I looked into CAA but the current dns provider doesn't support those records. Is there a reason it had to be a new type not a more common TXT record?
Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
111–120 of 150 posts
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#112Earlier quoted context omitted.
Thinking laterally for a moment regarding the big picture here, why do we still rely on data centres. They made sense in a world of dialup and low speed / high latency broadband. But there are lots of places with high speed fibre and not much latency to the peering points. And the more we break away from data centres and clouds, the more the internet infrastructure will have to work the way it was designed instead of…
> They made sense in a world of dialup and low speed / high latency broadband. But there are lots of places with high speed fibre and not much latency to the peering points. Yes, but then you need backup power, someone to replace disks / hardware if things break, proper security for compliance reasons, cooling, noise. Once you set up all these things you just invented a data center again. I don't see how getting rid…
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#113Earlier quoted context omitted.
I would hope they at least: * Require a copy of the badge number, and verify that this officer is assigned and expected to be at this business right now. * Require them to sign into and out of the site. * Annotate which systems / compromises are in place. - That all of the above MIGHT be sealed under a court order; I would hope any such order has an automatic 'sunset' date, and possibly renewal upon review by a diffe…
A business can request visiting law enforcement to do all those things, and hopefully law enforcement complies. However, if they refuse to comply, realistically you just have to let them in anyway. Document their non-compliance and provide it to your lawyers, who can decide what action to take (lodge a formal complaint to the law enforcement agency, apply to a judge for an injunction to compel their compliance, etc)…
No, you don't. If they have a warrant then you need to let them in for the purposes specified in the warrant. Otherwise you're free to tell them to piss off. Unfortunately you're also free to acquiesce to any of their demands.
This kind of passive, default-compliant attitude from service providers, while understandable from a "path of least resistance" standpoint, is exactly the kind of behavior that allows the third party doctrine to circumvent so many of our basic rights. As a service provider, often the more difficult path is to challenge authority, rather than to cooperate with it. And unfortunately that means that most service providers will simply cooperate.
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#114A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#115A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
They had the option to send it encrypted with PGP. But yes, this reminds me of communist countries where you had to leave your ID at the hotel upon check in. The Stasi mentality lingers on and accomplishes nothing.
Of course, that's not mutually exclusive with Western nations having "The Stasi Mentality..."
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#116Who are the end users of xmpp.ru and jabber.ru? Are they hoping to pick up traffic between Russian soldiers? Spies? I hate mass surveillance as much as the next guy but why target Russian domains specifically?
I can't imagine it is war-related, or at least not in any direct sense, like literally trying to intercept soldiers or spies. I think the more likely scenario is that someone was to catch carders/botnet operators, since Jabber/XMPP is still very popular amongst people in that scene in Russia; you'll see often see screenshots or logs containing @exploit.in, @jabber.ru, and various other servers pretty much in any Kreb…
The Ukrainian military has been using Discord, so it's not totally unimaginable. Are these domains administered by Russians? IMO it would be pretty naive for Russians to be hosting comm servers in NATO datacenters right now. Perhaps related: I interviewed for a job recently where the hiring manager was a Russian immigrant. He was telling me I should go visit St. Petersburg and didn't seem to understand that is not an option at the moment. I was flattered by the suggestion of course and it is a nice reminder that regular people are typically tolerant, but also confused. Do people not understand the severity of the situation or is this behavior of acting like it is business as usual a coping mechanism?
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#117A quick warning on hetzner. I needed a personal bare metal machine so signed up. I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server? Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email conta…
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#118Earlier quoted context omitted.
They had the option to send it encrypted with PGP. But yes, this reminds me of communist countries where you had to leave your ID at the hotel upon check in. The Stasi mentality lingers on and accomplishes nothing.
Plenty of modern hotels in Western countries require you to submit your passport to reception, who then scans it and keeps a copy of it. In fact Marriot recently suffered a data breach where the attacker obtained the photos of these passports. Of course, that's not mutually exclusive with Western nations having "The Stasi Mentality..."
I can understand scanning documents if one rents a vehicle, although for hotels I fail to see why the form shouldn't be enough. It's not like they don't have cameras at the reception desk and I don't pay with a card under my name, they can also check my ID and fill in the form themselves if they don't trust the customer. Why should I trust them to properly handle copies of my ID? They are not a bank operating under strict regulation.
The thing is back then they were physically keeping your ID until you've paid in full and checked out. Last time it happened to us in Serbia, in 2019. The receptionist regarded us with suspicion. Brought back memories from the '80s. If you've played Papers Please you know what I mean. Now about 8 Schengen Area states have introduced border checks. Great.
https://www.euractiv.com/section/justice-home-affairs/news/s...
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#119The provider has access to the host, they can just inspect the job from the outside and you won’t be able to tell
The Hetzner one is a physical server. You would need to stage a "power outage" and backdoor it, which is probably not that easy - e.g. planting a kernel module which survives kernel upgrades and is pretty advanced at hiding itself (the article talks about analyzing raw memory dump).
Re: Mitigating the Hetzner/Linode XMPP.ru MitM interception incident
#120Earlier quoted context omitted.
Plenty of modern hotels in Western countries require you to submit your passport to reception, who then scans it and keeps a copy of it. In fact Marriot recently suffered a data breach where the attacker obtained the photos of these passports. Of course, that's not mutually exclusive with Western nations having "The Stasi Mentality..."
I know. Most of them have a fill in the blanks sheet with name address and document s/n. I can understand scanning documents if one rents a vehicle, although for hotels I fail to see why the form shouldn't be enough. It's not like they don't have cameras at the reception desk and I don't pay with a card under my name, they can also check my ID and fill in the form themselves if they don't trust the customer. Why shou…
For renting a vehicle (or more likely, something like a bike or moped), I can understand why they take your ID as a form of collateral in exchange for the material goods they're lending you. But for a hotel there's no real reason to hold onto it.
Out of curiosity, did you acquiesce and leave your passport with them?