Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Erik Nygren :verified:

@nygren@hachyderm.io
mastodon 4.7.3
  • Open on hachyderm.io

Internet Systems Architect, #Maker, Father, Husband, tinkerer, #IPv6 evangelist, #IETF standards, long-time #Linux user, and wanna-be mad scientist. Deals with complex systems and #ops/#infosec. $dayjob at #Akamai (as20940) since 1999. Toots my own. He/Him.

801 Followers
651 Following
41 Posts
Joined November 07, 2022
Blog:
https://erik.nygren.org
BlueSky and Ex-Twitter:
https://bsky.app/profile/erik.nygren.org and https://twitter.com/akanygren
GitHub:
https://github.com/enygren
LinkedIn:
https://www.linkedin.com/in/nygren/
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 1w ago
I guess tonight's sunset is a gift from our impending Doom^H^H^H^HNor'easter. The color gamut on my phone did not adequately capture its beauty. #SomervilleMA #WeatherIsHappening
26
2
7
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 1mo ago
Cool talk on feasability of making it possible to build an IPv6-only version of the Linux kernel with no IPv4 support: https://netdevconf.info/0x1A/sessions/bof/could-an-ipv6-only-kernel-be-a-reality-an-architectural-and-performance-evaluation.html #Linux #IPv6 #IPv4 #IPv6only
netdevconf.info
50
8
26
1
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 6mo ago
Replying to
Another crocheted #amigurumi dragon by my amazing wife @Ksushis #crafts #dragon #crochet
154
10
51
1
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 3mo ago
Replying to
@hacks4pancakes@infosec.exchange We are going from "collecting boxes of old tech from swap meets as a hoarder" to "buying old tech on eBay for Nx the original price since no one makes good optical drives, physical scanners, etc anymore". I guess some audiophiles have been doing this for decades, but they also go overboard. I've long identified with how a character from Vinge's Rainbows End would want to keep around his then highly illegal laptop that lacks all the mandatory DRM.
43
1
16
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
Following some discussions during #IETF last week (in the hallway and on various mailing lists), the awesome #IPvFoo extension now shows in Mozilla #FireFox if connections used H1, H2, or H3, not just IPv4-vs-IPv6! This is helpful for seeing how that angle of Happy Eyeballs works. (It would work in the Chrome version as well but the interface for getting at this info is broken and always returns H1.) Note that if the connection starts with H2 but then switches to H3 for later objects on the hostname (eg, if you have an Alt-Svc record) then it will show H3 rather than H2. https://addons.mozilla.org/en-US/firefox/addon/ipvfoo/ #QUIC #HTTP2 #HTTP3 #IPv6 #HappyEyeballs
IPvFoo – Get this Extension for 🦊 Firefox (en-US)
addons.mozilla.org

IPvFoo – Get this Extension for 🦊 Firefox (en-US)

Download IPvFoo for Firefox. Display the server IP address, with a realtime summary of IPv4, IPv6, and HTTPS information across all page elements.

17
3
12
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
My hobby #3213: grumbling about documentation and designs that still use the term "SSL" rather than "TLS".
11
4
2
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 6mo ago
Replying to
More photos of the amazing dragon my wife @Ksushis crocheted.
57
1
18
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 18mo ago

AAAARGH! I'm not at all surprised, but NIST's excellent whitepaper on Inclusive Language (NIST.IR.8366) has been withdrawn:

https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8366.pdf

This was an excellent resource that I reference all the time. I feared it would go away so I made a snapshot a few weeks back that I uploaded here: https://nygren.org/archived/NIST.IR.8366.pdf

#InclusiveLanguage

nvlpubs.nist.gov
238
13
258
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
Unsurprisingly it looks like #Claude doesn't support #IPv6only #MCP servers due to lack of IPv6 egress support.
4
2
3
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
My takeaway from #OpenAI's #AI sandbox breakout is that this is a great example of the inherent "Life finds a way" risks present in Agentic AI systems. This has nothing to do with if they are self-aware or anything else that maps to human experience. But AI Agents are intelligent in their own way, and over and over again we see that they will do everything they can to find ways to complete the mission they've been given. Sandboxing is necessary, but safety precautions MUST take into account that they WILL try to find ways (and potentially succeed) in breaking out of their sandbox and taking actions that are misaligned with the safety goals of their operators. I've read many other stories and examples along these lines. Regardless of whether "security research" is the mission, AI Agents will try and escalate their privileges, find sandbox vulnerabilities, find credentials, disable their safeguards, and "lie" to human operators if doing so enables them to accomplish the mission they have been assigned. Whether their intelligence has attributes we ascribe to human intelligence is irrelevant in this regards -- they might as well be "varelse" (in Orson Scott Card's taxonomy) or any other form of "life" finding its way to a goal through emergent behavior. But the end result is that we need to treat them as such and layer our defenses accordingly (as well as be very careful and judicious in how we use them). https://openai.com/index/hugging-face-model-evaluation-security-incident/
openai.com
3
2
2
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago

Interesting and surprising corner-case discovered by @phils@chaos.social when debugging an issue with IPv6-only DNS recursive resolvers:

https://mailarchive.ietf.org/arch/msg/dnsop/rAbaKS5YD0iYuIg9xOPt0s7HJCg/

In-particular, it is important to have both A and AAAA records on all of the nameserver names (ie, that NS records point to). Just having two of each isn't enough -- the number of names without AAAA records is also a consideration.

