"Do not go gentle into that good night." Flying in registration and resolution planes since 1997. Duduk fan.
Public Key
npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Profile Code
nprofile1qqsfr0juzkhnfe2vvkc539mrhtx6qhp3kx6sgmsvqa7t8ts535s3mpgpz4mhxue69uhhyetvv9ujuerfw36x7tnsw43qzrmhwden5te0dehhxarj9ekk7mg0puh75
Show more details
Published at
2026-06-19T23:54:09Z Event JSON
{
"id": "1db26095a5ebeb4dc4c1974789d638ef72b1d19ab1de8f33abc96267223d16a8" ,
"pubkey": "91be5c15af34e54c65b1489763bacda05c31b1b5046e0c077cb3ae148d211d85" ,
"created_at": 1781913249 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://framapiaf.org/users/pmevzek",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"Patrick Mevzek\",\"about\":\"\\\"Do not go gentle into that good night.\\\"\\n\\nFlying in registration and resolution planes since 1997.\\n\\nDuduk fan.\",\"picture\":\"https://stockage.framapiaf.org/framapiaf/accounts/avatars/000/048/923/original/1d29f656422bcc28.jpeg\",\"nip05\":\"[email protected] \",\"fields\":[]}" ,
"sig": "09e514a112573cf13aed25fbb86067dbf4398ad0f795a99a783be6f601004fd5f84a1c6d2143555b4d9f75873753325b6c574f4d56134b20cdeef92140acf43f"
}
Last Notes npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…gqn3 @nprofile…kjcu Oui, mais mon clavier n'avait pas ces touches ;-) npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…kjcu Enregistrez un .fr simple/court puis vous pourrez créer des sous-domaines dans n'importe quelle langue et alphabet... et même des emojis, cf initiative `y.at`. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…h3v3 For simple straightforward needs, NSD might be just what you need. Far simpler to configure, because only authoritative, where bind was always both authoritative and recursive, which created endless security vulnerabilities, now long gone, but still means you have to be more careful in the configuration. So bind is like the army knife and you need to be careful for big zones or big amount of zones. There is also PowerDNS, KnotDNS and CoreDNS. Ideally, diversify and use secondaries. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…gqn3 Needs of DoD for DNS over DNS, like encoding DNS messages totally inside TXT packets. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…2hpy You need `\U`. `\u` can be used only with 4 hex digits hence up to `\uFFFF`. Anything above, like U+1F534 needs `\U` that accommodates 8 hex digits. `python -c 'print("\U0001F534")'` works as expected and displays the character. See https://docs.python.org/3/howto/unicode.html#unicode-literals-in-python-source-code for all details. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ntm0 "It’s so annoying that they basically hand out IP addresses if you want them". No, not the case today. You have to be a member of RIR and prove use of IPs, and certainly not for scarce IPv4 addresses. Plus that space is far from litigation/problems, see the Afrinic saga? "ICANN is a shitty company anyways" but it is not a company at all… ICANN is a late 199X invention. Noone saw needs of regulations there before the Web exploded in use. Alternative would/could have been the UN/ITU… npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n @nprofile…xg7q Because not all #TLD registries joined the #RDAP fiesta 🙂 ? And in theory even a change of registrant, or maybe even DNS provider (or MX records) should trigger a "emails on this domain are not verified anymore" situation. As it should trigger certificates revocation too, which won't happen (hence shorter lifetimes as a solution). npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…salt Lots of examples from @nprofile…y9me in his recent presentation: https://www.icann.org/en/engagement-calendar/details/icann-webinar-series-for-europe-bizarre-and-unusual-uses-of-the-dns-2025-05-21 and his former study: https://labs.ripe.net/author/pgl/the-joy-of-txt/ npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…8wcz "Hah! I predicted years ago that attackers would leverage DNS like this! " DNS tunnels by TXT records (which is just the same thing as encoding malware inside TXT records) were shown by Kaminsky in 2003, and it was known even before that… See https://www.slideshare.net/slideshow/bh-eu-05kaminsky-5939200/5939200 ; there is really nothing new in this field and I hope it is not the "hexadecimal encoding" (rotfl) that is presented as the novelty there. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…fn2v @nprofile…ped7 Do note/remember that validity will decrease. Per public generic rules, in 2029, 47 days will be the max of validity and certificates life will decrease until then progressively. Not sure what LE policy will be, but they also allow/will allow as an option 6-days validity certificates. So, in short, yes, you need to automate. