Would you work differently if you knew every keystroke was being saved, every website logged, every idle minute counted against you?
Everything I read about the AI industry leads me to think there will be an AI crash.
I designed this to help with different BGP communities and configuring them on your routers.
It’s commonly believed that when selecting between a number of routes for the same address prefix, a BGP speaker will select the route with the shortest AS Path.
There is an interesting fight within the leadership of U.S. AI companies. It is between the supporters of open-source AI and those driven to oppose open-source AI.
We often talk about “human infrastructure” in network engineering–but what does this mean, and how do we help engineers “produce” while helping them to flourish as individuals? Catherine Hicks joins Tom and Russ to discuss the psychology of software engineering, and how the lessons learned apply to network engineering.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-315.mp3download
You can find Catherine’s new book on the psychology of software engineering here.
If you would like to follow Catherine’s writing in this area, including the impact of AI on work, you can find her blog here.
You can connect with Catherine on LinkedIn.
The honest target is goodput, meaning requests per second that actually met your latency targets. Count anything else and you are counting cold plates.
I find it strange that as a software industry, we put in so much effort to make our systems efficient to design, build, and scale with DevOps practices, cloud native architectures, event-driven functions, optimized databases and storage, and resource-sipping Lean IT — then we threw it all out the window when Big AI came along.
If there is one universal law in internet infrastructure, it is that no good intention goes unpunished by the practical realities of legacy software maintenance.
This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE).
Using our unique position on the Internet, we took an investigative look at one of the well-known mandatory attributes in BGP, the ORIGIN attribute.
Sometimes we can be so focused on the problems in front of us that we forget the people who are following in our footsteps. Michael McCollum, a new network engineer, joins Tom and Russ to ask questions about life as a network engineer.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-314.mp3
download
Today’s Internet runs on a vast infrastructure of replicated data, and the difference between order and chaos lies in maintaining consistency through synchronization across the many distributed points where that data is published.
IPv6-only networks often still depend on IPv4 subnets and ARP. This article introduces an IETF proposal to eliminate both.
Traditional software engineering approaches reliability as a binary state of uptime and downtime. Modern ML pipelines render this paradigm obsolete.
Yet while the radios and protocols largely reuse terrestrial 5G designs, one small but crucial component has been left behind: The control plane timers that quietly govern how registration, mobility, and session procedures behave under real-world conditions.
Apparently, nearly all of them have reached the same conclusion. I don’t merely need AI occasionally. I need it waiting inside every search bar, messaging app, music player, and document reader I already use.
Most designers and operators default to carrying all traffic–including network management traffic–across the same paths as application data, or in band. Is this the right choice, or should operators seriously consider creating an out-of-band network just for network management? If you decide to build an out-of-band network, what are some of the considerations and lessons learned? Daryll Swer joins Tom and Russ to discuss.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-313.mp3
download
Email authentication has quietly held the internet’s mail together for two decades, and it has just taken its biggest step forward yet.
A few months ago in Mercer County, Kentucky, more than 200 residents packed a planning and zoning commission meeting until every seat was filled, with citizens standing along the walls. Yard signs reading “NO DATA CENTER” lined farm roads from Harrodsburg to Burgin.
AI coding tools have changed the software development world in a few short years, but security risks and rising costs associated with AI-generated code mean organizations should consider their potential return on investment (ROI) before jumping into the deep end.
A recent PING episode noted that, for the Border Gateway Protocol (BGP) at least, ‘the shape of the curve’ appears to have changed.
Today’s Internet runs on a vast infrastructure of replicated data, and the difference between order and chaos lies in maintaining consistency through synchronization across the many distributed points where that data is published.
In fact, in Q1 2026, the Ethernet switch market grew faster than the overall server market did according to the latest statistics from IDC.
We are tempted to treat a capable language model as a knowledgeable colleague whose conclusions we can accept. It is more accurate, and more useful, to treat it as an untrusted component that produces plausible output which must be checked before it is relied upon.
In my view, MoQ occupies a middle ground between WebRTC (which is used for lots of video conferencing applications like Google Meet) and DASH (Dynamic Adaptive Streaming over HTTP) which powers most entertainment video streaming on the web.
Content consumption is detached from the website itself, as users rely on AI-driven systems to aggregate, summarize and contextualize information without visiting the original source. Instead of researching across multiple tabs, readers ask an AI system to do the work for them.
Shifting data centers from earth to space has become an alternative touted as solving concerns without generating new ones. In sun synchronous, low Earth orbit, orbiting data centers (“ODCs”) may have comparatively less environmental impact and lower operating costs.
The entire technology world has, for decades, treated the IP address as a shorthand host identifier. This is clearly not the way IP was designed, but what are our other choices? In this episode of the Hedge, Scott Robohn joins Russ And Tom to discuss a recent paper arguing cryptographic keys should be the primary host identifier, and another article on the centrality of DNS to the Internet.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-312.mp3download
Reports of AI corporate implementation failures have continued to mount over the last year.
AI assistants now hand you a single, ready-made answer, and a harder question comes with it: who decides what we get to know, and what never makes it into the reply?
Vendors are trying to position “confidential computing” as the technical backbone of Europe’s sovereign cloud ambitions. But new research shows that a security protocol used to prove cryptographic trust in the system may have a fundamental architectural flaw.
The Internet should stop asking only who was in the room. It should ask who can bind the party bearing the loss.
America won’t beat China by banning AI. We’ll win by building the world’s best open models and letting innovation—not government—lead the way.
A unanimous Supreme Court reversed a $1 billion dollar jury award against a broadband provider in its March 2026 ruling in Cox Communications v. Sony Music.
Differential privacy (DP) data synthesizers are increasingly proposed to afford public release of sensitive information, offering theoretical guarantees for privacy (and, in some cases, utility), but limited empirical evidence of utility in practical settings.
LLMs are relentless data miners that train on unimaginably large text databases, looking for multi-dimensional statistical relationships among small chunks of text called tokens.
Regulatory filings and new business models suggest hyperscalers are shifting from simply building AI capacity to managing the enormous financial risks that come with it.
olicymakers are casting more and more problems as issues of cybersecurity. So reframed, wildly different policy issues, from misinformation, to child social media safety laws, to antitrust regulations, to alleged journalist misconduct, to anti-sex trafficking statutes become what this Article calls “cybersecuritized.
We are often told that if engineers who don’t go “all in” on AI will be left behind. While there are a few voices who argue that AI can be a dangerous tool, impacting not only the quality of our work, but the very quality of our thinking skills. Doug Smith, a critic of using AI for engineering, joins this episode of the Hedge to argue the contrary view of AI.
What are the dangers of relying on AI?
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-311.mp3download
You can find Doug’s blog here.
What is AI Ops, and how can it be useful for your network? Akshay Balaganur and Sushanth Mascaren join Tom and Russ to discuss various aspects of AI Ops.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-310.mp3
download
A better, more nuanced understanding of tasks in recommender systems can help minimize user costs across the entire recommendation process.
The current estimate of the world’s population is 8.264 billion people, so the share price of SpaceX is currently at a phenomenal USD $261 per head.
The analysis from space monitoring firm LeoLabs, provided to Breaking Defense, found that from January 2021 to January 2025 China has abandoned 51 spent rocket bodies in LEO above 650 kilometers (about 404 miles) in altitude, more than doubling the number for the previous five years to bring the total to 96.
A big problem, Pauzauskie said, revolves around reproducibility. So far, labs haven’t been able to show that they can consistently cool semiconductors.
This article recounts the evolution of modern computing systems to provide an analysis of security risks and their evolution, with a past and present look at key cyber-defense innovations as well as a perspective on future cybersecurity hard problems.
It’s no longer just about your IP address or the specific endpoint you think you’re connecting to, it’s about your location and which intermediary services can most effectively handle your request.
Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court held that the AI’s summaries are reflections of the company and “above all an expression of Google’s business activities.”
The distribution of Content Delivery Networks (CDN), cloud and content provider capacity across Internet Exchange Points (IXPs) provides a fascinating lens into the physical infrastructure of the Internet and public peering.
The memory market – by which we mean dynamic main memory as well as flash persistent memory – has been utterly and perhaps forever changed by the GenAI boom.
These days you could be excused by suspecting that the world has gone AI-mad, and if you were at the NANOG meeting your suspicions would’ve only been confirmed!
As the development of data centers in the U.S. faces intense criticism from local communities and legal action, project supporters are claiming “foreign influence” could be fueling the fire.
In this bingecast installment of the Mind Matters News podcast, host Robert J. Marks welcomes economics professor and author Gary Smith to discuss the hype around artificial intelligence and its impact on the market.
In the DNS name resolution space queries are free. To what extent do we see over-querying on the part of recursive resolvers in the DNS?
Over the past year, the Ethernet community has examined 400Gbps‑per‑lane signaling from many angles: AI network use cases, modulation options, channel limitations, and technology feasibility. Those discussions have been necessary, but they now need to converge into decisions that allow the industry to move forward.
For most of the internet era, distribution was scarce and content was abundant. Platforms that controlled distribution captured the majority of value.
As DNS is more widely used to distribute certificate information, proving ownership of a resource becomes more critical. The constant challenges required to prove resource ownership, however, increase delay in connecting or using a resource. DNS persists–as the name implies–creates a persistent connection between a resource and a certificate authority. Henry Birge-Lee, Michael Slaughter, and Shiloh Heurich join Russ and Tom to explain how this new record type works and it’s importance to DNS.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-309.mp3
download
In this post, I discuss our recent work that models and analyses the resilience of authoritative DNS infrastructure that supports individual domain names on the Internet.
The RIPE NCC made its all-powerful single sign-on tokens available to over 1000 third parties. From a single link click, any logged-in RIPE NCC user would leak their session token.
Identifying active IPv6 addresses is a challenging task, but it’s also an important one. As researchers and network operators, it helps us understand the current deployment, identify weak spots that need strengthening, and detect vulnerable devices for disclosure.
The fundamental bubble barometer is that speculators buy an asset because they expect the price to keep rising, not because they want the income generated by the asset. Indeed, most speculators don’t plan on holding the asset long enough receive any income.
Recently, there has been a surge in progress in quantum computing that has shortened the hypothetical timeline on which quantum computers can ‘break’ traditional public-key cryptography that uses the RSA scheme.
We all talk about how engineers deal with imposter syndrome–but we don’t often talk about the experience of making things work “in the background.” What is competence, and what do we do when competence isn’t recognized? Justin Wilson (j2sw) joins Russ and Tom to discuss.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-308.mp3
download
When business volume and market capitalization cross a critical threshold, vertically integrating infrastructure ceases to be merely a cost-cutting financial tactic; it becomes an existential imperative for computational resilience and commercial survival.
It looks like industry mergers and acquisition activity is in high gear lately.
Building multi-agent systems right now feels painfully identical to the early, chaotic days of the micro services gold rush.
The standard is called DNS-AID (Domain Name System for AI Discovery). Its premise is that the internet already solved the problem of finding things at scale forty years ago with DNS — and that the same infrastructure should handle AI agents.
Mythos is real. I know a big chunk of the industry thinks it’s a marketing stunt, and I get why. I get it. But I’ve seen the findings, and they’re bad.
In a paper published late in 2025, Østergaard and colleagues reported on their examination of almost 40 psychiatric referrals across Denmark that implicated AI chatbots in harmful interactions, including suicidal thoughts, eating disorders, and fostering delusions
Since its deployment in 2011, the adoption of RPKI by Internet Service Providers has shown continuous growth, a trend that persists to this day. As this growth continues it is important to measure its effect on BGP stability.
AI companies, AI influencers and famous professors have been making extraordinary claims for years about AI.
A robotic system that can produce a rubbery pancake is a true technical and logistic achievement, but why all this work to automate the production of mediocrity?
The greatest risk we face today isn’t that AI is becoming “too smart”; it’s that we are beginning to treat this technology as an infallible “oracle” rather than a capable, yet fundamentally fallible, “intern.”
Many companies rely on open source, regardless of whether or not they realize it. In this best of the Hedge episode, Alistair Woodman joins Russ White and Tom Ammon to talk about not only why you should support the open source projects you use, but how you can.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-015.mp3
@nbsp;
download
$nbsp;
Reposting a classic episode this week because I was out of town and didn’t get around to editing an episode.