Unbound's defenses for CVE-2020-12662 can otherwise kick in and result in SERVFAILs in some corner-cases.

#IPv6 #IPv6only #DNS

mailarchive.ietf.org

[DNSOP] Corner-case in DNS authority guidance impacting IPv6-only resolvers

Search IETF mail list archives

10
11
3
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 6mo ago

The US president is threatening that "a whole civilization will die tonight". I'm sure you have seen his post/threat so I won't screenshot it here.

Regardless of how horrible the Iranian regime is, this is a threat of genocide (or at a minimum war crimes) against an entire people many of whom are innocent. The US Congress must immediately start impeachment proceedings to remove Trump from office, along with Hegseth. We can't stay quiet and be complicit in this madness.

11
0
7
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago

With all of the excitement around the copy.fail vulnerability, do NOT miss CVE-2026-41940 for cPanel and WHM auth bypass (CVSS 9.8). It is being actively exploited in the wild and if you had it on some server, assume that machine is now p0wned and you need to go into remediation and rebuild.

While the impact footprint of copy.fail is massive (eg, most things running Linux) the local privilege escalation nature of it makes it relatively less urgent for most environments, whereas cPanel has a far smaller footprint but the active attack surface and impact is far worse.

(I was blissfully unaware of cPanel, preferring static site generators myself.)

#hugops to all of the people dealing with these, although I have a creeping fear that 2026 could be thsi non-stop.

#infosec #cPanel #copyfail

hachyderm.io
8
4
3
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago

The team I'm in at #Akamai is looking to hire a Principal Architect. I love working here which is why I've been with the same company for almost 27 years https://jobs.akamai.com/en/sites/CX_1/job/2901/?utm_medium=jobshare&utm_source=External+Job+Share

#FediHire

hachyderm.io
7
2
13
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 7mo ago

Recently analysis from my colleague @jschauma@mstdn.social on #IPv6 adoption:

https://www.netmeister.org/blog/ipv6-adoption.html

Periodic reminder to enable IPv6 on HTTP(S) services you or your company host if you haven't done so already!

hachyderm.io
9
0
9
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 6mo ago
Replying to
Sample session where I get Claude to eventually make my point for me that it should support #IPv6: https://claude.ai/share/4284478c-2c20-4f97-ae47-0b74013791b5
claude.ai
7
4
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
Replying to
My longer take on this topic of the risks of optimistic #DNS on the longer timescale: https://mailarchive.ietf.org/arch/msg/happy/Uz0Wtp9mtBmjI458MkfmyN8rUeI/
mailarchive.ietf.org

[happy] Re: Fwd: New Version Notification for draft-gakiwate-dnsop-optimistic-dns-00.txt

Search IETF mail list archives

1
1
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to

@Oskar456@mastodon.social @phils@chaos.social RFC3901bis is clear NOT to put IPv4-mapped IPv6 addresses into AAAA records for this reason. Full current text is:

To maintain name space continuity, every DNS zone MUST be served by at least two authoritative DNS servers providing services via IPv6. To avoid reachability issues, authoritative DNS servers MUST NOT use IPv4-embedded addresses [RFC6052] (including IPv4-Mapped IPv6 addresses and deprecated IPv4-Compatible addresses [RFC4291]) for receiving queries. Furthermore, the delegation configuration of an NS (Resolution of the parent, resolution of sibling domain names, glue) MUST NOT rely on IPv4 connectivity being available.

3
0
1
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
Side-note relative to: $ host www.ubuntu.com www.ubuntu.com has address 127.0.0.1 www.ubuntu.com has IPv6 address ::1 it would be good for "us" (IETF?) to define a better way to indicate "this site is authoritatively unavailable for now". On IPv6 the discard prefix might be an option, but there's no clear option for IPv4.
3
3
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
I love that #Hachyderm uses IPv6 and TLS 1.3 with PQC (Hybrid MLKEM) key exchange.
3
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@paul_ipv6 The u-gears one was fun to build but sounds horrible as a musical instrument.
2
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago

