Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

John Kristoff

@jtk@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

UIC PhD candidate | Dataplane.org | Verisign
#BGP #DNS #infosec and bit mechanic
#Blues / #Chicago / #tfr / #fedi22
Views are my own

1132 Followers
647 Following
50 Posts
Joined November 01, 2022
Homepage:
https://dataplane.org/jtk
Open post
John Kristoff @jtk@infosec.exchange
· 1w ago
RE: https://mastodon.social/@botgov/117322742497839711 app.gov leads to a whitehouse page for a new whitehouse mobile app, looking forward to the sure to be forthcoming app analysis
mastodon.social

Botgov: "The following .gov domains have been registered i…" - Mastodon

4
0
3
0
Open post
John Kristoff @jtk@infosec.exchange
· 2w ago
This is the first time I'm aware of since Russia's invasion into Ukraine in 2022 that this data center was disrupted due to hostilities: "We are writing to inform you that our data center in Kyiv has been damaged in a drone attack. As a result, all cloud services hosted from this facility are currently unreachable." - oneprovider
1
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
#DNS root servers on an observed June 2026 traffic increase: "[...] a representative from the AS responded on July 3rd. They confirmed that the traffic originated from their networks (i.e., was not spoofed) and was the uninten4onal result of recent recursive resolver software updates." https://root-servers.org/media/news/2026-06-29-increase.pdf
root-servers.org
10
1
6
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@rene_mobile@infosec.exchange DoW is a secondary name now, only an act of Congress can change the primary name which remains the DoD. Presumably a new administration of a different party will rescind the exec order for the DoW name.
7
2
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

Weekend Reads

* ICMP tunnel bypass in LTE nets
https://arxiv.org/abs/2607.04783
* Abuse in the standards process
https://sphericalcowconsulting.com/2026/07/07/when-process-stops-protecting-the-work/
* Monitoring DNS registry mutations
https://www.sidnlabs.nl/nieuws-en-blogs/thesis-monitoring-dns-registry-mutations-with-an-ensemble-anomaly-detection-framework
* Why orbital data centers are hard
https://spectrum.ieee.org/orbital-data-centers-heat
* OONI's approach to bad measurements
https://ooni.org/post/2026-faulty-measurements/

#ICMP #Standards #DNS #DataCenters #OONI

Ghost Traffic: ICMP Tunneling-Based Billing Bypass in LTE Networks
arXiv.org

Ghost Traffic: ICMP Tunneling-Based Billing Bypass in LTE Networks

Cellular data billing is a core operational mechanism for mobile Internet service providers (ISPs), and a policy gap that excludes a specific protocol from usage accounting can lead to a practical security threat. Some cellular ISPs treat ICMP echo traffic as control traffic rather than user data and exclude it from billing. At the same time, Android allows ordinary applications to create ICMP echo sockets without root privileges because of an unsafe default configuration, and the combination of

7
0
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

Probably not for $50,000 (US)
@transfers@social.bgp.tools

social.bgp.tools
4
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
My otherwise forgettable toot has triggered something in bluesky ai-loving bot accounts I guess.
3
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

As far as I can tell, United Airlines doesn't have any public #IPv6 space.

https://aws.amazon.com/blogs/networking-and-content-delivery/how-united-airlines-solved-ip-exhaustion-with-private-nat-gateway/

"United Airlines’ existing infrastructure (AWS routing, monitoring, security policies) is built on IPv4 across hundreds of accounts. However, adopting IPv6 is an organization-wide decision at United Airlines."

Translation "We see nails, we love hammers"?

infosec.exchange
5
4
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

Gemini is hungry?