A BBC journalist recently performed a silly experiment to prove a very serious point. In just 20 minutes, he manipulated ChatGPT and Google into telling the public he was a world-champion competitive hot dog eater.
Many (perhaps most) of the BGP route leaks reported on Cloudflare Radar (as with its predecessors) are what I term ‘ephemeral leaks‘, brief routing anomalies that exist only momentarily during convergence and have little to no operational impact.
In this episode of PING, APNIC Chief Scientist Geoff Huston and I discuss the Network Time Protocol (NTP). NTP is one of the oldest systems we rely on today.
The Gentlemen ransomware is a ransomware-as-a-service (RaaS) threat that is distinguished by its ability to pair its strong per-file encryption with an aggressive self-propagation capability designed to enable broad network compromise.
LLMs can help tame the complexity at the root of many of today’s software security challenges.
If you advertise routes into the default free zone (or global Internet), you might struggle with seeing and understanding what they look like “on the other side.” While there are many manual tools to help operators with this process, bgproutes.io gives you visibility in the global routing table through interfaces like BMP. Listen to this episode of the Hedge to learn more.
You can find bgprotues.io here.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-307.mp3
download
The rising power demand of the data center industry almost appears like an industry running within the integrated grid but outside the usual paradigm of the traditional electric utility sector. Indeed, it should be treated as such.
Much has been said about the use of the DNS as a means both of tracking the online behaviour of individual users and as a means of online censorship and control. Almost every online transaction starts with a DNS query, and if one were able to assemble the complete set of DNS queries generated by an individual user it would be possible to assemble a relatively complete profile of their online activity.
Let’s say you wanted to make sure that your AI is secure. Can you just maximize the security and privacy benchmark and call it a day? Nope.
The internet is fragmenting. Not in the future. Now. At three different layers simultaneously.
In June, Microsoft Secure Boot certificates are set to expire for the first time ever.
Synchronizing information across the Internet, at an initial glance, looks like a fairly simple problem to solve. Just copy a file to a host and create a magic protocol, right? Not really. Each kind of data has a fairly unique set of requirements–and RPKI data, used to provide security information for BGP, is no different. Job Snijders joins Tom and Russ to talk about ERIK, a protocol developed to synchronize RPKI records.
For more information, check out Job’s web site and the IETF draft.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-306.mp3
download
The Technocratic State represents a new invisible risk of the 21st century, as it does not present itself as a conventional political authority. It appears as a technical solution that seems inevitable.
Author and journalist Michael Pollan characterizes our era as the “Second Copernican Shock,” a civilizational turning point where the boundary between human empathy and algorithmic calculation is increasingly blurred.
It’s always difficult for ISPs to fully understand how changes in the economy might impact them. Folks in the industry see the usual statistics on unemployment and inflation, but those don’t really tell much about the future as it relates to broadband adoption.
Companies rushing to adopt AI and LLMs without a clear strategy may be creating new risks.
Power failures are to blame for the most impactful data center outages, while network issues are the most frequent culprits for IT service disruptions, according to Uptime Institute’s latest analysis.
We’ve all been in that meeting where someone pulls up a chart and says, “Our AI product boosted conversion by 15%.” Everyone nods. Nobody dares to ask: “What if conversions had risen anyway?”
The proposed repair is Running-Code Primacy: the number-resource layer should be interpreted only by reference to the minimum technical function running networks require—uniqueness, interoperability, proof of control, routing-adjacent security, and locally verifiable state.
You already know IPv6 is overdue. You’ve known for years. You’ve probably sat in a meeting where you laid out the case — address exhaustion, rising costs, growth constraints — and watched leadership nod politely before approving the budget for another batch of leased IPv4 addresses.
A key question was whether this reflected a breakthrough specific to one model, or part of a broader trend. Results from an early checkpoint of GPT-5.5 suggest the latter: a second model, from a different developer, now reaches a similar level of performance on our cyber evaluations.
The most mature U.S. small modular nuclear reactor vendor — NuScale Power — and a politically connected firm planning to build perhaps the largest reactor project in the U.S. to power an enormous Texas data center — Fermi America — have both suffered recent, major, possibly existential blows.
Given the trend of using generative AI tools like ChatGPT, Gemini, Copilot, and Claude for software development, many companies have decided that developers must use GenAI to succeed. I strongly disagree.
Here, through a series of randomized controlled trials on human-AI interactions (N = 1,222), we provide causal evidence for two key consequences of AI assistance: reduced persistence and impairment of unassisted performance. Across a variety of tasks, including mathematical reasoning and reading comprehension, we find that although AI assistance improves performance in the short-term, people perform significantly worse without AI and are more likely to give up.
Last month, market research company, Gartner, said that AI companies need close to “$2 trillion per year in revenue by 2029”, token consumption of between 50,000 and 100,000 times its current rate by 2030, and “a 10% profit margin per token.” With huge losses and small revenues, it is not likely that AI companies will achieve these goals on time.
He said that about 20% of all network traffic today, about 80 exabytes, comes from machine-to-machine traffic, and that alone is big news. Nokia is betting its future growth will come from meeting this growing demand.
For centuries, political power has repeatedly attempted to territorialize systems whose operational logic depended upon openness, circulation, and coordination beyond borders.
We don’t often hear the stories of those who move from some other IT career field into network engineering. Ayush Mishra, a student at University of Colorado Boulder, joins Tom and Russ to discuss why he moved from security to network engineering.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-305.mp3
download
The screenshot feature has cultivated a wide range of impactful academic research across computing and social scientific fields.
When Motorola unveiled its Iridium global satellite-based mobile telephony service in the late 1990’s everything augured well for a revolution in the satellite communications market, only it didn’t happen.
While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk.
The analytic company IDC says the U.S. economy will be generating 394 trillion zettabytes of data annually by 2028 (a zettabyte is a trillion gigabytes).
Enterprise strategists need to worry about securing their environments against AI-powered attacks.
These milestones highlight the significance RPKI has gained over the past decade. Starting off as an experimental technology, it has become a central component of the Internet, affecting a large percentage of its networks.
More than 9.7 million third-party businesses sell goods on Amazon, and Amazon makes a lot of money charging those third parties to sell on its platform—$117.7 billion in 2022, representing 23% of Amazon’s total revenues.
For much of the history of computing, it was reasonably safe to assume that a machine was doing what you told it to do (and what its creators promised it would do), because its operations were local.
There is always the case that the unexpected happens, and X.509 certificates are no exception. There are circumstances where the certificate should be marked as unusable immediately, which is before the notAfter expiration time.
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure.
If you’ve ever been curious about what an advanced degree in network engineering looks like, you’ll want to join us for this episode of the Hedge. Levi Perigo from the University of Colorado at Boulder joins Tom and Russ to talk through what earning a Master’s in Networking involves and what kinds of things you would learn.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-204.mp3
download
DDoS mitigation often relies on BGP for “scrubbing”, but how this appears in routing data is not well understood. We analyse five major providers to distinguish between always-on and on-demand protection.
This column argues that without AI, adequate privacy has become simply out of reach. This is not because AI is benign; it most definitely is not. Rather, the modern digital ecosystem has evolved to a point where no human, unaided, can understand, monitor, or manage the complexity of today’s data practices.
Conventional memory schemes follow the Pareto Principle, in which approximately maintaining 20% hot data can meet 80% of requests. L
Google has just forked its Tensor Processing Unit, or TPU, designs for these two workloads, the very first time in more than a decade that TPU systems of the same generation were truly architecturally distinct from each other.
Fake domains are not a new problem. What’s now changing is the scale and how easily attackers can blend into your domain ecosystem with lookalikes, inactive registrations, and domains set up purely for email.
What can we learn about QUIC deployments just by listening to unsolicited QUIC traffic? This question becomes specifically exciting since QUIC aims for enhanced privacy by obfuscating metadata.
Securing AI means securing all the AI layers and throughout the lifecycle: data, model, and applications, in training and in inference.
According to a Reuters report, Meta is installing tracking software on its employees’ work computers. The tool, called Model Capability Initiative (MCI), will log mouse movements, clicks, and keystrokes. It will also take occasional screenshots of employees’ screens.
Despite its usage, the behaviour of BGP-based scrubbers is not well understood, such as whether scrubbers are always on-path or activated on-demand.
The UK’s National Cyber Security Centre (NCSC) has officially endorsed passkeys as the default authentication standard, marking the first time the agency has told consumers to move away from passwords entirely.
Many BGP route leaks reported by automated detection systems are actually brief, low-impact artifacts of normal BGP convergence.
Long round‑trip times have serious consequences for protocols like TCP, which rely on a steady stream of acknowledgements (ACKs) to manage sending rates, estimate delay, and trigger retransmissions.
As datacenter networks evolve toward ultra-high-speed links, the energy footprint of host-side packet processing grows increasingly significant.
The old perception of satellite internet as slow, expensive, and marginal is increasingly outdated. Today’s market includes multiple orbital models, each with distinct technical and operational characteristics.
What can we learn about QUIC deployments just by listening to unsolicited QUIC traffic? This question becomes specifically exciting since QUIC aims to enhance privacy by obfuscating metadata.
In this roundtable episode of the Hedge, Eyvonne, Tom, and Russ hang out and talk about data centers–why are we building all these things again? Our second topic is the FCC’s ban on non-US made home routers. Was this the right thing to do? Was it the wrong thing to do? Were there any other policy options?
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-303.mp3
download
In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings.
This report explores the evolution and current state of neuro- symbolic artificial intelligence, an approach that integrates neural network capabilities with symbolic reasoning.
The Linux 7.0 kernel is now out, and it’s one of the most impactful releases in years for networking professionals.
The human-speed defense of small business is being obliterated by the machine-speed offense of AI-driven cybercrime. Today, what large companies treat as a manageable risk is a terminal expense for small enterprises, with 60% of small enterprises shutting down within six months of a major attack.
The original frustration was familiar. You build on one provider, they change pricing, deprecate an API, or just aren’t the right tool anymore, and migrating is brutal.
What does biology have to do with computer networks? Much more than you might think. Communications systems, after all, need to solve the same problems–and they often use the same kinds of tools. In this episode of the Hedge, Emily Reeves and Joe Deweese join Russ and Tom to talk about a recent paper comparing computer communications to biological communications.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-302.mp3
download
Tech leaders hoping AI might help save money and improve efficiency in IT infrastructure should know that only 28 percent of use cases fully succeed and offer return on investment (ROI).
The best strategy in the world won’t succeed if a team falters operationally. But what is operational excellence, and what does it take to acquire it
Industry analysts are using the word convergence as shorthand for competition that bundles cell service with broadband. Convergence is the newest strategy that replaces the traditional bundling strategy of selling a package of broadband, cable TV, and voice.
Leaving aside my discovery that YouTube videos on the Naturalistic Fallacy are branded by female cleavage (???), we move on to the two problems embedded in statements I hear by articulation and by implication in the public discourse: “We must cultivate trust in AI,” and “AI acquiescence is inevitable.”
Most engineers don’t think about securing TCP itself. We rely on the applications riding on top of the network. When you run routing protocols or long-lived control sessions across untrusted or shared infrastructure, TCP becomes part of your attack surface whether you planned for it or not.
What are networking fundamentals, and why are they important? Join us for this repost of a classic Hedge discussion with Ethan, Eyvonne, Tom, and Russ.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-030.mp3
download
Stanford researchers are warning that using AI chatbots for personal advice could backfire. The problem isn’t just accuracy, it’s how these systems respond when you’re dealing with complicated, real-world conflicts.
During the APNIC Routing Security Special Interest Group (SIG) session at APRICOT 2026 / APNIC 61, APNIC and LACNIC presented a case study of a Border Gateway Protocol (BGP) hijack that combined a technical attack with social engineering.
It is widely believed that all BGP routers within an Autonomous System (AS) must be connected in a full iBGP mesh, or, when this becomes impractical, that route reflectors or confederations must be used. However, a full mesh is not always necessary, and in some scenarios it may even be undesirable.