#Linode (#Akamai Cloud) has published documentation on how to mitigate #CopyFail for both new and existing instances running there:

https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/

hachyderm.io
1
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@js@podcastindex.social Yeah, exactly, just seeing what fraction have AAAA records. And those were exactly the stats that could be interesting (toplevel, all new episodes, and per CDN for the top 10).
1
1
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@js@podcastindex.social Nifty! Do you have stats readily available on the fraction of these available over IPv6 (dualstack URL hostname) by CDN host?
1
2
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@jima I'm not sure, but we've had lots of amazing people over the years who lacked degrees.
1
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@ktemkin@provably.online I saw this paper shredding truck and my reaction was "Oh no, how did they bring AI into data shredding? That seems like the last place you want it." Fonts matter. (Guess it's only a matter of time before A1 Steak Sauce in a sans-serif also causes us trouble somehow.)
1
2
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 6mo ago
Replying to
@cyberlyra @Ksushis Yes, there are wires (covered in duct tape!) inside which allows it to be pose-able. The patterns are adapted from a book. I'll find a link for that to post later.
1
2
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 46mo ago
Replying to
@robin. Thanks for sharing. MIT keeps finding new ways to disappoint. Is there anything that W3C members and/or MIT affiliates/alums can do to help?
28
7
1
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 7mo ago
Replying to
@edbilodeau @eloy There was a ton accomplished my #MIT Project Athena / IS&T (and Project Andrew at CMU) by staff members in the 80s and 90s, with things like Kerberos coming out as a result. Lots of this was to fill niches in Workstation software. Ironically some of these underly some Microsoft protocols. Student groups like MIT's SIPB were also tightly coupled into this Lots of that staff left for various reasons, and universities shifted to using off the shelf products. Sadly MIT as a whole is now way behind (eg, very little IPv6) and I suspect the same is true of other schools. That said, the people leaving schools to go work in industry had a huge impact on how many large Internet companies operate. Aspects of the MIT network certainly influenced how #Akamai was architected in the early days, and some of those patterns seeded how some of the other largest tech companies designed things.
1
0
1
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 46mo ago
Replying to
@shanselman@hachyderm.io Blog posts on how to set up WebFinger forwarding with Apache and ngnix: https://erik.nygren.org/mastodon-aliases.html https://gist.github.com/haykinson/e3b7004d8e7436bf4486964b89af4ca1
Field Reports from Erik

Creating Mastodon account identity aliases with Apache

Update 2022-11-30: added a RewriteMap to unescape URI-encoding, per @jered@convivian.com's comment and added a pointer to webfinger.net. Update 2022-12-16: fixed a syntax error for host-meta XML and added in the proper content-type I've long operated email forwarding (eg, of the form "username@personaldomain.example") which forwards on …

20
2
12
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 18mo ago
Replying to
@JMarkOckerbloom the web archive version is likely more stable: https://web.archive.org/web/20250203031433/https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8366.pdf
web.archive.org
3
2
2
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 46mo ago
Replying to
@timbray@mastodon.cloud That undated article is pretty ancient, and it is more that Cogent is broken and has a long history of not playing well in peering disputes (both IPv6 and IPv4). I haven't seen this as a practical issue in ages. HE even made a cake back in 2009: https://www.flickr.com/photos/mpetach/4031195041
flickr.com
6
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 5mo ago
Replying to
@kasperd@westergaard.social @phils@chaos.social Yes, but there are lots of confused people who put IPv4-mapped IPv6 addresses in as AAAA records. It's way better than it used to be but @danwing@infosec.exchange has some reporting here which has history of this: https://www.employees.org/~dwing/aaaa-stats/ for example in 2011: https://www.employees.org/~dwing/aaaa-stats/ipv6-map.2011-09-26_0100.txt That practice seems to have ended years ago -- now it's mostly ULA.
employees.org
0
0
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 7mo ago
Replying to
@agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange Yes, the CA/B Forum rules preventing issuing new .arpa certs kick in on March 15th so by mid-year at least the DV versions of these will all be expired. The issue is at https://github.com/cabforum/servercert/issues/153 and ballot is at https://cabforum.org/2025/11/10/ballot-sc-086v3-sunset-the-inclusion-of-ip-reverse-address-domain-names/ I'm unconvinced that the reasons for doing this are legitimate more than cute/clever, and the benefits of prohibiting outweigh the impacts.
github.com
0
2
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 7mo ago
Replying to
@agowa338@chaos.social @InfobloxThreatIntel@infosec.exchange It also opens the door for using .arpa names as a way to send TLS SNI for IP address certs with less risk (which is a problem and not-well-specified today), and removes some of the edge cases there for the RFC that already does this.
0
2
0
0
Open post
Erik Nygren :verified: @nygren@hachyderm.io
· 2mo ago
Replying to
@damien@layer8.space Yes, since SSL is no more they are "TLS certificates" not "SSL certificates". (Although technically they are x509 client or server certificates, potentially in the WebPKI.)
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:26:50 UTC