@transfers@social.bgp.tools

social.bgp.tools
3
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 1mo ago
Ignoring everything else, seems hard to ignore the latency cost introduced here: "The data center then beams AI results generated by the GPUs to satellites and sends them back to land." https://www.theinformation.com/articles/ocean-powered-data-center-startup-set-double-valuation-2-billion?rc=9btsxw&shared=eacd621056a6e353
theinformation.com
2
0
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
I've noticed access to fsf.org and gnu.org through Tor (e.g., torify, onion browser) is unreliable. As in the connection is often refused. I'm not sure if this is a recent change at the content end, perhaps due to this: https://www.fsf.org/blogs/community/blocking-botnets-with-reaction The number of sites and content nets that are becoming inaccessible via Tor and what I've used as "jump" hosts (i.e., my personal proxies) seems to only be increasing. Unless someone beats me to it or points me at an existing "blocked via [tor/jumphost]" monitor, I might look at the scope of this problem further and write up some initial findings in a blog.
fsf.org

How the FSF sysadmins block botnets with reaction — Free Software Foundation — Working together for free software

4
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@nygren@hachyderm.io Very early in my career the old timers used to complain about things like Ethernet having no debugging and the web having no proper transaction mechanisms. They forgot to complain about the very loosely defined and practiced DNS requirements.
3
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@miniBill@mastodon.uno @badsamurai@infosec.exchange @fullywoolly@mastodon.social @syn_rst@norden.social @gayint@infosec.exchange @spamhaus@infosec.exchange I wouldn't recommend using the first list at all, it significantly overblocks (e.g., 174 runs a root server).
2
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@paul_ipv6@infosec.exchange "The foul-up has been attributed to an end-of-life Symmetricom SyncServer S300 time synchronisation server. It comes as Telstra CEO Vicki Brady revealed the telco had known about a GPS rollover bug with the server, but did not replace it." That is description I've seen so far. Sounds plausible.
3
11
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@resingm@infosec.exchange Not the same argument at all. IP address resources are just numbers, but because they are associated with real hosts, domain names, and all the associated traffic they receive or emit, and in the case of v4 not so readily available, their value profile is very different.
3
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

RE: @botgov@mastodon.social

visas is a state dept name, http-only but no content at the moment

mastodon.social
2
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Shares of #IBM have dropped about 25% today. Biggest single day drop ever. A generation ago this would be huge news, but we don't talk or think about IBM like we used to in the tech industry.
3
2
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
And gone from the me. zone. telegram.me WHOIS, which I believe is related, shows the same state, but still resolves. Not a telegram user or fan so I'll defer to others to dig into this more.
3
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Received email spam from newly registered socialdb [dot] xyz. Some kind of escrow racket for wannabe influencers. Looks like if they find an email associated with your Mastodon account you'lll get subscribed to their mailing list. Platform allows you to create an account using an email without verification and set 2fa via Tor. Just saying.
2
2
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

ObThought: We could use the equivalent of a doi.org for news articles that could help arbitrate / aggregate access with stable links and if necessary payment to sources.

A large proportion of articles people link to I try to read are often inaccessible for various reasons such as:

  • Subscription required
  • Client access IPaddr is blocked
  • Any ad-blocking fu
2
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
An edu block to lambda.ai https://social.bgp.tools/@transfers/statuses/01KX52W18SZR1PRDXAPYJANK57
social.bgp.tools
3
0
2
0
Open post
John Kristoff @jtk@infosec.exchange
· 3mo ago
Replying to
@briankrebs@infosec.exchange I'm told that name is retired, cve.org (which it does redirect to) is the one to use instead.
3
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@PogoWasRight@infosec.exchange Do a significant number of those suspects travel to the U.S.? Restrictions on family members might be slightly the more meaningful message here? I'd guess this is more of a statement, and a relatively small baby step in fighting cybercrime outside the border. It may also just be a political statement to the administration's supporters?
2
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
Someone bid on it, auction ends in less than 24 hours.
2
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
RE: https://infosec.exchange/@dannyjpalmer/116975079605921576 "Disabling web proxy auto-discovery (WPAD) where not required" Why is wpad even still supported by browsers?!? A 30-year-old mechanism, expired I-D almost as old, and the upward namespace traversal nonsense that might be one of the worst uses of the DNS ever devised.
Open quoted post
Quoting
Danny Palmer
@dannyjpalmer@infosec.exchange
A widespread DNS poisoning campaign is targeting the hotels, conference venues and the hospitality sector with credential harvesting attacks designed to steal corporate login credentials from visitors, researchers have warned. Identified by cybersecurity analysts at ReliaQuest, the campaign begins by targeting routers used to provide public Wi-Fi to visitors to hotels, conference centers and other shared venues frequently visited by corporate employees. These compromised Wi-Fi gateways were identified around the world, including across multiple US cities, India and Saudi Arabia. (Researchers point out that the tactics look suspiciously similar to APT28/Fancy Bear... 👀 ) https://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/ #cybersecurity
Open quoted post
infosec.exchange
2
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