The skies are quickly filling with communications satellites. Following is a short list of the many ventures that have or will soon be launching large numbers of broadband satellites.
In early demos, the system looked impressive. It could summarize logs, explain configuration issues, and suggest possible fixes. Instead of digging through internal docs, the answers were coming back in seconds. For a while, it really felt like this system was going to work as expected.
What appears as double extraction at the operator level becomes something larger and more serious at the level of the state. It becomes sovereignty inversion.
Major memory makers have already sold all the kit they can make this year, creating shortages and price increases.
It’s fading from our collective memory, but almost thirty years ago the global IT industry was gripped by Y2K fever.
What do you get when you combine Big Tech, a Bill Clinton fixer, Davos, the architect of the Hunter Biden laptop disinfo, and “Artificial Intelligence”? The biggest heist in world history.
Stop blaming the GPUs! Your AI feels slow because data is getting stuck in traffic. Fix the “supply chain” to keep those tokens flowing.
What’s the deal with SONiC? Is it easy to build and use, or hard? Is it something you should be looking at? Jeff Doyle joins Russ and Tom to look at the SONiC operating system, ecosystem, and deployment.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-301.mp3
download
This document provides DNS deployment guidelines to secure the DNS protocol and infrastructure, mitigate misuse or misconfiguration, and provide an additional layer of network security as part of a zero trust and/or defense-in-depth security risk management approach.
However, eBPF has not seen similarly widespread adoption in other types of networked applications, such as web servers and databases. In this blog post, we argue that this gap stems from limitations in the current eBPF architecture — specifically, the kernel runtime, APIs, and compiler toolchain.
Time and again, I see people begging for companies with deep pockets to fund open source projects. I mean, after all, they’ve made billions from this code. You’d think they could support the code’s creators and maintainers. It would be only fair, right?
The weird, rare, surprising patterns that make data rich slowly get smoothed out when an AI model trains on outputs from a previous model.
In the previous note, the claim was not that the registry layer merely imposes visible fees or administrative inconvenience. The claim was more precise. The first extraction occurs when a scarce, transferable, revenue-enabling resource is kept institutionally discounted through non-asset rhetoric, conditional recognition, and friction around transfer and use
It’s episode 300, and it’s roundtable time. In this episode, Tom, Eyvonne, and Russ talk about how systems can be designed to prevent injection attacks, and then the perennial unpleasantness of layoffs.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-300.mp3
download
For organizations in telecommunications, financial services, healthcare, and public infrastructure, the driver for running inference at the edge is not to reduce milliseconds. It is because the data cannot legally leave the building, the country, or the jurisdiction.
Internet number resources are not political property. They are operator-held assets embedded in functioning networks.
Just over half of U.S. teens say they have used chatbots for help with schoolwork, and 12% say they’ve gotten emotional support. More teens think AI will be positive for them than negative
You’ll use AI and like it too – if you work for PwC. Paul Griggs, US chief executive of the global professional services giant, has made clear there is no room at the corporation for AI skeptics.
For some time, I have been looking after a routing analysis report called the “CIDR Report”. Here I’d like to explain the reasons for this report, and what is in the report and share some thoughts as to its usefulness today to the Internet routing community.
The ENIAC (Electronic Numerical Integrator and Computer), a machine that profoundly reshaped computing, marked its 80th anniversary on 15 February 2026. ENIAC was a technological leap that laid the foundation for the modern computing revolution and eventually transformed nearly every aspect of society.
During the APNIC Routing Security SIG session, held at APRICOT 2026 in Jakarta, the community heard about six applications of Resource Public Key Infrastructure (RPKI) to the problem of secure Internet routing.
There is no doubt that automation offers benefits such as speed, accuracy, reliability, and efficiency, and goes far beyond simple configuration management tasks, including resource provisioning. However, it may not be a good fit for every infrastructure environment. One must evaluate and compare the pros and cons before adopting automation.
Meta’s Ray-Ban smart glasses are a privacy nightmare, with footage of naked people, sensitive information, and violent acts captured and seen by Meta’s AI and an army of employees.
MOSAIC ditches lasers for cheap MicroLEDs and medical imaging fiber, cuts cabling energy by up to 50%, and already fits in a standard transceiver after a proof-of-concept with MediaTek.
As malicious domains continue to pose a threat across the Internet, security professionals are left to consider the measures that can effectively defend their organizations from these threats.
Right now, a growing chorus is treating India’s “lock and suspend” approach as a success story and a model for the world.
On the last day of December 2016 there was a brief hiccup as the world’s clocks adjusted their time according to the Coordinated Universal Time (UTC) standard by adding an extra second to the last minute of the 31st of December.
For the past decade, Docker has provided a robust solution for building, shipping, and sharing applications. But behind its simple “build and run” workflow lie many years of complex technical challenges.
AI assistants that produce drawings and other output that looks like evidence reduce questioning without increasing correctness.
As we discussed in the prior episode, the 6G hype is building. What’s in 6G, though, and how realistic is it that a new wireless technology is going to radically change the world? In this episode of the Hedge, George Michaelson joins us from Australia to discuss the ins and outs of 6G.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-299.mp3
download
A number of recent changes have helped to push Ethernet forward, advancing its capabilities to better meet the needs of AI.
Cloudflare has confessed to a coding error using a React useEffect hook, notorious for being problematic if not handled carefully, that caused an outage for the platform’s dashboard and many of its APIs.
Working with MikroTik and IP Infusion’s OcNOS to interop EVPN/VxLAN has been on my wish list for a long time.
Have you heard about MRT dumps, but never tried to use them because the bar seems too high? Or are you tired of doing “parse -> grep -> process” every time you touch BGP MRT dumps?
Unfortunately, history is again being rewritten. It is rapidly becoming clear that LLMs are not economical.
As part of our research into post-quantum cryptography (PQC) for DNSSEC, we test PQC as a drop-in replacement for classical algorithms. We explore a transition where both run simultaneously, analysing how resolvers validate records, edge cases, and the feasibility and impact of such a period.
In much of the world, we are in an era that I like to call the “post-gigabit era”. Many users have access to gigabit connections—or at least hundreds of Mbps—and have moved from an era of bandwidth scarcity to bandwidth abundance.
“Where are you?” is not an easy question to answer on the Internet. The telephone system’s address plan embedded a certain amount of physical location information in the fixed line network, and a full E.164 telephone number indicated your location in terms of your country, and your area within that country.
Sure, some days you hate your job. But how do you know when an IT position has gone from being run-of-the-mill annoying to truly toxic
The digital world is shifting toward access rather than ownership, and nothing shows this more clearly than the rise of subscription-based business models.
We network engineers often find ourselves without a viable plan–our plans always seem to go awry, to the point that many network engineers just give up on planning. Is “giving up” the right solution? Or can we learn to be better planners? Jonathan Adams and Tim McConnaughy join Russ to discussion planning for network engineers.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-283.mp3download
On this episode of the Hedge, Anil Varanasi joins Russ to talk about the complexities of network operations and what Meter is doing in this space.
note: even though this is a more product-heavy episode of the Hedge than usual, it is not sponsored
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-282.mp3
download
Multicloud is all the rage — but is this always an intentional state of affairs, or do companies just “fall into” multicloud? Security in multicloud and certifications round out this episode of the Hedge, where we are joined by Joe Cozzupoli. You can get in touch with Joe through twitter at @jcozzupo24150.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-004.mp3
download
“Classic” TCP uses an extremely simple loss-based congestion detection algorithm that is intended to save networks from collapsing under extreme overload.
The endgame is a society where corporate algorithms make decisions about employment, education, and social interaction with no accountability.
The rise of Agentic AI, the emergence and adoption of AI agents and agent-to-agent networking to autonomously perform tasks on behalf of humans, has introduced unique challenges for existing security products.
In the landscape of organizational management, a distinction exists between teams that (a.) efficiently deliver a high-quality service or product, and (b.) those that innovate and develop their thought leadership in an area of emerging technology.
Broadcom CEO Hock Tan delivered a rather defiant keynote to open the VMware Explore conference in Las Vegas recently, telling the audience they are better off using the latest version of VMware Cloud Foundation (VCF) on-premises than hyperscale cloud service providers.
The public is told that AI systems are super smart and have the world’s info at their electronic beck and call. At the same time, it is humans and human organizations who claim professional expertise and so deliver their “truth” via media and Internet.
While Eutelsat’s OneWeb operates the second-largest commercial LEO satellite network, its real-world network performance remains largely unexplored by researchers, due to its targeted enterprise and government markets.
If AI is to become pervasive, as the model builders and datacenter builders who are investing enormous sums of money are clearly banking on it to be, then it really goes have to be a global phenomenon.
It looks to me like history is repeating itself. We’re seeing the same hype cycle for 6G that we saw for 5G.
This article taxonomizes the 25-year history of IPID-based exploits and the corresponding changes to IPID selection methods. By mathematically analyzing these methods’ correctness and security and empirically evaluating their performance, we reveal recommendations for best practice as well as shortcomings of current operating system implementations, emphasizing the value of systematic evaluations in network security.
But for NaaS to truly transform enterprise networking, one thing has been missing: standards. Enter Mplify (formerly the Metro Ethernet Forum), a non-profit focused on standardizing NaaS service definitions.
What is the relationship between blockchain technologies and network engineering? Is blockchain “just another application,” or are there implications for naming, performance, and connectivity? Austin Federa joins Tom and Russ to discuss the intersection of blockchain and networks.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-281.mp3
download
When you think of careers in network engineering, you probably think of being a console jockey, racking and stacking and configuring boxes. There is, however, much larger than just these things. Ethan Banks joins Eyvonne and Russ to talk about the broader world of careers in network engineering.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-280.mp3
download
The arrangements regarding the composition and organisation of the provision and operation of authoritative root servers are one of the more long-lasting aspects of the public Internet.
Microsoft has achieved a breakthrough in the hollow core fiber technology, reducing data transmission loss to just 0.091 dB per kilometer, the lowest ever achieved and significantly below the 0.14 dB/km limit that has constrained fiber networks for decades.
China has pursued a strategy of competition among government-owned organizations, and it initiated two government-owned constellation projects, Hongyun and Hongyan, in 2018.
There is no question that one of the smartest things that chip designer, packager, and manufacturing process manager Marvell Technology did was to shell out $650 million in May 2019 to buy Avera Semiconductor.
In early 2024, a Hong Kong-based clerk at multinational consulting engineering firm Arup was duped into transferring about $25 million to scammers who used AI to impersonate the company’s CFO, and other senior executives, in a live video meeting.
Returning to a thread here at the Hedge, Rick Graziani joins Tom and Russ to discuss a college professor’s perspective on why network engineers should learn the theory, and not just the configuration.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-279.mp3download
Among the plethora of advanced attacker tools that exemplify how threat actors continuously evolve their tactics, techniques, and procedures (TTPs) to evade detection and maximize impact, PipeMagic, a highly modular backdoor used by Storm-2460 masquerading as a legitimate open-source ChatGPT Desktop Application, stands out as particularly advanced.
In this episode of PING, APNIC’s Chief Scientist, Geoff Huston, explores the economic inevitability of centrality in the modern Internet.
Philipp delivers a sober message for innovators: invention is only half the battle; defending your invention can define your company’s fate.
Google now estimates that the specs for a Cryptographically Relevant Quantum Computer (CRQC), which can break conventional public key encryption in a useful amount of time, are lower than they had previously estimatedナby 95%.
In this report, I’ll focus on the material presented at the DELEG and DNSOP Working Groups.
Can we trust AI? Will AI take our jobs? Is an AI app safe? Shall we invest in AI company? Create an AI startup? Will AI accelerate cybercrime?
This study highlights the inadequacy of current privacy protection measures and proposes an automated, sustainable approach to correlate user profiles, including homonyms and pseudonyms, solely through publicly available data.
Bargury’s attack starts with a poisoned document, which is shared to a potential victim’s Google Drive. (Bargury says a victim could have also uploaded a compromised file to their own account.)
I wrote last week about three examples of the new GPT 5.0 chatbot contradicting Sam Altman’s claim that “it really feels like talking to an expert in any topic, like a PhD-level expert.”
