Repeat after me: Separating username and password fields on separate (fucking responsive) page WILL NOT INCREASE A FUCKING SECURITY IN ANY WAY! IT WILL JUST MAKE THE PASSWORD MANAGERS TO WORK WORSE AND THUS IT WILL FUCKING DECREASE THE SECURITY!!!
Ondřej Surý
Speaker for the Dead Code, raging feminist, DNS Artist, tooth-fairy agnostic, male ally, skipper, my opinions are my own, not perfect, he/him/his
Hey U.S., I’ll make it easy for you. Fuck U.S.A., fuck ICE, fuck Donald Trump and fuck all the Nazis in the current government (you fucking pricks know who you are).
https://www.nytimes.com/2025/12/09/travel/social-media-tourists-visa-border-patrol.html
Enshittification commences in 1…2…3
(The application is now closed for new applicants, sorry.)
I’m hiring a software engineer for BIND 9. All you need is to speak English, program in any procedural or object-oriented language, be willing to learn technologies we use (C17), be a nice person and be brave to apply!
Microstory: Imagine living in a world where it would be okayish and safe to go in China for IETF and absolutely not ok and unsafe to go into US. Oh wait… @letoams@defcon.social
They are just laughing straight to our faces…
Anyone from FreeBSD project to who I can speak about jemalloc project?
So, here they are… the new “keys to the Internet”!
X41 did a security audit of BIND 9 last year, and this is kind of reassuring to hear from external security experts:
> While vulnerabilities were found during this audit, the code has been hardened and could serve as an example on how to develop C code with security in mind.
https://x41-dsec.de/news/security/research/source-code-audit/2024/02/13/bind9-security-audit/
I can obviously name 20+ things that could be improved immediately, but still this is nice…
Also hug your #DNS recursive resolver #Developers, they needed it for past couple of weeks and they couldn’t tell anyone.
Kids, don’t do drugs! Also never implement your own DateTime arithmetics… this is how 30 minutes of free parking looked like this morning here ;)
This is such a shitshow :-(, just my computer:
* Termius - Electron/21.4.4
* Mattermost - Electron/26.1.0
* Podman Desktop - Electron/25.2.0
* balenaEtcher, WhatsApp - Electron/13.6.9
* AdGuard for Safari - Electron/18.3.15
* Microsoft Teams - Electron/19.1.8
Special kudos go to:
* Dropbox - Electron/13.1.0-dropbox.20221010.faa890d59 - VULNERABLE, WHAT THE FUCK? MY EYES BLEED @TomSellers@infosec.exchange
This is exactly the reason why we don’t plan to have bug bounties for BIND 9. We have enough issues to go through even without LLM generated bullshit…
Also we are thankful for all the solid security researchers finding issues in DNS servers even if that’s often very inconvenient ;). @bagder@mastodon.social
Infamous Dear Anonymous User from @bert_hubert@fosstodon.org is asking for help in https://gitlab.isc.org/isc-projects/bind9/-/issues/4107 with BIND 9.4.1 (released in 2007) in a proprietary telco stuff, but reporting it against BIND 9.18.15 because “the lines are same”.
Now, I’ve seen everything and I can finally retire from DNS.
Hey all, ISC is hiring a support engineer! This is not my team, but you will work closely with my team acting as a much appreciated bridge between the customers and the software engineers.
https://isc.recruitee.com/o/support-engineer-for-isc-bind-and-kea-dhcp-2
My personal note: We are looking for a genuine answers. Honest “I don’t know, but I am willing to learn” is much better than AI generated answers, so don’t be afraid to apply.