Weekend Reads

  • Inside an Internet shutdown https://labs.ripe.net/author/mdkamruzzaman-khan-2/inside-a-shutdown-bgp-evidence-from-an-operator-who-was-there/
  • Inferring shared IP addresses https://burdantes.github.io/assets/pdf/multi_user_ip-sigcomm.pdf
  • BGP origin attribute manipulation https://blog.cloudflare.com/bgp-origin-attribute/
  • IP reassembly congestion DoS attacks https://cispa.saarland/group/rossow/papers/FragJam-usenix2026.pdf
  • Operators on academic BGP security solutions https://pure.mpg.de/rest/items/item_3719779_1/component/file_3719780/content

#InternetShutdown #NAT #BGP #DoS #RPKI

Inside a Shutdown: BGP Evidence from an Operator Who Was There
RIPE Labs

Inside a Shutdown: BGP Evidence from an Operator Who Was There

When Bangladesh vanished from the global routing table in July 2024, public routing data captured the event as it unfolded. Drawing on first-hand observations from inside one affected network, this article explores what that data can and cannot tell us.

2
0
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago

@transfers@social.bgp.tools

Nothing to do with actual birds, not the router software, not even Larry Legend. This of course:

"Communications infrastructure your AI agents operate"

social.bgp.tools
1
0
1
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@fanf@mendeddrum.org I've used both ivory and icecubesapp. I've found the former to be vastly more stable and reliable compared to the latter. The latter in my experience was unusable for timeline reading due to bugs. Maybe those bugs I care about are gone by now so it's time to reevaluate but updates can be even less frequent than ivory and the open github issues list is very long.
1
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@christopherkunz@chaos.social Any 3-digit ASN or less is kind of cool to say you have, but 1) if you weren't the original assignee it is much less cool and 2) there should be relatively little practical value for any number. Maybe someone can come up with some scheme where you'd derive some practical benefit. I can't think of any really good reason. Maybe nets will be more likely to peer with you if you have a low number? Or maybe some nets that never update their configs set LOCALPREF for certain ASNs?. Or threatintel reputation systems have magic/golden/exception rules for certain ASNs? None of these things I can think of seem likely a sufficiently good reason to spend a premium on a magic combination of bits.
1
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@sahil@morii.sahilister.net Some words from recently former Googler @menscher@infosec.exchange says some things things here. He may be able to point to more. https://nanog.org/events/nanog-80/content/2229/
nanog.org
1
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 3mo ago
Replying to
@tubsta@social.bsdlab.au @hkrn@mstdn.social @stucchimax@social.secret-wg.org @phessler@bsd.network Be careful what you ask for. The IEEE had the foresight to charge $1000 US for OUIs to dissuade every grad student from getting their own, but cheap enough to be essentially inconsequential to real card vendors. There is a real administrative burden on RIRs, arguably much more so than there is for OUIs. Now, probably the bigger concern isn't the grad students, but the potential harm in Internet security and stability. What are reasonable RIR administrative fees to limit pollution, abuse, and bad actors while making the costs a minor part of the budget for serious networks?
1
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 3mo ago
Replying to
@paul_ipv6@infosec.exchange That one has been going around for awhile, since at least 2022 :-)
1
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@benjojo@benjojo.co.uk Somewhere there must have been a well-known list with the incorrect /15 a bunch of us copied from. I would have guessed it might have been something we messed up at Cymru, but I can't find an old bogon list to confirm and archive.org seems to returning a lot of 503s today. Older versions of nmap (at least as early as 2013) had the incorrect prefix so this mistake probably was and remains widely deployed. I fixed my old repo and archived just in case. Nice find!
0
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@bortzmeyer@mastodon.gougere.fr The firehol lists have been running on autopilot for years. Not really the best data set to use for most serious measurement these days.
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 1w ago