RFCs are, inherently, the result of a design-by-committee writing process; usually intended for engineers to read. Especially with cryptography, they err on the side of technical specification rather than introductory blog post.
The transition to IPv6 is now a practical necessity for networks under pressure to scale, secure, and streamline their operations.
In this episode of PING, Robert Kisteleki from the RIPE NCC discusses the RIPE Atlas system — a network of over 13,000 measurement devices deployed worldwide in homes, exchange points, stub and transit Autonomous Systems, densely connected regions and sparse island states.
The common denominator in both tests was technology called “Innovative Optical and Wireless Network” (IOWN), an all-optical networking stack that NTT hopes will mature in 2030 and expects will reduce power consumption by 100x, improve transmission capacity by 125x, and reduce network latency to 0.5 percent of current levels.
Internet Exchange Points (IXPs) are often overlooked in discussions about critical infrastructure. Yet their role in routing stability, local resilience, and digital sovereignty is undeniable.
Is adding AI to your environment a software purchase? Or is it more like hiring an employee?
Design by committee should always ring alarm bells, particularly in technology. The desire to achieve acceptable compromises between various opinions often leads to compromised technical outcomes, and it seems to me that the current work on redefining zone cuts and delegation in the DNS is leading to this same outcome
The TCP/IP Interoperability Conference—later renamed Interop—began as a small workshop in August 1986. It quickly grew in scope to incorporate tutorials, and by 1988 an exhibition network connected 51 exhibitors to each other and to the global Internet.
There is a relatively new fiber technology that most readers will not have heard about. Multi-core fiber (MCF) is a technology that packs multiple strands of fiber inside a bundle that is about the same size as a single strand of fiber today.
This is where the “Jericho” StrataDNX switch/router chips and their related “Ramon” fabric elements come in, which are an important part of the Broadcom datacenter networking portfolio.
We had a series of mini-outages at sketch.dev on July 15th, caused by LLM-written code.
“Advocate for yourself!” What does this mean, and how can you do it? Alexis Bertholf joins Tom and Russ to discuss practical strategies to advocate for yourself.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-278.mp3
download
From time to time, I like to dive into the archive and find a show that’s worth repeating. Forthwith, Derrick Winkworth and automation.
Network automation efforts tend to focus on building and maintaining configurations–but is this the right place to be putting our automation efforts? Derick Winkworth joins Tom Ammon and Russ White at the Hedge for a conversation about what engineers really do, and what this means for automation.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-003.mp3
What is the relationship between humans and machines? Do we adapt to machines, or do we adapt machines to humans? Does technology drive culture, or does our culture drive our technology? Join Mark Prosser, Eyvonne, Tom, and Russ as they discuss what a sociotechnical system is and how it impacts our lives.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-277.mp3
download
The current state of digital identity is a mess. Your personal information is scattered across hundreds of locations: social media companies, IoT companies, government agencies, websites you have accounts on, and data brokers you’ve never heard of.
It turns out that, if you have your domain hosted by a big provider (we happen to use GoDaddy), it’s easy to turn on DNSSEC. But I think it says a lot that it took us this long (and the stimulus of working on a new security book) to get us to turn on DNSSEC
As we left the laboratory, I thought about how we in the computing field build a tremendous number of things that really cannot be called beautiful and then are commonly tossed aside without a thought.
The accelerated migration to advanced services will be accompanied by unprecedented complexity, and security and reliability concerns that must be addressed by the network-engineering and formal-methods communities.
Quantum scientists have long treated quantum entanglement as precious cargo, forging fresh links for every secure message or computation. A new theoretical study proposes a thriftier route, letting an existing pair pass portions of its entanglement down an extended chain.
Fast following fails.
Whenever I hear a leader in a technology business say, “We’re going to fast follow because it’s the most profitable place to be,” I know I’m looking at a failed organization. I didn’t come to this conclusion by thinking about it. I came to this conclusion by observing it repeatedly.
After observing it, however, I wanted to understand why this particular strategy fails so consistently and spectacularly. Why? To understand my theory, we need to start in a somewhat different place than business—we need to start with the nature of goals and humans.
You can place goals into two buckets: first things and second things.
First things are foundational. If you are a technology company, the first thing is building a stable, resilient, and flexible platform (or foundation). The products you sell will only be as stable as your platform. The innovation you achieve will only be as consistent as your platform is.
Second things are goals you can only achieve once you’ve built the first things.
Here’s the hard truth no one wants to hear: Generating revenue is a second thing.
Humans become what they do.
We all want to believe we can become what we desire—but we actually become what we do. In Aristotelian philosophy, this is called the virtue ethic. You become physically virtuous by exercising your body. You become intellectually virtuous by thinking about hard things.
Companies are the same way. A company can only become innovative by innovating. Innovating becomes a habit—or it doesn’t.
What does this have to do with fast following?
The theory of the “fast follower” is: “I’m going to let other people spend money on research and development, I’m going to let them carry the burden of innovating and making all the mistakes, then I’m going to jump in and scoop up their innovation.”
This seems sound at first glance. It’s a compelling story.
It doesn’t work, however, because you are chasing another organization’s success without building their platform. You’ve placed a second thing—revenue generation—in first place, and first things—building a platform and innovating—in second place.
When you put building a platform and innovating on top of that platform in second place—when you “fast follow”—you lose the habit of building a solid platform and the habit of innovating.
Building a platform on which you can actually ship innovative products—no matter who invented them—and cultivating a mindset that seeks out good innovation creates a culture of innovation. When you build the mental habit of waiting until someone else’s innovation succeeds and then building “just enough platform to make it work here, too,” you are building an unstable platform and killing innovation.
“But what about all those fast-following success stories?”
One reason “fast following” success stories abound is that you can make a lot of money for a little while with the fast-following strategy. Another is that when an organization first moves to fast following, they have the leftover platform and innovation culture to carry them for a little while.
But time will out all fast following organizations. When the market shifts, fast followers will have neither the platform to shift with it nor the innovation to change with the market.
By putting second things first, the fast follower loses the first things that make the second thing possible.
“But I’ll make a lot of money until it fails, right? I don’t care about the future, just making a lot of money quickly!”
Sure, if that’s the life you want to lead, go for it. If you want to live a life devoid of community, and you want to lie on your deathbed and say, “I don’t care what damage I caused,” if sheer wealth is all that matters, feel free to fast follow.
If you want to build something, however, go build it.
Fast following gives up building platforms and innovating for immediate success, and winds up failing to innovate or succeed.
Requests for proposals (RFPs) are a little understood part of running a network–or any other IT system. What are some common mistakes, and some things engineers should think about, when building and executing RFPs? Andreas Taudte joins Tom and Russ to discuss RFPs.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-276.mp3download
We sketch out the enabling technologies for AI. They include search, reasoning, neural networks, natural language processing, signal processing and computer graphics, programming and conventional software engineering, human-computer interaction, communications, and specialized hardware that provides supercomputing power.
For decades, thanks to the low latency enabled by Remote Direct Memory Access, or RDMA, a method of allowing CPUs and then GPUs and finally other kinds of XPUs to directly access the main memory of each other without having to go through the entire network software stack, InfiniBand found a niche and was one of the reasons why Nvidia shelled out $6.9 billion to acquire Mellanox Technologies more than five years ago.
Shipments of tape storage media increased again in 2024, according to HPE, IBM, and Quantum – the three companies that back the Linear Tape-Open (LTO) Format.
In this episode of PING, APNIC’s Chief Scientist, Geoff Huston, discusses a day in the life of Border Gateway Protocol (BGP). Not an extraordinary day, not a special day, just a regular day.
Dumb phones represent the laziest possible solution to a complex behavioral problem. They’re the dietary equivalent of having your jaw wired shut.
What is Jevon’s Paradox? Tom, Eyvonne, and Russ discuss how this famous paradox impact network engineering.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-275.mp3
download
They call themselves Scattered Spider. They’re probably younger than your college freshman. They live in suburban bedrooms across America and Britain, and they’ve just brought industries to their knees.
The RPKI makes use of RSA signatures. These “traditional” digital signatures are expected to be vulnerable to attacks with powerful quantum computers. While no quantum computer currently exists that can break traditional cryptography, the development of quantum computers is progressing rapidly, and it is expected that they will be able to break RSA and other traditional cryptographic algorithms, be it in several years or several decades.
Analysing Transmission Control Protocol (TCP) SYN segments, the initial step in the TCP three-way handshake, can reveal patterns and anomalies in network traffic, providing insights into potential threats.
One way to establish if a QUIC connection is viable without paying a time penalty is for the server to signal the capability to use QUIC to the client in the first (TCP/TLS) connection, allowing the client to initiate a QUIC session on the second and subsequent connections.
These are not bugs but are inherent limitations of the technology. The same limitations make it unlikely that LLM machines will ever be capable of performing all human tasks at the skill levels of humans.
Is Your Wi-Fi Router Tracking Your Browsing? Here’s What 30,000 Words of Privacy Policies Revealed.
Browser Dating wants your search history — all of it. Your 3 a.m. Reddit rabbit holes, your medical anxieties, your peculiar curiosities about President Trump’s hair, and whether cats plot murder.
Now, people are rethinking the trade-off. Ubuntu has disabled some protections, resulting in 20% performance boost.
Each time you swipe a loyalty card, you’re not just saving on groceries—you’re feeding a powerful data machine known as retail media.
Over the last ten years, more than 600 million websites have been secured with free certificates from Let’s Encrypt. Here’s how it all began and why.
What is DNS Delegation and what is it used for? What is new in the Delegation world, and what impact does it have on DNS security and operations? George Michaelson joins Tom Ammon and Russ White for a discussion about DNS DELEG in this episode of the Hedge.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-274.mp3download
Many of us old timers (and a lot of young timers) worry about the future of networking. What if the future isn’t a technology, or even AI, but a change in focus? Mike Bushong joins Tom and Russ to argue for operations as the future of networking.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-273.mp3
download
Ossification is still a major issue in today’s networking environment, and while it’s not a theme in the architecture of the transmission platform, we see it in the Internet Protocol itself, in our transport protocols, in our routing protocols, and in various applications.
The Federal Bureau of Investigation (FBI) is issuing this Public Service Announcement to warn the public about cyber criminals exploiting Internet of Things (IoT)1 devices connected to home networks to conduct criminal activity using the BADBOX 2.0 botnet2.
hile the architecture of the 900 series had no support for partitioning memory (requiring cooperation for multi-user activity), and many ran without any operating system at all, there was an optional NPL interface.
Most protocols do not have the equivalent of an X-Forwarded-For header. To solve this, HAProxy came up with the PROXY protocol, which is a Layer 4 protocol that allows a proxy server to communicate client information to a backend server.
If you built a proper technology strategy in the first place, driven by the business strategy, then no matter what is happening don’t ignore it, and don’t throw it out—update it and stick to it!
Are you stressed? Everyone in IT seems to be continuously stressed–but what can we do about it? Sonia Cuff joins the Hedge to talk about stress.
https://content.blubrry.com/hedge/hedge-001.mp3download
From time to time we like to repost episodes of significance–this week we’re reposting episode 1.
Is the CLI the best way to configure, manage, and troubleshoot routers and other networking gear? Or should we move past the CLI towards automation and (possibly even) GUI-based tools? Mark Posser joins Russ and Tom to discuss on this episode of the Hedge.
https://media.blubrry.com/hedge/media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-272.mp3
download
For more reading on this topic, please check out this post by Chris Grundemann.
If you’ve worried that AI might take your job, deprive you of your livelihood, or maybe even replace your role in society, it probably feels good to see the latest AI tools fail spectacularly.
The Virginia Supreme Court issued a ruling against Cox Communications that should trouble anybody building a fiber network that must cross railroad tracks. The case involves a dispute brought by the Norfolk Southern Railroad that challenged a new right-of-way law related to railroads.
Julia Angwin’s opinion piece clutches at courtroom verdicts and minor regulatory wins like a child gripping a plastic sword in the middle of an actual war. Yes, there are lawsuits.
This makes a huge difference to the way ChatGPT works: it can now behave as if it has recall over prior conversations, meaning it will be continuously customized based on that previous history.
