2025-09-25 08:57:19

If you're using Pi-hole with Sky Broadband, you can't directly change the DNS settings for the router (in my case a Sky Hub).
However, if you save the settings as a file, edit the file to add the Pi-hole's address in the DNS field, and re-import it, it appears to work.
pistonheads.co…

@manawyrm@chaos.social
2025-11-03 11:40:48

PSA: Use the "accounturi" feature of Let's Encrypt CAA!
If you're hosting a safety/security-critical service, there's a way too unknown feature called "accounturi", that allows you to restrict TLS certificate issuance to a single Let's Encrypt account (and account private key).
You simply create a CAA record on your domain and put your LE account ID into it.
This means that attackers cannot issue TLS certificates and pull man-in-the-middle…

@kubikpixel@chaos.social
2025-10-29 10:40:08

»Exploit-Code verfügbar — DNS-Einträge unzähliger Bind-Server manipulierbar:
Angreifer können via Cache-Poisoning Datenverkehr auf eigene Domains umleiten. Allein in Deutschland sind laut BSI rund 40.000 DNS-Server anfällig.«
Mist aber auch, dem muss ich wohl nun nachgehen ob ich und/oder Kunden davon ebenfalls betroffen sind und wie behebt mensch das?
🔓

@ripienaar@devco.social
2025-12-02 08:20:22

Sweet next year letsencrypt will support a persisting DNS record so these tools don’t need access to DNS for renewal

@TFG@social.linux.pizza
2025-09-28 20:09:55

DNS. It's always DNS. Nextcloud server down? No... It's just DNS. *sigh*
#homelab

@finlaydag33k@social.linux.pizza
2025-10-30 08:40:19

>Me: *setups secondary DNS server in case primary fails*
>Primary: *fails*
>Hosts: *pretend that secondary doesn't exist*
I sure love DNS...

@timbray@cosocial.ca
2025-11-06 17:26:08

Huh… CIRA runs the .ca TLD. Not high-profile but… seem to be OK?
[Tl;dr: They’re offering a free DNS resolver, Canadian-built and -run.]
cosocial.ca/@kgw/1155034388741

@arXiv_csCR_bot@mastoxiv.page
2025-09-30 12:04:31

DNS in the Time of Curiosity: A Tale of Collaborative User Privacy Protection
Philip Sj\"osv\"ard, Hongyu Jin, Panos Papadimitratos
arxiv.org/abs/2509.24153

@gedankenstuecke@scholar.social
2025-10-29 17:45:40

Microsoft didn't want to be left out of showing everyone why having everyone and everything depend on the same 3 companies is a bad idea 😂
bleepingcomputer.com/news/micr

@zachleat@zachleat.com
2025-12-04 19:34:38

DNS stands for “DO NOT meSs with this or you’re going to have a bad time”

@almad@fosstodon.org
2025-10-25 15:56:55

I had to migrate my #DNS today, and Hurricane Electric is such a pleasurable return to 90s.
Website obviously designed by a backend engineer. Has only tables and buttons. Buttons work and do things. It's fast. It support features fancy sites do not support. On top of it, free.
12/10

@wyri@toot-toot.wyrihaxim.us
2025-12-10 18:13:39

@… and this is why I ran ad blocking on the DNS level. And browser addons that deal with most of these crappy modals

@tschundler@leds.social
2025-10-14 05:38:02

See, not always DNS! Sometimes it's BGP.

@Stomata@social.linux.pizza
2025-10-13 13:13:34

Hey #askfedi one of my family members android device is making these DNS quarries. I can't fine the culprit. I don't see any weird property apps install on it. Any idea who could be doing this?
Edit: I found syncthing is doing this. But why? Why syncthing needs this? And what is stun?
#DNS

Nextdns logs page showing 
content-signature-2.cdn.mozilla.net
stun.voipstunt.com
stun.hitv.com
stun.voipbuster.com
stun.miwifi.com
stun.internetcalls.com
stun.sipgate.net
stun.counterpath.com
stun.miwifi.com
stun.schlund.de
stun.hitv.com
stun.voipbuster.com
stun.voipstunt.com
stun.counterpath.com
stun.voip.aebc.com
stun.sipgate.net
stun.internetcalls.com
@pavelasamsonov@mastodon.social
2025-12-06 01:59:05

Tao Te Ching: The tao that can be told is not the eternal Tao. The name that can be named is not the eternal Name.
Paul Mockapetris: that's going to make it really hard to issue you a DNS address

@jtk@infosec.exchange
2025-11-12 17:43:55

.gov #DNS notes
On 2025-01-19 there were two "biden" names, bidenlibrary and bidenwhitehouse. Not so unusual. Associated names for Obama and Trump were also there and remain still. These are exec branch names but the agency responsible for them is the National Archives and Records Administration (NARA).
As of today, there are four additional "trump" labels in the …

@x_cli@infosec.exchange
2025-12-19 11:09:26

@… I am using dnsv2 to develop a "mock" DNS server for my unit tests.
I noticed that when specifying Server.Listener or Server.PacketConn, you also need to specify Server.Net or you end up with a "bad network" error when calling ListenAndServe.
Specifying the Net property seems redundant when the PacketConn/Listener properties are specifie…

@waidler@bayerwald.social
2025-09-26 10:55:43

Roon Discovery erfolgreich von mDNS auf DNS-basierte Erkennung migriert – lokale Overrides in Unbound definiert, Firewall-Regeln angepasst, Logging aktiviert. Multicast eliminiert, DNS-Transparenz und Segmentkontrolle sichergestellt. Portöffnungen auf ein Mindestmaß reduziert. ROON Server und alle Endpoints werden nun ohne mDNS zuverlässig erkannt und das Streaming funktioniert reibungslos in Richtung aller Endpoints.

