Earlier quoted context omitted.
Indeed. The DPRK was right from the start. They always were. For the longest time I thought they'd gone too far, but now we're the clowns putting on a show.
Sure, but there must always be a fear that the military and public would not want to die in a nuclear inferno to defend national sovereignty. And may tolerate a coupe instead. Which then reduces the madness and the deterrent effect. The extra step the Dprk have taken is to try and build bunkers so that the regime could survive the destruction of the country. A step further into madness that goes beyond what western c…
There were BGP anomalies during the Venezuela blackout
211–220 of 476 posts
Re: There were BGP anomalies during the Venezuela blackout
#212I guess one of the interesting things I learnt off this article(1) was that 7% of DNS query types served by 1.1.1.1 are HTTPS and started wondering what HTTPS query type was as I had only heard of A, MX, AAAA, SPF etc... Apparently that is part of implementing ECH (Encrypted Client Hello) in TLS 1.3 where the DNS hosts the public key of the server to fully encrypt the server name in a HTTPS request. Since Nginx and o…
Adguard Home and others can be configured to complete your DNS requests over HTTPS (using, for example, https://dns.cloudflare.com/dns-query ).
HTTPS is the name of a protocol, which is mostly used to make the World Wide Web work, but we do lots of other things with it, such as DNS-over-HTTPS aka DoH.
However HTTPS is also the name of a type of DNS record, this record contains everything you need to best reach the named HTTPS (protocol) server, and this is the type of record your parent didn't previously know about
In the boring case, say, 20 years ago, when you type https://some.name/stuff/hats.html into a web browser your browser goes "Huh, HTTPS to some.name. OK, I will find out the IPv4 address of some.name, and it makes a DNS query asking A? some.name. The DNS server answers with an IPv4 address, and then as the browser connects securely to that IP address, it asks to talk to some.name, and if the remote host can prove it is some.name, the browser says it wants /stuff/hats.html
Notice we have to tell the remote server who we hope they are - and it so happens eavesdroppers can listen in on this. This means Bad Guys can see that you wanted to visit some.name. They can't see that you wanted to read the document about hats, but they might be able to guess that from context, and wouldn't you rather they didn't know more than they need to?
With the HTTPS record, your web browser asks (over secure DNS if you have it) HTTPS? some.name and, maybe it gets a positive answer. If it does, the answer tells it not only where to try to connect, but also it can choose to provide instructions for a cover name to always use, and how to encrypt the real name, this is part of Encrypted Client Hello (or ECH)
Then the web server tells the server that it wants to talk to the cover name and it provides an encrypted version of some.name. Eavesdroppers can't decrypt that, so if many people share the same endpoints then eavesdropper can't tell which site you were visiting.
Now, if the server only contains documents about hats, this doesn't stop the Secret Hat Police from concluding that everybody connecting to that server is a Hat Pervert and needs to go to Hat Jail. But if you're a bulk host then you force such organisations to choose, they can enforce their rules equally for everything (You wanted to read News about Chickens? Too bad, Hat Jail for you) or they can accept that actually they don't know what people are reading (if this seems crazy, keep in mind that's how US Post worked for many years after Comstock failed, if you get a brown paper package posted to you, well, it's your business what is in there, and your state wasn't allowed to insist on ripping open the packaging to see whether it is pornography or communist propaganda)
Re: There were BGP anomalies during the Venezuela blackout
#213Earlier quoted context omitted.
That just sounds like more 'strongly worded letters' which never go anywhere and they never do anything about. It's over for the EU. They rested on their laurels for too long and cowardice rotted them from the inside. I don't think Denmark will put even a smidge of resistance up. Trump is going to bark some orders, boots are going to hit the ground and it's fait accompli .
What does action (i.e. not-strongly-worded-letters, i.e. not words) look like? Capture Trump? Invade the US? The idea the EU is some bureaucratic hellhole incapable of anything is really odd and nigh-universal - I'm used to righties adopting it from Brexit & antipathy for social demoracy, but I'm not used to see it as a despondent wailing from people otherwise sympathetic to it. Note no one even mentioned the EU - it…
Europe withdraws from the non-proliferation treaty, publicly resolves to building and maintaining a European nuclear deterrent and greenlights members who have been militarily threatened (the Baltics, Poland and Denmark) to start clandestine programmes.