Traditionally, Cilium’s BGP implementation required users to explicitly specify peer IP addresses in BGP cluster configurations to establish BGP sessions with Top-of-Rack (ToR) switches. While this approach functions adequately in small environments, it becomes difficult to manage for large-scale deployments involving thousands of Kubernetes nodes distributed across numerous racks.
There has been a major change in the landscape of the internet over the past few years with the progressive introduction of the QUIC transport protocol. Here I’d like to look at where we are up to with the deployment of QUIC on the public Internet. But first, a review of the QUIC protocol.
The PCI Special Interest Group (PIC-SIG) just released official specs for PCIe 7.0, doubling the bandwidth again for high-performance kit such as network cards, while hinting that PCIe 8.0 may not achieve the same.
Our model training with adversarial data significantly enhanced our defenses against indirect prompt injection attacks in Gemini 2.5 models (technical details).
Apple has a new paper; it’s pretty devastating to LLMs, a powerful followup to one from many of the same authors last year.
Good intentions don’t always result in good outcomes. This is especially the case with recent suggestions regarding end-to-end-encryption adaptability requirements for number independent communication services.
asically, model collapse happens when the training data no longer matches real-world data, leading the new LLM to produce gibberish, in a 21st-century version of the classic computer aphorism “garbage in, garbage out.”
As AI workloads scale to thousands of accelerators, the interconnect fabric (also known as a scale-up fabric) for rack-scale systems is under intense scrutiny. Significant advancements are reshaping scale-up connectivity in 2025.
Standardized in 2021, QUIC is a UDP-based protocol designed to improve upon the TCP / TLS stack. While the QUIC protocol recommends pacing, and congestion control algorithms like BBR rely on it, the user-space nature of QUIC introduces unique challenges.
According the Google Cloud’s mini incident report, the issue occurred due to an invalid automated quota update to the API management system, which was distributed globally, causing external API requests to be rejected.
The specification details enhancements to Ethernet that improve low-latency transport in high-throughput networking deployments. It includes a modern Remote Direct Memory Access (RDMA) approach, direct memory access implementations, transport protocols, and congestion control mechanisms.
AI chatbots and image creators are all the rage right now–we are using them for everything from coding to writing books to creating short movies. One question we do not ask often enough, though, is how this impact human creators. How will these tools shape creativity and thinking skills?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-271.mp3download
This report examines the growing global trend of Internet blocking and its impact on the stability, openness, and interoperability of the Internet. It details how governments and private actors are increasingly using network-level interventions—such as DNS blocking, IP address blocking, and protocol filtering—to control online content.
Broadcom began shipping its answer to Nvidia’s upcoming Quantum-X and Spectrum-X switches on Tuesday: the Tomahawk 6. The chip doubles the bandwidth of its predecessor and comes in both standard and co-packaged optics flavors.
Artificial intelligence, once hailed as the great liberator of human productivity and ingenuity, is now moonlighting as a con artist, data thief, and spy.
The current craze for AI has helped drive a wave of datacenter building, but the industry has run into opposition from local communities in many areas, something it is understandably keen to address.
Low orbit space is growing increasingly crowded. Starlink has over 7,100 satellites in orbit and has plans to grow to 30,000. Project Kuiper has plans for a constellation of 3,232 satellites.
The story of computing and communications over the past eighty years has been a story of quite astounding improvements in the capability, cost and efficiency of computers and communications.
In recent discussions, it became clear that additional information could be helpful, breaking down what a user or administrator needs to understand about TLS implementation and configuration options to better assess points of potential exposure.
The use of pseudo-random processes to generate secret quantities can result in pseudo-security. A sophisticated attacker may find it easier to reproduce the environment that produced the secret quantities and to search the resulting small set of possibilities than to locate the quantities in the whole of the potential number space.
We’ve all had the serendipity experience, even online — clicking through a chain of links, scanning Google search results, drifting between loosely connected ideas. But search engines and information retrieval systems aren’t designed to enhance serendipity.
Here I want to look at just one day of the operation of the Internet’s BGP network by looking at the behaviour of a single BGP session. The day we’ll use for this study is the 8h May 2025, and the BGP vantage point used here is an unremarkable network at the edge of the network, AS 131072.
Password hygiene drives IT professionals crazy–people forget their passwords, will not change them often enough, and choose weak ones. But are IT folks immune to these problems? What is the psychology behind passwords, and how do we do better? Karl Buhl joins Tom and Russ to talk about passwords.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-270.mp3
download
There is an interesting article from the Brookings Institute that documents four trends in infrastructure funding. The conclusions of the report surprised me and I suspect they will surprise others.
And when details do emerge, they usually involve a retraction. IBM laid off 8,000 workers in 2023, and then hired them back in May 2025. In 2024, a top headline for Klarna was “Klarna’s AI Assistant Is Doing The Job Of 700 Workers” but a year later it was “Klarna Reverses AI-Only Customer Support Strategy.”
I would like to look at the ways in which the operators of the number Resource Public Key Infrastructure (RPKI) have deployed this infrastructure in a way that maximises its available and performance and hardens it against potential service interruptions, or in other words, an examination of the resilience of the RPKI infrastructure.
OFC 2025 made one thing clear: The transition to Co-Packaged Optics (CPO) switches in data centres is inevitable, driven primarily by the power savings they offer.
I’d like to look at that spike in the total route count that occurred on the 1st May in further detail. Between 16:00 UTC on the 1st May and 18:00 UTC on the same day, the routing table grew by some 4,500 routes.
Note to readers: I’m merging the worth reading and weekend reads into a “couple of times a week” worth reading. How often I post these depends on the number of articles I run across, but I’ll try to keep it to around five articles per post
I have been consistently skeptical of claims that LLMs are intelligent in any meaningful sense of the word. It is undeniably remarkable that LLMs can generate coherent conversations and articulate answers to almost any question.
For decades, Communist China’s spies, hackers and businessmen have feasted on the forced transfer of technology from vulnerable US corporate enterprises drawn to the vast Chinese market. Little has been accomplished to reduce this massive theft of intellectual property. US businesses seem to have resigned themselves to such unfair practices as the price of doing business in China.
His technical work and evangelism have improved the Internet, and I will give some examples of his contributions to the Internet community and users, but I am sad because he was a good person—idealistic, unselfish, open, and funny.
To build a data-driven story, we must use a basic narrative model. Various models exist in the literature, such as the Data-Information-Knowledge-Wisdom (DIKW) pyramid4, or other models taken from cinema.
But lurking beneath the surface is a growing threat that does not involve human credentials at all, as we witness the exponential growth of Non-Human Identities (NHIs).
Yes, we took an (unintentional) three-week break for medical reasons … but we’re back with a new episode.
What is Web 3.0, and how is it different from Web 2.0? What about XR, AI, and Quantum, and their relationship to Web 3.0? Jamie Schwartz joins Tom Ammon and Russ White to try to get to a solid definition of what Web 3.0 and how it impacts the future of the Internet.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-269.mp3download
One of the “great fears” advancing AI unlocks is that most of our jobs can, and will, be replaced by various forms of AI. Join us on this episode of the Hedge as Jonathan Mast at White Beard Strategies, Tom Ammon, and Russ White discuss whether we are likely to see a net loss, gain, or wash in jobs as companies deploy LLMS, and other potential up- and down-sides.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-268.mp3
download
Solving technology problems often involves breaking a problem into multiple smaller problems, build interaction surfaces between the pieces, and glue the pieces back into a larger system. We also know every technology problem is actually a people problem–whether in the past, the present, or the future.
Given these two points, can we say something like: “If technology and people problems are interchangeable, we should be able to solve people problems the way we solve technology problems–via modularization?”
Join us as Tom, Eyvonne, and Russ discuss how this might–or might not–apply to the real world. The second trend we’re discussing on this episode of the Hedge is the apparent movement towards government telling data center operators to “bring your own power.”
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-267.mp3download
When most people think of segment routing (SR), they think of SRv6–using IPv6 addresses as segment IDs, and breaking the least significant /64 to create microsids for service differentiation. This is not, however, the only way to implement and deploy SR. The alternative is SR using MPLS labels, or SR/MPLS. Hemant Sharma joins Tom Ammon and Russ White to discuss SR/MPLS, why operators might choose MPLS over IPv6 SIDs, and other topics related to SR/MPLS.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-266.mp3download
You can find Hermant’s recent book on SR/MPLS here.
Out of band management networks were once more common than they are today. Should we go back to building out of band management networks? Should out of band management networks be virtual or physical? How can we sell out of band management networks to the folks paying the bills? Daryll Swer joins Tom Ammon and Russ White to discuss the importance of OOB management.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-265.mp3download
On this episode of the Hedge, Eyvonne, Tom, and Russ talk about topics near and dear to every network engineer’s heart–documentation, legacy, and tech debt. What should our philosophy of documentation be? What are legacy, end of life, and tech debt, really?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-264.mp3download
How do Non-Fungible Tokens, or NFTs, impact value and the future of all things digital? How are they different from–and similar to–blockchain? Jaime Schwarz joins Russ White and Tom Ammon to talk about what NFTs are, how they work, and how they might impact the future.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-263.mp3
download
Many providers count on detection in the global routing table to discover and counter BGP route hijacks. What if there were a kind of BGP hijack that cannot be detected using current mechanisms? Henry Birge-Lee joins Tom Ammon and Russ White to discuss a kind of stealthy BGP attack that avoids normal detection, and how we can resolve these attacks.
To find out more, check this RIPE video.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-262.mp3
downloa
In the United States, the National Telecommunications and Infrastructure Administration manages spectrum and researches the current state of Internet connectivity for policy makers. Henning Schulzrinne joins Tom and Russ to discuss the role of the NTIA, spectrum management, and broadband management.
You can read the NTIA’s reports here.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-261.mp3
download
Trends in the global BGP table–the Default Free Zone (DFZ) table–can tell us a lot about the state of the global Internet. Is the Internet growing? Is IPv6 growing, or are we still in a world of “all things IPv4?” Geoff Huston joins Tom Ammon and Russ White to review the state of the routing table from 2024.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-260.mp3
download
We often try to “institutionalize” things that work into repeatable processes—and most of the time, it doesn’t work. The process ends up becoming unwieldy, eventually failing to prevent failures and stifling innovation. How can we get out of this rut? Differentiating between architecture and process. Far too many IT shops try to replace architecture with process. Our second topic for this episode is the destructive lies of the tool trope. Tools are not “neutral,” they impact the way we think and work. A primary example of a tool that can often reshape our thinking and doing in very negative ways is … the process.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-259.mp3download
We often think of network automation as a configuration tool, but automation can also be used for one-off, integration, and even continuous testing. Dan Wade joins Tom Ammon and Russ White to talk about pyATS and the concept of automated testing. To find out more about pyATS, check here.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-258.mp3download
Every recruiter and hiring manager wants people with five years of experience, but you cannot get experience without being hired into a position. How can you break this conundrum? Daniel Dib joins Tom and Russ to talk about how folks just coming into IT, or even those with lots of experience who are trying to shift their focus, can gain experience.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-257.mp3download
Richard Wexelblat published an article in 1980 titled: “The consequences of one’s first programming language.” We’ve all seen C code written like Python, or Python code written like C, so it’s obvious a coder’s first language has a long lasting effect on their style. What about network engineers? Are there times and places where the first of anything a network engineers encounters has a long lasting impact on the way they think and work? In this roundtable, Tom, Eyvonne, and Russ consider different ways this might apply to network engineering.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-256.mp3download
RADIUS is one of those protocols we tend to forget about because it is ubiquitous–but authentication protocols are very large attack surfaces network engineers should pay more attention to. Alan DeKok joins Tom Ammon and Russ White to discuss the RADIUS protocol.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-245.mp3download
Instead, Broadcom is now experimenting with co-packaging the optics directly into the GPUs themselves.
With K-12 schools back in session across the nation, millions of students are adjusting to a new learning environment — a cellphone-free classroom or, in some cases, a phone-free school day.
Being at the core of the Internet places the DNS under a lot of pressure. New forms of DNS abuse emerge each year, disputes over domain names persist, and all the while, the Internet just keeps getting bigger.