Weekend Reads

  • File notification attacks https://inoti.fyi
  • IP geolocation at APNIC 62 https://blog.apnic.net/2026/09/24/ip-geolocation-at-apnic-62-challenges-geofeeds-and-data-quality-perspectives/
  • Russian MAX Messenger analysis https://interseclab.org/research/max/
  • SubTel Forum Issue #150 https://issuu.com/subtelforum/docs/subtel_forum_issue_150_-_offshore_energy
  • What it's like to work in data centers https://www.wsj.com/business/what-its-like-to-work-in-one-of-americas-data-centers-b4358003?st=y1Zg9t

#SideChannel #IpGeoLoc #RU #SubTel #DataCenter

File Notification Attacks
File Notification Attacks

File Notification Attacks

Side-Channel Leakage from the File-Notification System on Linux, Android, Windows, and macOS. Accepted at The ACM Conference on Computer and Communications Security (CCS), November 15-19, 2026 — The Hague, Netherlands File-notification systems tell applications when files change, e.g., opened, closed, written, deleted. With only read permission on a file or directory, an attacker can watch these notifications and reconstruct user behavior. We find generic issues similar on each of Linux, Android

0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Networking numerology
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Any #PortlandME fedi people involved with #DNS, #BGP, #infosec, or #blues?
0
4
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@bortzmeyer@mastodon.gougere.fr Letter to investors suggesting weaker than expected profits to be reported.
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@IPngNetworks@ublog.tech @wrmsr@peering.social You could always announce your prefixes with AS8075 in the path, make them drop it for you >:)
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 1mo ago
Replying to
https://news.ycombinator.com/item?id=49499217 #IPv6
news.ycombinator.com

Tell HN: HN's IPv6 address is down | Hacker News

0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 3mo ago
Replying to
@lw@mastodon.bsd.cafe Would a virustotal (or similar service) search suffice?
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@SteveBellovin@infosec.exchange Is that original script archived anywhere or maybe any of the next nearest descendants?
0
1
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 1w ago
This content is associated with an intro CS course by some renowed and well-known academics, but there is at least one kind of serious mistake therein, can you spot it? https://textbook.cs161.org/network/dnssec.html
Computer Security

DNSSEC

Online textbook for CS 161: Computer Security at UC Berkeley.

0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2w ago

The Internet Last Week

  • Central Asia regional connectivity https://labs.ripe.net/author/anastasiya-pak/capif-5-regional-interconnectivity-in-central-asia/
  • DNSSEC-anchored stateless encrypted auth DNS https://arxiv.org/abs/2609.14210
  • Router compromise walk-through https://blog.j2sw.com/netops/mikrotik-router-compromise-forensic-walkthrough/
  • Russia changed domain name registration rules https://riposte.levelflow.org/2026/09/rururu/
  • Weaponizing digital choke points https://www.foreignaffairs.com/china/new-chinese-way-cyberwar-ai

#CAPIF5 #DNSSEC #MikroTik #RU #DNS #CN

CAPIF 5: Regional Interconnectivity in Central Asia
RIPE Labs

CAPIF 5: Regional Interconnectivity in Central Asia

Central Asia’s Internet looks very different than it did back at CAPIF 1. We trace the rise of direct regional routes, stronger routing security and new connectivity options - along with the gaps that remain.

0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@benjojo@benjojo.co.uk Found it. The Team Cymru bogon list did have the 192.18.0.0/15 prefix listed up until about 2011 when the error was identified and subsequently fixed. 15 years later it persists!
0
0
0
0
Open post
John Kristoff @jtk@infosec.exchange
· 2mo ago
Replying to
@bms48@mastodon.social Not sure you'll find many shell account providers anymore. Maybe ask a friend with a VM? Or if you want to rent one yourself, 1984 and flokinet are two options in Iceland for starters.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:29:48 UTC