The last part doesn't even have to happen. Hell, none of it has to happen. But that would be playing from strength.
Unfortunately, Europe is not politically unified enough to do this. (Same for Asia.)
Re: There were BGP anomalies during the Venezuela blackout
#214Earlier quoted context omitted.
It's not only downvoted, it was flagged, and dead . (flag accepted by moderator, no one else will see this comment thread without expanding) Mr. Trump good. Trump derangement syndrome bad. If Mr. Trump does what you say eventually, then it was good. (see rule #1) I see this frequently on HN since the re-election, won't speculate as to why: only way around the downvote is to criticize policy generically, untethered to…
Of course, because this site is control of Mark Eggman Andrreesen.
You're mixing up your VCs?
Re: There were BGP anomalies during the Venezuela blackout
#215Earlier quoted context omitted.
or even by normal load from someone deciding to split a /8 prefix into /24's
Most BGP peers have router filters in place. It's not 1996 anymore. I remember the days of logging into a Cisco connected to a Sprint T1 and seeing a coworker had fat fingered a spammer's route, sending it to null0. Oops. How did that happen?
The radio towers we used to access to obtain the accounting data (CDRs) all had the same very weak password.
Re: There were BGP anomalies during the Venezuela blackout
#216Earlier quoted context omitted.
Nuclear capability by itself isn't a complete deterrent. It has been widely reported that the US military has made contingency plans for a decapitation strike and seizure or destruction of nuclear weapons in Pakistan in case the situation turns really bad there. Real deterrence requires a credible second-strike capability on survivable platforms such as submarines.
> the US military has made contingency plans for a decapitation strike and seizure or destruction of nuclear weapons in Pakistan in case the situation turns really bad there. Real deterrence requires a credible second-strike capability on survivable platforms such as submarines. The existence of a plan does not equate to the feasibility of its execution. A submarine-based deterrent is indeed the "gold standard" for s…
These are the states whose Senators are in play this year [1].
Let's say Trump decides it's fuck-around-with-Islamabad-o'clock. He fucks around. Pakistan nukes at India. How many of those Senate seats flip as a result? I'm going to guess none.
Let's go one step further. Pakistan nukes Al Udeid and Camp Arifjan (both theoretically within range of their Shaheen-III). American troops are killed. Does the President's party lose any seats? At that point, I'd bet on a rally-'round-the-flag effect.
The truth is there isn't political downside to the President fucking around with Pakistan. Its nuclear deterrent isn't designed to contain America. And it can't threaten us with maybe the one thing that could make Trump suffer, a refugee crisis.
Re: There were BGP anomalies during the Venezuela blackout
#217Re: There were BGP anomalies during the Venezuela blackout
#218I assume that nuclear capability would rule out a target from this kind of snatch operation, and that this event will add pressure to proliferate.
You still have to be willing to use the nukes. The threat has to be real or it doesn't work as a deterrent. I think this is a situation where even if Venezuela had nukes, this still would have happened.
Re: There were BGP anomalies during the Venezuela blackout
#219Re: There were BGP anomalies during the Venezuela blackout
#220Earlier quoted context omitted.
1) It's complex. Formally, Moscow controlled the launch codes. However Ukraine designed and built the ICBMs, and are near the top of nations with the highest nuclear physicist per capita ratio. On top of that the Soviet nuclear lockout systems are rumored to be much simpler than the American ones. Whereas the American system is rumored to be something like the decryption key for the detonation timings (without which…
> However Ukraine designed and built the ICBMs Your computer is designed and built in China therefore your computer belongs to Chinese and China. Right? > See above Maybe you should see how good the Ukraine was at keeping their naval assets after they used the totally legal methods to obtain them. Maybe then you would have a clue on how good they could had maintained them.
The question is whether china would be capable of maintaining the equipment they created and have physical possession of, not whether they can root it without physical access.