The censorship war has hit a flashpoint. Late last month, Brazil banned Elon Musk’s social media site, X, after Musk refused a government order to suppress seven dissident accounts.
This raises a question. If someone is situated in South America and wants to access youtu.be, is their performance going to be impacted (assuming he has to do the entire recursive lookup with no cache)?
ODA focuses on identifying macroscopic Internet outages, such as outages that affect a significant portion of the population within either a geographic region or an Autonomous System (AS).
For practitioners, this study provides a rich set of criteria that can be used for evaluating their projects, as well as strong evidence of the importance of considering not only project execution, but also post-project outcomes and impacts in the evaluation.
As if we didn’t have a long enough list of problems to worry about, Lumen researchers at its Black Lotus Labs recently released a blog that said that it knows of three U.S. ISPs and one in India was hacked this summer.
While the usage of internationalized domain names (IDNs) has allowed organizations the world over to enter the global market using their native-language domain names, it can also enable cyber attackers to craft look-alikes of legitimate domains they wish to spoof.
In Texas, for example, the chatbot only consumes an estimated 235 milliliters needed to generate one 100-word email. That same email drafted in Washington, on the other hand, would require 1,408 milliliters (nearly a liter and a half) per email.
Fiber splicing is joining two optical fibers to create a continuous, low-loss, and highly efficient optical path.
Efforts to curb illegal online content through domain shutdowns are proving ineffective and carry significant risks, according to a new report by eco and its topDNS initiative.
The majority of open source project maintainers are not being paid for their work, spend three times as much time on security than they did three years ago, and have become less trusting of contributors following the xz backdoor, according to open source package security firm Tidelift.
What are the requirements for running AI workloads over a data center fabric? Why is InfiniBand so popular for building AI networks? What about Ethernet for AI? Jeff Tantsura joins Tom Ammon and Russ White to discuss networks for AI workloads.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-244.mp3download
The cellular network world is similar enough to the IP networking world to feel familiar, but different enough to require learning new terms and ideas. Tom Nadeau joins Tom Ammon and Russ White to discuss one element of this networking world, the RAN network, and the current move towards open source and white box disaggregated solutions.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-243.mp3download
A federal judge struck down a Biden administration rule on Tuesday that banned employers from using noncompete agreements, which would have affected the contracts of millions of Americans.
The Open Compute Project, the org best known for offering designs for hyperscale hardware, has rounded up AWS, Google, Meta, and Microsoft to help it test concrete.
Recent trends show that ransomware attacks continue to grow more advanced and persistent.
When you are designing applications that run across the scale of an entire datacenter and that are comprised of hundreds to thousands of microservices running on countless individual servers and that have to be called within a matter of microseconds to give the illusion of a monolithic application, building fully connected, high bi-section bandwidth Clos networks is a must
The National Institute of Standards and Technology (NIST) just released three finalized standards for post-quantum cryptography (PQC) covering public key encapsulation and two forms of digital signatures. In progress since 2016, this achievement represents a major milestone towards standards development that will keep information on the Internet secure and confidential for many years to come.
Linearity is one of the greatest success stories in mathematics. According to Encyclopedia Britannica, “Unlike other parts of mathematics that are frequently invigorated by new ideas and unsolved problems, linear algebra is very well understood.”
The Turing test could be useful for checking whether a customer service chatbot, for instance, is interacting with people in a way that those people are comfortable with, demonstrating what Jones calls a flexible social intelligence. Whether it can identify more general intelligence, however, is difficult to say.
But in at least some situations, the Supreme Court held this spring in a case called Lindke v. Freed,a it is illegal to block other users. If you are a government official, and you are using social media as part of your job duties, they may have a First Amendment right against being blocked
The recent emergence of generative artificial intelligence and the arrival of assistive agents based on this technology have the potential to offer further assistance to searchers, especially those engaged in complex tasks.
Design and engineering teams increasingly are turning to both classical AI and generative AI to rethink, reinvent, and remake the modern microchip.
In a groundbreaking development for quantum communication, researchers at Qunnect Inc. have successfully achieved the automated distribution of polarization-entangled photons over New York City’s existing fiber network.
The internet is currently controlled through searching, and if Google single-handedly dominates the means through which searching works, then Google effectively controls the internet.
In the early days of computer programming, some thought there was a difference between a coder and a programmer. Did this division ever really exist, and are there similar divisions in network engineering?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-242.mp3download
Microsoft on Thursday disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).
Cybersecurity researchers have discovered multiple critical flaws in Amazon Web Services (AWS) offerings that, if successfully exploited, could result in serious consequences.
As many as 10 security flaws have been uncovered in Google’s Quick Share data transfer utility for Android and Windows that could be assembled to trigger remote code execution (RCE) chain on systems that have the software installed.
SiFive has announced the launch of its latest core for datacenters, the P870-D, and claims it has a leg up on Arm’s Neoverse N2 in density for AI.
Unstoppable Domains (UD), a provider of Web3 domain names and digital identities, has been officially accredited by the Internet Corporation for Assigned Names and Numbers (ICANN).
CENTR, the association overseeing European country code top-level domain (ccTLD) registries, has announced the public release of its Domain Crawler Project code.
Remote SIM provisioning (RSP) for consumer devices is the protocol specified by the GSM Association for downloading SIM profiles into a secure element in a mobile device. The process is commonly known as eSIM, and it is expected to replace removable SIM cards.
The WhoisXML API research team analyzed more than 7.3 million domains registered between 1 and 31 July 2024 in this post to identify five of the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.
Unit 42 monitors ransomware and extortion leak sites closely to keep tabs on threat activity. We reviewed compromise announcements from 53 dedicated leak sites in the first half of 2024 and found 1,762 new posts.
Cybersecurity researchers have disclosed a security flaw impacting Microsoft Azure Kubernetes Services that, if successfully exploited, could allow an attacker to escalate their privileges and access credentials for services used by the cluster.
To illustrate the complexity and severity of modern application attacks, let’s examine an attack against the infamous Log4Shell vulnerability (CVE-2021-44228) that sent shockwaves through the cybersecurity world in late 2021
When it comes to breach disclosures, today’s chief information security officers (CISOs) are struggling with an especially turbulent regulatory environment.
Data centers are part of the vital infrastructure behind consumer-facing services, and they now find themselves in the crosshairs. By weaponizing permitting and zoning laws, emissions and electricity regulations, and tax hikes, policymakers aim to sabotage operations altogether.
Inspired by recent presentations and discussions around Tetragon, we picked out the top security observability use cases – and what we find are extensive use cases deep across the security application landscape.
Over the past few years, TV makers have seen rising financial success from TV operating systems that can show viewers ads and analyze their responses.
When Starlink first went into service we heard a lot of stories about how its Internet service was slow and unreliable. We’re a few years into Starlink launching satellites–how is Starlink holding up? Is service improving? Geoff Huston joins Tom, Eyvonne, and Russ to look into Starlink’s performance today.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-241.mp3download
I’ve been working on new material over at Rule 11 Academy. This month’s posts are:
Many network operators think the idea of building rather than buying is something that’s out of reach–but is it? Join Steve Dodd, Eyvonne, Tom, and Russ as we discuss the positive and negative aspects of build versus buy, what operators get wrong, and what operators don’t often expect.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-240.mp3dlownload
Beware of Internet FORCES aiming to change your mind or direct your decisions! That acronym, coined by behavioral scientist Patrick Fagan, helps people know when they’re being “nudged.”
Enter your name into an internet search engine and the first few results will probably include detailed profiles of you compiled by “people-search” websites with names like Intelius, PeopleFinders, and Spokeo.
Following the July 19 outages caused by a bad update, the cybersecurity firm faces shareholder lawsuits and pressure to pay damages for at least one major customer, Delta Airlines. Will software liability follow?
Since 1998 — the last year Congress passed a major law to reform the tech industry and protect children in the virtual space — a lot has changed.
According to a damning report from 404 Media, backed with internal Slack chats, emails, and documents obtained by the outlet, Nvidia helped itself to “a human lifetime visual experience worth of training data per day,” Ming-Yu Liu, vice president of Research at Nvidia and a Cosmos project leader, admitted in a May email.
It has been an enduring fascination to see how we could use packet networking in the context of digital communications in space.
At a recent conference I attended, a speaker referenced media ecologist Neil Postman and his “rules” for evaluating the pros and cons of any given technological development.
In the 18th century, Wolfgang von Kempelen’s victorious mechanical Turk (1770) amazed the world, see Figs.1-4. However, there was a person hidden inside.
LibreQoS is an open source project and the subject of a popular recent APNIC Academy webinar. Responding to feedback given at the webinar, this post will look at the features of LibreQoS.
Huawei Cloud has developed a network monitoring tool that, when used in production on three of its own regions, was able to observe more of its infrastructure than existing tools, and revealed issues that previously evaded human efforts.
Decoupling authorization from your main application code makes authorization more scalable, easier to maintain, and simpler to integrate with your components. However, these benefits are difficult to realize if you don’t consciously plan for them within your authorization implementation.
In this episode of PING, Casper Schutijser and Ralph Koning from SIDN Labs in the Netherlands discuss their post-quantum testbed project.
There are (at least) three different aspects of AI in network engineering: network design to support AI, AI for development, and AI for operations. J.P. Vassuer joins Tom Ammon and Russ White to discuss AI for understanding and operating networks. What are the possibilities? What are the pitfalls? What can we expect to see?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-239.mp3download
Network observability tools provide information on the health and behavior of applications, offer insights into end-user experience, and detect anomalies that are indicative of security incidents.
Maestro is a general-purpose, horizontally scalable workflow orchestrator designed to manage large-scale workflows such as data pipelines and machine learning model training pipelines.
It might be time to get the pens and notebooks back out and shut off the keyboard for a while. Just pretend you’re back in the first grade and don’t have a minicomputer in your back pocket.
Intel has finally provided an update on instability issues on 13th-gen and 14th-gen CPUs. An update posted by Thomas Hannaford, Intel’s communications manager, pins the instability on an error in the microcode that requests incorrect voltage numbers, leading to instability in the processor.
Separation agreements Meta gave to employees during mass 2022 layoffs are illegal, a US judge has decided, and the reasoning could have implications far beyond Zuckercorp.
In 1940, thirteen percent of the U.S. population lived in suburbs. In 2010, it was half. An analysis by demographer Wendell Cox of population trends during the 2010s showed that 92 percent of all growth in major metropolitan areas was in the suburbs and exurbs ラ a trend that well preceded the pandemic.
Searchable Encryption has long been a mystery. An oxymoron. An unattainable dream of cybersecurity professionals everywhere.
Two US senators have urged the FTC to probe and potentially prosecute three automakers that allegedly unlawfully sold motorists’ personal data for pennies.
As the COVID-19 pandemic came to an end, a number of large companies pushed for their workers to return to the office five days a week — a policy that prompted many employees to “quiet quit” in protest.
At what was billed as a “fireside chat” at Tel Aviv University in June 2023, the very first question from the audience posed to OpenAI CEO Sam Altman and chief scientist Ilya Sutskever was, “Could open source LLMs (large language models) potentially match GPT-4’s abilities without additional technical advances, or is there a ‘secret sauce’ in GPT-4 unknown to the world that sets it apart from the other models?”
The blame game doesn’t stop there. One link in this chain of infamy hasn’t received the attention it deserves – but this link took what should have been a small hiccup and turned it into a global meltdown.
Now it seems that AI itself might be our best defense against AI fakery after an algorithm has identified telltale markers of AI videos with over 98% accuracy.
Rolls-Royce has cleared a key hurdle in the race to build Britain’s first mini-nuclear power plant as competition across Europe ramps up.