Der Screen Shot ist von der ROON Weboberfläche und zeigt alle ROON Endpoints, die in unterschiedlichen VLANs sitzen. Diese werden nur unabhängig von mDNS zuverlässig erkannt.
@fanf@mendeddrum.org
2025-11-08 09:42:04

from my link log —
Async DNS with Mac OS getaddrinfo_async_start and Rust smol.
fnordig.de/2025/11/07/async-dn
saved 2025-11-08

@arXiv_qbioQM_bot@mastoxiv.page
2025-09-30 10:05:21

De novo peptide sequencing rescoring and FDR estimation with Winnow
Amandla Mabona, Jemma Daniel, Henrik Servais Janssen Knudsen, Rachel Catzel, Kevin Michael Eloff, Erwin M. Schoof, Nicolas Lopez Carranza, Timothy P. Jenkins, Jeroen Van Goey, Konstantinos Kalogeropoulos
arxiv.org/abs/2509.24952

@arXiv_physicsfludyn_bot@mastoxiv.page
2025-10-06 08:28:59

oRANS: Online optimisation of RANS machine learning models with embedded DNS data generation
Daniel Dehtyriov, Jonathan F. MacArt, Justin Sirignano
arxiv.org/abs/2510.02982

@niqdanger@social.linux.pizza
2025-09-26 16:59:22

Our certificate provider just told me I have to make my internal DNS server public, and share all my RFC1918 DNS enteries, otherwise they wont issue me certs. WTF is this shit? We have run split horizon for YEARS with no issues.

@hansaplast42@social.wastedalpaca.wtf
2025-11-05 12:19:45

Boah ey, ich glaube ich gehe mett.
Seit Monaten nehme ich mir vor meinen alten Raspi 3 durch einen 5er zu ersetzen.
Bisher macht der nicht viel außer piHole DNS blocking.
Der Plan war nun unter anderem Home Assistant zu installieren.
Warum? Weil ich diverses ioT Gedöns habe, von diversen Herstellern. Ich hätte das aber gerne mit nur einer App steuerbar.
Gleichzeitig will ich den Pi noch für andere Dinge nutzen,z.B. TimeMachine für Mac Backups, LUKS-Verschlüsselte Ne…

@luana@wetdry.world
2025-10-02 16:22:19

Nice, if you use DNS via Tailscale AdGuard/pihole can work even if you have Private Relay turned on!!

@shaun@mastodon.xyz
2025-10-29 21:50:44

I really dislike the "it's always DNS" trope because frequently it's something else, but #Kroger's shit was fucked all day and it was definitely #DNS. I think they have it loosely functional now, though there are so many nested CNAMEs the

422 22965x2630 images are not supported
@whitequark@mastodon.social
2025-11-13 20:01:42

chat, what's your favorite DNS-over-HTTPS library on npm that can use fetch() as a backend?

@jtk@infosec.exchange
2025-10-07 18:45:41

There is an ActivityPub proposal that involves the #DNS.
I have only just discovered it and have not considered it deeply so I am reluctant to make any grand statements. It is not obvious to me why this is useful or better than alternative approaches. It appears to involve the use of TXT RRs, any new de facto use of which makes me skeptical.

@hikingdude@mastodon.social
2025-10-29 18:26:06

#AWS goes down due to DNS.
#Azure: hold my beer

@theodric@social.linux.pizza
2025-12-07 12:00:26

Brief Starlink outage (our second ever). Strange that throughout I could ping 1.1.1.1 but not 9.9.9.9 or any other Internet host for which I have the IP saved. I reckon this means Cloudflare has a DNS instance in the same DC/on a peering fabric adjacent to the Starlink "Dublin" (LDNGBR) ground station.

@grifferz@social.bitfolk.com
2025-12-02 21:06:39

This was very welcome news from Let's Encrypt today and more interesting than cert lifetimes.
"This means you can set up the DNS entry once and begin automatically renewing certificates without needing a way to automatically update DNS."
I already do DNS-01 but not having to do the dynamic updates will be appreciated.

@trezzer@social.linux.pizza
2025-09-30 20:17:27

I wish there were a DNS-like solution to simply drop all links to the closed web. If someone sends me a link I can’t see without opening an app or an account, I don’t really care to see it.

