Earlier quoted context omitted.
“Well known” in conspiracy circles. You’re referring to national security letters and, no, those cannot compel “whatever they need”: it’s limited to release of transactional data, not payload: https://en.wikipedia.org/wiki/National_security_letter Part of why the news about MUSCULAR was so shocking was that the Buah-era NSA was attacking the fiber connections between American tech companies’ data centers, because the…
If that was shocking, put your rubber gloves on for this read: https://en.m.wikipedia.org/wiki/2010s_global_surveillance_di...
In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare
71–73 of 73 posts
Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare
#72Earlier quoted context omitted.
Unlike AWS, GCP or Azure themselves? You think the people who own the computers you use can't see whats happening on them?
Isn't that the whole value proposition of Cloudflare? Nearly all traffic (in terms of volume) gets swallowed by CloudFlare and never approaches most instances: DDoS attacks swallowed whole, WAF rules block illegitimate traffic (which is, in most cases, the vast majority of traffic to dynamic endpoints or, frequently, non-existent endpoints, if you've ever tailed webserver logs), and Cloudflare-caching handles most of…
Re: In 2023 operations for the .GOV TLD transitioned from Verisign to Cloudflare
#73Earlier quoted context omitted.
??? at best that means there's more need for practice, testing, better processes, and so on. it does not mean everything should be easy. (especially changes to a critical name authority.) there's an argument that maybe .nz needs to spend more on this, delegate this, or accept a decreased security assurance, but that's definitely not true in general.
if you read the post-mortem they did everything by the book they made a small mistake, and .nz was down for 2 days as a result of course the 95% of people that have competent ISPs that don't verify DNSSEC records were completely unaffected there's a reason ALL major tech companies refuse to deploy it for their zones
> and .nz was down for 2 days as a result
so it was not a small mistake
yes, the same thing happens when people start using technology that actually verifies what it reads/writes. ie. btrfs, ZFS, ECC, etc. and turns out disks fail, bits rots, etc. it was just unnoticed.