The massive failure resulting from a failed update to 8.5 million Windows hosts by Crowdstrike will live in Internet history for years to come. The failure will be studied by engineering teams and college classes to understand what went wrong and how we can stop this from happening in the future. Derick Winkworth (@cloudtoad), Eyvonne Sharp, Tom Ammon, and Russ White hang out at the hedge to talk about what happened and lessons learned from a network engineering perspective.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-238.mp3
download
Looking at changes in the market in the last ten years, it certainly seems like vendors work less toward innovation and more towards locking customers in to revenue streams. Chris Emerick, Dave Taht, and Russ White decided it’s time to talk about. What’s wrong with vendors? And since everything can’t be wrong with vendors, where are they doing the right thing?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-237.mp3
download
Recent events involving CrowdStrike’s Falcon security software have underscored a critical lesson across the industry: the importance of having a robust, secure release process.
My analysis of the event has a lot of similarities with my reflections on the Optus outage last year, the incident underscores the critical issue of resilience in IT infrastructure, particularly in systems that lack diversity.
But recovery is just the beginning. What’s sure to follow is a barrage of regulatory oversight, hard feelings among the IT community, and a tough reminder that even a small slip-up in a software update can have catastrophic global consequences.
Over the years, there has been a lot of discussion on if VLAN 1 in Cisco switches is special or not. Does it have any characteristics that other VLANs donメt?
Are you considering the switch from network engineer to cloud engineer? This post wo’t teach you everything needed to become a cloud expert, but hopefully, it will create a level of comfort and familiarity such that you can start your journey to the cloud from here.
The creation of voluntary standards is an idea that may seem easier than imposing regulations. But devising voluntary standards presents unique challenges, different from those which arise in devising standards which can be imposed on developers. The AI community should take note.
The landscape for digital rights has evolved rapidly over the last 15 years, and will only continue to shift and stratify more quickly in the years ahead. Iメll start with some horizon-scanning, though it is far from comprehensive.
Our research team analyzed more than 21.5 million domains registered between 1 April and 30 June 2024, as seen in the Newly Registered Domains (NRDs) Data Feed. We detected that the number of NRDs slightly increased compared with the previous quarter, at 2.6%.
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could be exploited to trigger a denial-of-service (DoS) condition.
Analysys Mason, an industry consulting firm in the U.K. recently wrote an interesting report looking at long-term capex spending for the telecom industry. The prediction looks at both broadband and wireless spending.
Eyvonne and Russ catch up with Greg Ferro one last time to talk about the permissionless Internet–a thing of the past–vendor lock in, and many other random topics on this episode of the Hedge. Greg–here’s to a grand time in the future. We’ll miss you.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-236.mp3download
On the other hand, these same minimal overheads imply that DNS over UDP cannot perform prompt detection of packet loss and cannot efficiently defend itself against various approaches to tampering with the DNS, such as source address spoofing, payload alteration and third-party packet injection. Perhaps most importantly, the way UDP handles large payloads is a problem.
User interface (UI) design is currently experiencing a transition from traditional graphical user interfaces (GUIs) to systems designed to recognize a personメs gestures and movements.
The U.S. Federal Trade Commission (FTC), along with two other international consumer protection networks, announced on Thursday the results of a study into the use of “dark patterns” — or manipulative design techniques — that can put users’ privacy at risk or push them to buy products or services or take other actions they otherwise wouldn’t have.
One of the most concerning aspects of social media is that much of its influence evades our notice. We don’t realize that we’re being influenced, or shaped to think a certain way, or view the world through a specific lens.
Chinese automobile conglomerate Geely has made significant strides since I last wrote about their Geesat LEO constellation for mobile vehicle connectivity.
Retail banking institutions in Singapore have three months to phase out the use of one-time passwords (OTPs) for authentication purposes when signing into online accounts to mitigate the risk of phishing attacks.
A threat actor that was previously observed using an open-source network mapping tool has greatly expanded their operations to infect over 1,500 victims.
With the first Zen 5 CPUs and SoCs set to ship later this month, AMD offered a closer look at the architectural improvements underpinning the platform’s 16 percent uplift in instructions per clock (IPC) during its Tech Day event in LA last week.
At least a dozen organizations with domain names at domain registrar Squarespace saw their websites hijacked last week.
Everybody knows that companies, particularly hyperscalers and cloud builders but now increasingly enterprises hoping to leverage generative AI, are spending giant round bales of money on AI accelerators and related chips to create AI training and inference clusters.
Alphabet’s cloud computing division, Google Cloud, tried to sustain the European Union’s inquiry into Microsoft’s antitrust practices in the cloud computing sector by offering complainant Cloud Infrastructure Services Providers in Europe (CISPE) a package worth €470 million ($511 million), Bloomberg reported.
Just one problem: observability tools wonメt help us solve any of the problems above. Even real-user monitoring (RUM) wonメt give us the information we need.
Join us as Tom, Eyvonne, and Russ hang out for another roundtable. We start the show talking about Tom’s plant (is it real or … ??). What does copyright have to do with Internet Service Providers? Should the two topics be related at all? What can the IETF do about Internet centralization?
Thanks for listening—and please reach out if you have a topic you’d like to hear about, or a guest you’d like to hear.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-235.mp3download
The gang’s time from initial access to draining data out of a Veeam server is shockingly fast; after which the attackers went on to deploy actual ransomware in less than a day.
A critical security issue has been disclosed in the Exim mail transfer agent that could enable threat actors to deliver malicious attachments to target users’ inboxes.
The new fireball is the arrival of AI, its widespread acceptance and adoption, and the view that it is now a competitive imperative.
As a follow-up to the post yesterday on native VLANs, there was a question on what would happen to 802.1Q-tagged frames traversing an unmanaged switch.
State-controlled media on Tuesday covered the proceedings of the third China IPv6 Innovation and Development Conference, at which officials revealed that as of May 2024 the Middle Kingdom was home to 794 million users of the protocol, and that 64.56 percent of mobile traffic – plus 21.21 percent of fixed network traffic – is carried on networks that employ it.
In fact, since 2017, Google’s environmental reports show that the company’s electricity use, CO2 emissions, and carbon intensity have soared.
Using DevSecOps helps ensure the right level of security throughout both the development phase and the entire lifespan of the software.
While these tools and studies have merit, there is a need to understand what the developers want instead of what we think they want.
ORCA Computing engineers and builds quantum computers using the photonics quantum modality (i.e. photonic, or light based qubits), which operate at room temperature.
The power efficiency of a server fleet, that is, how much work servers perform for the energy they use, is influenced by multiple factors.
We often hear about how there simply aren’t enough tech people out there–especially in cybersecurity. Rex Booth, CISO at Sailpoint, joins Tom and Russ to discuss the problem, and why we should be looking in unconventional places to find the right people.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-234.mp3download
Data centers turn large amounts of electricity into heat. Is it possible to recover even some part of this heat rather than throwing it off into the local environment? David Krebs of masterresource.org brings his vast experience with using heat from engines to bear on the problem to propose solutions.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-233.mp3download
Anybody not involved in the telephone business will probably be surprised to find that the old TDM telephone networks are still very much alive and in place.
Intel has demonstrated an optical chiplet co-packaged with a CPU capable of supporting 4 Tbps data links to feed the increasing datacenter bandwidth requirements of AI and high performance computing (HPC) applications.
My one-liner for The AI Delusion is that the real danger today is not that computers are smarter than us but that we think computers are smarter than us and consequently trust them to make decisions they should not be trusted to make.
If the Senate passes an expansion of the Foreign Intelligence Surveillance Act, any Americanメs international communications could become an open book.
Anybody who builds fiber networks can describe the litany of state and local regulations involved in constructing fiber. Following are the primary kinds of such regulations ヨ and there are others in some places.
OpenSSH maintainers have released security updates to contain a critical security flaw that could result in unauthenticated remote code execution with root privileges in glibc-based Linux systems.
This only works for so long. Software can keep getting bigger and slower only for as long as computers keep getting faster, and the rate of improvement there has fallen off a cliff and shows no sign of recovery.
While data-driven insights propelled tech giants to unprecedented heights, they also led to privacy debacles. As a reaction, the last decade witnessed the emergence and strengthening of data protection regulations such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in California.
It is easy to overlook the role lithography plays in developing digital technologies. Every year, new and more advanced integrated circuits appear, pushing computing capabilities to more advanced levels.
While Broadcom claimed that many users would see their costs fall because of the changes in licensing, it was simultaneously telling its shareholders that the changes were expected to lead to double-digit revenue growth for its VMware portfolio throughout 2024.
Added 11 new lessons in June:
If you’ve ever wondered what the process of creating and publishing a book is like, listen in as Aninda joins Tom and Russ to discuss the trials and rewards of publishing his first book, Deploying Juniper Data Centers with EVPN VXLAN.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-232.mp3
download
Often the scourge of tech execs in the US, Britain’s competition regulator has a new potential target in its sights: HPE’s proposed $14 billion purchase of Juniper Networks.
Normally, with a signature scheme, you have the public key and want to know whether a given signature is valid. But what if we instead have a message and a signature, assume the signature is valid, and want to know which public key signed it?
Comparing social media with tobacco use is bizarre. Smoking cigarettes is a known danger, whereas social media is a generally positive development that has troubling side effects for some young people who spend too much time on the platforms.
The Biden administration today banned the sale of Kaspersky Lab products and services in the United States, declaring the Russian biz a national security risk.
Meta has identified another reason AI might produce rubbish output: Hardware faults that corrupt data.
During the 59th BEREC plenary meeting (6 June 2024), the Board of Regulators approved the Draft BEREC Report on the IP Interconnection Ecosystem (BoR (24) 93) for public consultation.
Is there any company out there who has hurt young people more than Mark Zuckerberg’s gargantuan Meta empire?
At the recent Internet Corporation for Assigned Names and Numbers (ICANN) 80 Policy Forum meeting, one notable takeaway was its close focus on questions around the stability and security of the technical layer of the Internet: the growing risks which assail it, and potential ways to address these through governance.
From a researcher’s perspective, SpaceX — Starlink’s operators — are quite opaque, however. There is little engagement with the research community, and official pronouncements often lack detail — they’re clearly not the kind of company that takes people on factory tours to proudly show off how they make and run things.
Large language models can be made 50 times more energy efficient with alternative math and custom hardware, claim researchers at University of California Santa Cruz.
Talking at Bernstein’s 40th Annual Strategic Decision Conference late last week, HP boss Enrique Lores acknowledged the pressures facing the print division, saying the number of printed pages has dropped by a fifth.
The petition makes three general arguments for issuing a pause on net neutrality, the first of which is that the FCC may not have the authority to reinstate net neutrality at all.
Each time someone interacts with a large language model (LLM), there is an energy cost in running the model for inference. In addition, there is an energy cost in the preparation and training of the model before it was brought to production.
On December 14, 2022, the European Parliament adopted the Directive on measures for a high common level of cybersecurity across the Union (Directive (EU) 2022/2555) hereinafter referred to as “NIS2”), which was published in the official journal on December 27, 2022
In my view, Thomas’ approach is inconsistent with the remainder of Article 28 and would not achieve the goals of NIS2 to improve cybersecurity across the EU member states.
This kind of marketing, historically, is quite effective – bigger numbers are easier for us customers to understand. But, as is the case with clock speeds and cores, it’s never as simple as the marketers make it sound.
And now that the OEMs are finally able to get some GPU allocations, they are beginning to drive sales, but they do not seem to be able to make money on this ridiculously expensive iron. Which is, well, ironic.
Dozens of policing agencies are currently using cell-site simulators (CSS) by Jacobs Technology and its Engineering Integration Group (EIG), according to newly-available documents on how that company provides CSS capabilities to local law enforcement.
TL;DR: AES-GCM is great, as long as every nonce (mnemonic: number used once) is truly unique. Once a nonce is reused, AES-GCM completely falls apart.
Topology Aware Routing is a feature of Kubernetes that prevents cluster traffic within one availability zone from crossing to another availability zone.
Our recent discovery in router firmware exposes a security flaw in routers’ Network Address Translation (NAT) mapping handling, which can be exploited by attackers to bypass TCP’s built-in randomization.
In a significant escalation against piracy, a French court has ordered Google, Cloudflare, and Cisco to tamper with their DNS resolvers to block access to approximately 117 pirate sports streaming domains.