@randy_@social.linux.pizza
2025-10-24 18:06:20

if i would buy a new Phone, with the full freedom what to install and completely without google or Apple bloat, my phone will have the following apps and the size of an iPhone SE 2022. #bringbacknormalsizedphones
Filen - cloud
Ente - auth
Next DNS - DNS
Ice cubes - Mastodon
Proton - Cal, Mail, pass
Deepl - Translation
DuckDuckGO and Fire…

@stsquad@mastodon.org.uk
2025-10-29 20:56:57

Is it#DNS?
Microsoft Azure outage: Heathrow, Xbox and Minecraft among sites down
bbc.co.uk/news/articles/c3rj45

@fanf@mendeddrum.org
2025-11-10 09:42:03

from my link log —
Discovering the discovery of designated resolvers (DNS DDR).
labs.ripe.net/author/yevheniya
saved 2025-11-09

@EarthOrgUK@mastodon.energy
2025-10-28 03:23:04

On Website Technicals (2025-10) - Tech updates: Sitebulb AdSense fails, RSS description, lite ads, ISSN lookup, micro-opts, DNS broke intensity, SVG inline URL-encoded, CO2 pcm, flock... - m.earth.org.uk/note-on-site-te

@x_cli@infosec.exchange
2025-12-16 15:10:48

Tu sais que t'es en train d'aller trop loin quand pour tester une fonctionnalité de ton programme (un client SSH), tu te retrouves Š implémenter un serveur SSH, un serveur DNS et un serveur HTTP et une PKI pour ton test E2E.
Heureusement, c'est facile Š faire en Go 😅

@jtk@infosec.exchange
2025-10-29 23:50:40

#DNS trivia, especially for those have ever used the "It was DNS" meme. What is wrong with this (real) dig response and what is the likely cause? AI probably won't help you.

dig @1.1.1.1 foobar.gov  norecurse  nocmd  noquestion  noauthority  nostats
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 1808
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, A…
@arXiv_physicsfludyn_bot@mastoxiv.page
2025-10-14 09:43:58

Sensitivity dependence of the Navier-Stokes turbulence of a two-dimensional Rayleigh-B\'{e}nard convection on time-step
Shijie Qin, Kun Xu, Shijun Liao
arxiv.org/abs/2510.11220

@whitequark@mastodon.social
2025-10-09 10:49:22

back when i was still in school i asked a classmate sitting next to me what should i be calling my machines. being a reenactor (I think? or something adjacent at least, it's been too long) she suggested Elder Futhark runes.
it was at least 5-10 years that passed between that and a realization that someone looking at my DNS zone without context would probably go "hm... is she secretly a nazi". anyway I phased the naming scheme out

@Stomata@social.linux.pizza
2025-10-29 19:06:21

Why am I smelling #DNS again :mortysmile:

@arXiv_physicsfludyn_bot@mastoxiv.page
2025-10-02 09:33:01

Physics-Informed Machine Learning Approach in Augmenting RANS Models Using DNS Data and DeepInsight Method on FDA Nozzle
Hossein Geshani, Mehrdad Raisee Dehkordi, Masoud Shariat Panahi
arxiv.org/abs/2510.01091

@fanf@mendeddrum.org
2025-10-13 14:42:01

from my link log —
Route 53 DNS: Amazon’s premier AWS database.
lastweekinaws.com/blog/route-5
saved 2021-02-18

@jtk@infosec.exchange
2025-10-29 19:50:39

This is not the first time for #Microsoft #DNS-related problems. As I recall, the first one I remember from 2001 had something to do with their authoritative name servers residing on the same IP4 /24 that had an access or availability problem.
It was a rookie mistake even then, and they were …

@fanf@mendeddrum.org
2025-12-13 09:42:04

from my link log —
Can I use HTTPS RRs?
netmeister.org/blog/https-cani
saved 2025-12-12 dotat.at/…

@Stomata@social.linux.pizza
2025-10-27 12:31:46

Oh my, @… is fast ! Faster than Cloudflare or Google. With average response time of 12 ms.
Where cloudflare was 22 ms
And Google shited with 232 ms 😆
#dns

@fanf@mendeddrum.org
2025-10-31 10:22:44

some things that make DNS hard lobste.rs/c/3ahld4
mastodon.bsd.cafe/@nuintari/11

@arXiv_physicsfludyn_bot@mastoxiv.page
2025-10-13 08:49:40

Smart navigation of a gravity-driven glider with adjustable centre-of-mass
X. Jiang, J. Qiu, K. Gustavsson, B. Mehlig, L. Zhao
arxiv.org/abs/2510.09250

@jtk@infosec.exchange
2025-11-07 23:23:09

Weekend Reads
* EDNS client subnet in practice
farrokhi.net/posts/2025/10/edn
* BGP-based DDoS scrubbing services survey

@fanf@mendeddrum.org
2025-10-11 20:42:04

from my link log —
Eon: a programmable effects-based OCaml DNS server.
ryan.freumh.org/eon.html
saved 2025-10-11 dotat.at/:/R4QXU.html

@jtk@infosec.exchange
2025-09-29 22:32:04

Whoops, trying to browse to mastometrics.com results in a Cloudflare "Error 1000 DNS points to prohibited IP".
Not sure anyone uses that much anymore, but I know @icecubesapp has built-in capability to integrate with it.
cc: @…