Erik Nygren 
mastodon 4.7.3Internet Systems Architect, #Maker, Father, Husband, tinkerer, #IPv6 evangelist, #IETF standards, long-time #Linux user, and wanna-be mad scientist. Deals with complex systems and #ops/#infosec. $dayjob at #Akamai (as20940) since 1999. Toots my own. He/Him.
AAAARGH! I'm not at all surprised, but NIST's excellent whitepaper on Inclusive Language (NIST.IR.8366) has been withdrawn:
https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8366.pdf
This was an excellent resource that I reference all the time. I feared it would go away so I made a snapshot a few weeks back that I uploaded here: https://nygren.org/archived/NIST.IR.8366.pdf
Interesting and surprising corner-case discovered by @phils@chaos.social when debugging an issue with IPv6-only DNS recursive resolvers:
https://mailarchive.ietf.org/arch/msg/dnsop/rAbaKS5YD0iYuIg9xOPt0s7HJCg/
In-particular, it is important to have both A and AAAA records on all of the nameserver names (ie, that NS records point to). Just having two of each isn't enough -- the number of names without AAAA records is also a consideration.
Unbound's defenses for CVE-2020-12662 can otherwise kick in and result in SERVFAILs in some corner-cases.
The US president is threatening that "a whole civilization will die tonight". I'm sure you have seen his post/threat so I won't screenshot it here.
Regardless of how horrible the Iranian regime is, this is a threat of genocide (or at a minimum war crimes) against an entire people many of whom are innocent. The US Congress must immediately start impeachment proceedings to remove Trump from office, along with Hegseth. We can't stay quiet and be complicit in this madness.
With all of the excitement around the copy.fail vulnerability, do NOT miss CVE-2026-41940 for cPanel and WHM auth bypass (CVSS 9.8). It is being actively exploited in the wild and if you had it on some server, assume that machine is now p0wned and you need to go into remediation and rebuild.
While the impact footprint of copy.fail is massive (eg, most things running Linux) the local privilege escalation nature of it makes it relatively less urgent for most environments, whereas cPanel has a far smaller footprint but the active attack surface and impact is far worse.
(I was blissfully unaware of cPanel, preferring static site generators myself.)
#hugops to all of the people dealing with these, although I have a creeping fear that 2026 could be thsi non-stop.
The team I'm in at #Akamai is looking to hire a Principal Architect. I love working here which is why I've been with the same company for almost 27 years https://jobs.akamai.com/en/sites/CX_1/job/2901/?utm_medium=jobshare&utm_source=External+Job+Share
Recently analysis from my colleague @jschauma@mstdn.social on #IPv6 adoption:
https://www.netmeister.org/blog/ipv6-adoption.html
Periodic reminder to enable IPv6 on HTTP(S) services you or your company host if you haven't done so already!
@Oskar456@mastodon.social @phils@chaos.social RFC3901bis is clear NOT to put IPv4-mapped IPv6 addresses into AAAA records for this reason. Full current text is:
To maintain name space continuity, every DNS zone MUST be served by at least two authoritative DNS servers providing services via IPv6. To avoid reachability issues, authoritative DNS servers MUST NOT use IPv4-embedded addresses [RFC6052] (including IPv4-Mapped IPv6 addresses and deprecated IPv4-Compatible addresses [RFC4291]) for receiving queries. Furthermore, the delegation configuration of an NS (Resolution of the parent, resolution of sibling domain names, glue) MUST NOT rely on IPv4 connectivity being available.
#Linode (#Akamai Cloud) has published documentation on how to mitigate #CopyFail for both new and existing instances running there:
https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/