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n Car les budgets du Pentagone ont été bloqués par DOGE :-) ? Au-delà de la blague, cet article explique comment les rumeurs sur les OVNIS étaient un moyen simple de cacher des recherches secrètes (quand ce n'était pas juste pour le lolz et l'audimat, comme Roswell) : https://archive.ph/2025.06.07-021826/https://www.wsj.com/politics/national-security/ufo-us-disinformation-45376f7e?st=28Hj5L ; et puis 1950 c'est aussi la guerre froide (ce qui a des impacts psychologiques), et de nos jours elle est très réchauffée... npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n Première fois que `mq`, `gp` et `gf` sont potentiellement redélégués (en tout cas ouvert à l'être) ? npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n C'est pour les gens indécis qui ont à la fois les "pro" et les "con" pour tout sujet? (pour et contre en anglais) 🙂 ? npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ct7c Une lettre très utilisée dans le français… npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n C'est plutôt la série « on découvre toujours des choses sur bind » car la documentation dit bien que c'est une fonctionnalité spécifique et propriétaire de bind, utilisant en plus un terme prêtant à confusion car ayant un autre sens dans le DNS comme l'autre fil l'a montré. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…qtg4 Could be monkey in the middle as well 🙂 npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…fpf4 Like `kp` you mean? 🙂 npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…emwt Yes it is. In less than a month (April 15th) Google Registry will stop providing it, you need to use #RDAP. #ICANN lifted the requirements for it recently, so now all #gTLD registries, and registrars can start decommissioning this 40+ years old service as successor does everything more and better. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ct7c @nprofile…528n "A company bought a TLD and actually uses it. What a day. 🤨" And some go overboard with it: https://domainincite.com/30838-toshiba-goes-all-in-on-its-dot-brand . Next: www.web.toshiba website 🙂 ? npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ct7c @nprofile…nnj9 @nprofile…528n Mais il y a `whois.nic.xn--tckwe` en tout cas d'après l'IANA à https://www.iana.org/domains/root/db/xn--tckwe.html npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…nnj9 @nprofile…528n @nprofile…ct7c 仕手株.コム but 0 clues what the website is telling about. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ct7c @nprofile…528n Plié par l'IETF depuis longtempts grâce a PRECIS. Qu'apparemment personne ne connaît :-( . Mais peut-être trop abstrait. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n Cloudfalre a pourtant souvent des certificats avec des dizaines de noms (dans leur offre gratuite il cumule des noms épars). Là tout de suite sur `orange.fr` je ne récupère qu'un certificat avec 4 noms dans le SAN, donc c'est "corrigé". Un lien vers un certificat spécifique ? npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n @nprofile…adlu GitHub fait pareil: toute tentative pour laquelle on n'a pas les droits suffisants (accès à dépôts privés) donne une page 404, je suppose pour "cacher" l'existence (enfin l'information de l'existence ou non) du-dit dépôt. Ca casse un peu le modèle HTTP mais c'est pour la "sécurité" 🙂 npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n @nprofile…seqg @nprofile…lvw7 @nprofile…ud6s @nprofile…g8zh "Cela n'est vrai que tant que les autres serveurs continuent à s'alimenter sur A". En cas de "problèmes" sur quoi d'autres pourraient-ils s'alimenter :-) ? D'autant que 3/4 des autres opérateurs sont des entités américaines de toute façon aussi. C'est de toute façon aussi théorique que les plaintes dans procès sur du terrorisme qui avaient demandé en rétribution de récupérer le contrôle du `.ir`. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…seqg @nprofile…lvw7 @nprofile…ud6s @nprofile…g8zh "il aura à coeur de controler les serveurs racines des noms de domaines". Trop tard. Il n'y a qu'un serveur à contrôler, le A, géré par une société américaine (Verisign). npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…lx5n "For example, a client certificate has to be signed with a key stored on the server." So each "certificate" is specific to one server? That doesn't scale, plus is possible today trivially already. Certificates can be issued by any private/local/limited CA, that just has to be trusted on each side. You seem to infer protocol problems from bad implementations, so the outcome will be rehash of what exists today... just without implementations 😞 Also see PSK mode of operations. