Dr. David McBride (dwm)
I'm not that kind of doctor. Senior IT technical specialist and occasional patient magnet.
Currently hostmaster@durham.ac.uk; previously answered to root@doc.ic.ac.uk, unix-support@csx.cam.ac.uk, postmaster@cam.ac.uk, oxcert@infosec.ox.ac.uk, and root@stats.ox.ac.uk.
The thought occurs that, now that the likes of Facebook, Twitter, Instagram etc. now predominately show you random shit off the Internet rather than what your actual friends you want to see are posting, it would be more accurate to call them antisocial media.
RE: @RinaVolpina@rubber.social
I'm just going to take a giant sip of coffee and read this email I've just received from Amazon about my account.
I'm looking at https://dns-aid.org/ and https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/ and not understanding why it doesn't make proper use of conventional DNS-SD SRV records, insisting on inventing their own, AI-agent-specific thing.
The ideas of DNS-based service discovery, central registries, and RPC are absolutely nothing new.
And not being able to indirectly point to other search domains seems like a serious omission.
I've had a look at this, and I think this is the wrong way to look at things.
rsync is load-bearing, mature, valuable software. It's featureful, it's complicated, it's useful, and it's everywhere.
And it's written in C.
And people have figured out that even relatively basic LLMs, hooked up to an appropriate harness, can be used to drive processes that once required lots of manual work.
Including vulnerability discovery.
This is fucking atrocious. UK folk, write to your MP, this is not okay.
Multitasking, v: The act of avoiding multiple sources of work at once.
I somehow missed these when they were first published.
https://www.rfc-editor.org/rfc/rfc8962.html
https://www.rfc-editor.org/rfc/rfc9948.html
I am also entertained that errata exist for these formal internet standards documents.
https://errata.rfc-editor.org/eid6516/
"It's a Superpower??" debuted today, and it's very, very good. I laughed out loud so much, in ways nothing has really prompted me to do in ages.
It's good. Go in cold. Trust me.
I am reminded of the time that, on the day I implemented DNSSEC validation on the university recursive nameservice, ac.uk broke its DNSSEC signatures.
Fortunately, I had a plan for that...
@jwz@mastodon.social I am assuming it's 80/443 traffic that is the problem.
If so, I would try fronting Apache with nginx, and using it's GeoIP module to return your HTTP error response of choice to HK.
e.g.
- Move Apache to 127.0.0.1:8080;
- Install
nginx, have it listen on TCP 80/443; - Configure the GeoIP module as described at https://nginx.org/en/docs/http/ngx_http_geoip_module.html
- Match against those locations you wish to block and return your HTTP error response of choice.
- For everything else, reverse proxy to Apache.
RE: @mullvadnet@mastodon.online
I'm really not keen on this "papers, please" Internet environment that the UK is rapidly deploying.
github.com's lack of reliability is a serious problem.
crimes detected
I'm looking at https://dns-aid.org/ and https://datatracker.ietf.org/doc/draft-mozleywilliams-dnsop-dnsaid/ and not understanding why it doesn't make proper use of conventional DNS-SD SRV records, insisting on inventing their own, AI-agent-specific thing.
The ideas of DNS-based service discovery, central registries, and RPC are absolutely nothing new.
And not being able to indirectly point to other search domains seems like a serious omission.
"Exclusive: Meta planning sweeping layoffs as AI costs mount"
> prepare for greater efficiency brought about by AI-assisted workers
[citation needed]
@portaloffreedom@social.linux.pizza A recursive DNS resolver like BIND or Unbound will, for any arbitrary query, start at the public DNS root (for e.g. .com) and recursively ask the authoritative nameservers for each domain individually until you get the name you want.
This is how DNS services work. You don't have to use someone else's; you can use your own.
(The downside is that DNS queries go over the wire in clear, so someone snooping on your DNS traffic can see what questions and answers you're getting.)
@portaloffreedom@social.linux.pizza I run my own, on my own local machine. apt install unbound pretty much covers it.
https://www.bbc.co.uk/news/articles/cdx85vkk0gko
"You know, I'm so sick of Congress I could vomit."
— Joshua Lyman, "The West Wing"
@bjh21@wandering.shop This may be relevant to your interests.
As context, you may find BG's inaugural lecture informative/entertaining:
https://www.bennett.ox.ac.uk/blog/2023/11/ben-goldacres-inaugural-lecture/
I remember thinking that it's always a good sign when ~rja14 has nice things to say about your security design.
Bonus points if you spot me in the audience. ;-)