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…lx5n So what is presented to the server then from the browser? Precisely. I suspect you are just reinventing TLS... npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…lx5n "The browser presents the public key to the server on request." Hence each browser can then impersonate every user on every other server! npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…528n IMHO, dans l'exemple `dig @k.root-servers.net g.root-servers.net AAAA` ne serait-il pas mieux d'utiliser une adresse IP plutôt que le nom du résolveur car sinon ca ressemble plutôt à un cercle vicieux (dig doit déjà résoudre `k` ou le connaître avant même de pouvoir chercher `g`) npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @nprofile…ct7c Et ils sont audacieux dans la combo fatale wildcard + CNAME + DNSSEC. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1jw5…9fry Et PostgreSQL alors? npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1qw7…q0ue For the first point: except that SSLv3 is clearly NOT in the list of things recommended today. Crosscheck the usage statistics I gave with the recommendations in RFC8624. Remember that some people may be below non really technical constraints, like gov. regulations and such (and ED25519 is “usually” less accepted by official bodies than ECDSA solutions). You can look at a study for RSA-4096 at https://indico.dns-oarc.net/event/40/contributions/888/attachments/854/1551/2021-11-30-rsa4096.pdf ; See https://indico.dns-oarc.net/event/39/contributions/868/attachments/825/1485/2021-09-08-ed25519.pdf specifically for ed25519. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1qw7…q0ue If you look at current live statistics, #ECDSA-P256 is used far more than #Ed25519. See https://stats.dnssec-tools.org/#/?dnssec_param_tab=0 and https://stats.dnssec-tools.org/#/?dnssec_param_tab=1 ; as for guidance, if not known, RFC 8624 should be a good start. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1hxf…g8qu First mover? I think DNSBelgium (.BE) moved all registry operations to AWS like 10 years ago. But I didn't read the full article, since I can't read Dutch. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1836…8jp6 Unfortunately, long ago was time you can have profits with domain names.That works on the 2nd market, and for registry premium names, otherwise all registrars compete on prices, so you can't really earn a lot there, hence all the added packages even just for a domain ("whois" "protection" in the past, etc.). So revenues come from volume. Once you are one domain out of a million, the registrar has low incentive to care about each... Sorry to be pessimistic, just 30 years in the business. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1836…8jp6 "actual real domain registrars whose whole business is just domain names." Happy to be proved wrong but I don't think there is anymore any ICANN accredited registrar that solely sells domains names and nothing else by the side. Might be different in ccTLDs, but I doubt it.All do webhosting, emails, etc. But otherwise your point is indeed very solid and that advice should be followed. However people also want the convenience of only one provider and one bill so will let one do everything. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1mpx…n2a6 Yes, but a provider not doing that is exactly the open door necessary to conduct subdomains takeover... As often, "simplicity"/ ease of operations (to not annoy people to have to edit the zone to put nonces there to prove ownership) trumps security. npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1jw5…9fry @npub1tzv…fnvp https://www.alchemistowl.org/pocorgtfo/pocorgtfo08.pdf#page=7 " We’ll be adding a privi- lege escalation bug to sudo version 1.8.13. The tar- get audience for this backdoor will be people whose system compiler is Clang/LLVM 3.3, released in June 2013.". Autre exemple avec les "minifiers JS" si on les considère similaires à un compilateur: https://blog.azuki.vip/backdooring-js/ npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1jw5…9fry @npub199n…fg60 Il me semble avoir vu passer une annonce récemment que "tous" les sites gouvernementaux allaient enfin passer sous `.gouv.fr`.... npub1jxl9c9d0xnj5ced3fztk8wkd5pwrrvd4q3hqcpmukwhpfrfprkzs9kz9a2 Patrick Mevzek @npub1jw5…9fry A priori c'est possible avec n'importe quel flux HTTP, dès 1.1 (HTTP Pipelining). Si le serveur n'est pas fracassé évidemment. Ca existe même en EPP :-)