We often think of decoupling, or modularization in network engineering speak, as a primary tool for scaling networks, but it also one of the best tools network engineers have to increase security. In this roundtable, Eyvonne, Tom, and Russ discuss an article by Bruce Schneier on decoupling, and how it applies to networking engineering.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-231.mp3
download
This Friday at 1pm ET, Bruce McDougall and I are teaching a live class on using Containerlab to build and automate network labs. From the course description:
This course will guide learners through the tools and techniques to build virtual labs either locally or on common cloud services, so you can become more proficient at understanding, designing, monitoring, and troubleshooting networks. The course begins with obtaining and starting the basic tools required to build and test network labs using open-source and freely available tools. The instructors will build a variety of network topologies, including data center and campus, to help learners understand how to test in different environments.
Register here.
You will probably be laid off at least once in your career–we no longer live a world of “permanent positions,” or even a world where people are in complete control of their “work destiny.” It’s important, then, to prepare to be laid off, made redundant, or impacted by a RIF, today. Mike Bushong joins Eyvonne Sharp, Tom Ammon, and Russ White in a wide-ranging discussion about preparing to be laid off.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-230.mp3download
Two new videos over at Rule 11 Academy:
Single FE Inbound Path
Single FE Outbound Path
Remember to use FIRSTSIX for your first six months for free.
The US Securities and Exchange Commission (SEC) wants to clarify guidelines for public companies regarding the disclosure of ransomware and other cybersecurity incidents.
Technical report 69, or TR-069, which defines how people’s broadband routers and other customer-premises equipment can be remotely provisioned and managed by ISPs automatically, is turning 20 years old.
Google and many other organizations, such as NIST, IETF, and NSA, believe that migrating to post-quantum cryptography is important due to the large risk posed by a cryptographically-relevant quantum computer (CRQC).
IPng’s network is built up in two main layers, (1) an MPLS transport layer, which is disconnected from the Internet, and (2) a VPP overlay, which carries the Internet.
Elon Musk doesn’t want you to share links from Substack, the blogging and newsletter platform that has grown in popularity over the last two years and serves as the primary mode of expression for independent Internet writers.
Quantum computers are probably coming, though we don’t know when—and when they arrive, they will, most likely, be able to break our standard public-key cryptography algorithms.
Domain name monitoring—that is, the detection of domains with names containing a brand-term (or other string) of interest—is a very well-established element of brand protection services.
To tackle these challenges, we developed ROuting SEcurity Tool (ROSE-T), the first open source tool to verify MANRS compliance automatically.
Today’s blog talks about a practice that doesn’t get discussed very often, which is the warehousing of spectrum. Warehousing is the practice where carriers sit on spectrum without using it or make only a minimal technical deployment to protect a spectrum license without actually using the spectrum as intended.
In this blog, we will analyze the modern practice of Phishing “Tests” as a cybersecurity control as it relates to industry-standard fire protection practices.
Recent research showed that 60% of participants fell victim to artificial intelligence (AI)-automated phishing, which is comparable to the success rates of non-AI-phishing messages created by human experts.
From a high level, optical interconnects perform the task their name implies: they deliver data from one place to another while keeping errors from creeping in during transmission. Another important task, however, is enabling data center operators to scale quickly and reliably.
This blog will provide an understanding of what AI jailbreaks are, why generative AI is susceptible to them, and how you can mitigate the risks and harms.
Experts on artificial intelligence raised concerns about the implications of AI’s rapid growth at a panel discussion in Washington, D.C. Tuesday.
What is QUIC? Where did it come from? Why has it been successfully deployed where so many other protocols have either taken forever or flat-out failed? George Michaelson (of APNIC fame) joins Tom Ammon and Russ White on this episode of the Hedge to (quickly) talk about QUIC.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-229.mp3download
New material at Rule 11 Academy this week:
Understanding Intra-AS BGP
Suboptimal BGP Route Reflection Lab
I’ve done a good bit of BGP to this point; I’m probably going to work on link state or some other part of the outline next week. I’m trying to make certain everyone who signs up for the first time gets the first six months for free; the membership plugin is being a bit squirrely, so you might see accounts expired, etc. I’m fixing these as I see them.
In this episode of the RIPE Labs podcast, three Internet pioneers talk about how they helped grow the Internet out of its early infancy, back when its purpose – and much of the excitement around its development – lay in the promise of connecting researchers from around the world.
Meta, parent company of Facebook and Instagram, also now is in the AI-focused processor game. The company recently unveiled the next generation of custom-made chips to help power AI-driven rankings and recommendation ads on social media platforms.
Phishing threats have reached unprecedented levels of sophistication in the past year, driven by the proliferation of generative AI tools.
In recent news, more than 13,000 subdomains of brands were hijacked for a large spam campaign that “leverages the trust associated with these domains to circulate spam and malicious phishing emails by the millions each day, cunningly using their credibility and stolen resources to slip past security measures.”
Tenable Research has discovered a critical memory corruption vulnerability dubbed Linguistic Lumberjack in Fluent Bit, a core component in the monitoring infrastructure of many cloud services.
Pew Research Center conducted the analysis to examine how often online content that once existed becomes inaccessible. One part of the study looks at a representative sample of webpages that existed over the past decade to see how many are still accessible today.
As well as making EPP easier for registrars to use, such an API would help domain registries by increasing scalability and improving performance and security.
Three teams – in Boston, in China, and the Netherlands – have simultaneously announced that they’ve figured out ways to store entangled photons without breaking the entanglement, a critical step in building quantum repeaters, and, thus, scalable quantum networks.
Microsoft has a lot more than AI riding on Copilot+ PCs. Although AI is the current buzzword of the tech industry, Microsoft’s push into a new era of PCs has just as much to do with declining PC sales over the past several years, as well as Microsoft’s decade-long drive to get Windows on ARM working.
The IBM Power Virtual Server Private Cloud – announced Tuesday with little fanfare – is based on the IBM Power Virtual Servers Big Blue rents out in a manner that will be familiar to users of IaaS services.
We have a long-standing policy that when you redact text, the only way to do it securely is to use black bars. Sometimes, people like to be clever and try some other redaction techniques like blurring, swirling, or pixelation. But this is a mistake.
The relationship between shift length, fatigue and human error is well documented, but less clear is how the data center industry can define shifts that help minimize human error. The recommended best practices for other industries do not always translate into the data center world, where 24/7 service availability is the standard.
Miscommunication between techies and business leaders are often caused by misunderstanding. Listen in as Eyvonne, Tom, and Russ discuss these misunderstandings and how we can address them.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-228.mp3
download
One reason the OSI model isnメt all that useful anymore is because it assumes things about networks that are no longer true, such as the existence of a clear set of protocols neatly layered one atop another. We just donメt build networks this way any longer.
You’ve just finished building a 1,000 router fabric using a proper underlay and overlay. You’ve thought of everything, including doing it all with a single SKU, carefully choosing transceivers, using only the best optical cables, and running all the software through a rigorous testing cycle. Time to relax? Perhaps—or perhaps not.
Three new posts this week:
coupon code for first six months for free: BEAG2DRUP0TORNSKUT
The European Union’s new Digital Markets Act (DMA) is a complex, many-legged beast, but at root, it is a regulation that aims to make it easier for the public to control the technology they use and rely on.
When optimizing the write performance of GreptimeDB v0.7, we discovered through flame graphs that the CPU time spent parsing Prometheus write requests accounted for about 12% of the total.
We think that waferscale computing is an interesting and even an inevitable concept for certain kinds of compute and memory. But inevitably, the work you need to do goes beyond what a single wafer’s worth of cores can deliver, and then you have the same old network issues.
Evidence is mounting that tech companies’ policies demanding staff return to the office are only serving to drive out the talent that became accustomed to remote work.
ZTDNS integrates the Windows DNS client and the Windows Filtering Platform (WFP) to enable this domain-name-based lockdown. First, Windows is provisioned with a set of DoH or DoT capable Protective DNS servers; these are expected to only resolve allowed domain names.
The use of Machine Learning and Deep Learning models allows us to understand the intention of the message, who is sending it, and if the sender is pretending to be someone they are not. It also allows us to learn what a legitimate message looks like and identify the parts of an email that indicate malicious intent, making it easier to predict those markers in the future.
That said, I have been running e-mail servers since well before Google existed as a company. I started off at M.C.G.V. Stack, the computer club of the University of Eindhoven, in 1995.
Alas, the feds did something you wouldn’t want your government to do. The Federal Trade Commission launched an investigation into MGM — the victim of the cyberattack — and demanded that MGM, which suffered an estimated $100 million loss from the hack, provide information about the breach.
If successful in the Google and Apple cases, the result will be far more clarity on non-priced harms and a much-needed update to how we evaluate consumer welfare in the digital age, all without throwing the baby out with the bathwater.
How do you profit off intelligence once it’s been commoditized? Will the AI transition let a thousand flowers bloom, or will the returns largely flow to a few tech behemoths and their infrastructure providers?
Broadcom has introduced a new series of 400G Ethernet adapters specifically tuned for resolving network bottlenecks when moving massive amounts of data around for AI processing.
Yes, this time is different. And the key difference is Joe Biden’s EPA. On May 9, that agency published a rule in the Federal Register that, if it survives legal challenges, will force the closure of every coal-fired power plant in America and prevent the construction of new baseload gas-fired plants. If the rule survives those challenges, it will strangle AI in the crib.
The 29th of May, in 7 days, I’m teaching a four-hour webinar/class on Safari Books Online:
From technologists to business leaders, few have a “big picture” understanding of how the Internet is put together. Often this is because the Internet is composed of so many different systems, each of which is deeply complex, so it is easy to specialize in “one part of the Internet,” and it is hard to learn about the other parts without diving into many details. This class de-mystifies the overall structure and “moving parts” of the global Internet. The class begins with a user connecting to a web site, and the process of translating the name of the service the user is seeking to a logical location (a server) where the service is actually located. From there, the path of the packets between the user and the server is traced, exposing each of the different kinds of providers that carry the packet along the way.
This class isn’t just for network engineers, it’s for anyone interested in how the Internet works. You don’t need prior network engineering experience or knowledge to understand the content–so feel free to forward along to anyone you think might be interested, even managers (!) and coders.
Join me by registering here.
Europe and the United States are completely different landscapes of Internet service providers. Which provides better service for customers, and which direction should these different markets go? Luke Kehoe joins Tom Ammon, Eyvonne Sharp, and Russ White to discuss the European market specifically, and why the European market needs consolidation.
Luke’s article on this topic is here.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-227.mp3download
The FCC lawfully fined U.S. facilities-based wireless carriers nearly $200 million for selling highly intrusive location data about subscribers without their “opt-in” consent.
Geoff Huston explores the performance of the BBR and Cubic flow control algorithms on the Starlink network through comprehensive measurements.
An instruction set is a lingua franca between compilers and microarchitecture. As such, it has a lot in common with compiler intermediate languages, a subject on which Fred Chow has written an excellent overview
A new malware called Cuttlefish is targeting small office and home office (SOHO) routers with the goal of stealthily monitoring all traffic through the devices and gather authentication data from HTTP GET and POST requests.
But one need not know anything about aeronautics to understand that things are not going well for Boeing, and that the company’s approach is clearly broken. That much was made clear in a new Ars Technica piece from Eric Berger, walking readers through the race between Boeing and SpaceX to develop an astronaut capsule for space travel.
“Legal basis” requirements for data processing, justifying data processing activities and transfers, and adhering to data minimization principles began hitting organizations’ radars with the EU General Data Protection Regulation.
Given the fast-paced nature of AI evolution, we decided to circle back and see if there have been developments worth sharing since then. Eight months might seem short, but in the fast-growing world of AI, this period is an eternity.
Ransomware hit an all-time high last year, with more than 60 criminal gangs listing at least 4,500 victims – and these infections don’t show any signs of slowing.
Virtual private networking (VPN) companies market their services as a way to prevent anyone from snooping on your Internet usage. But new research suggests this is a dangerous assumption when connecting to a VPN via an untrusted network, because attackers on the same network could force a target’s traffic off of the protection provided by their VPN without triggering any alerts to the user.
But the insider history of Signal raises questions about the app’s origins and its relationship with government—in particular, with the American intelligence apparatus.
Distributed denial-of-service (DDoS) attacks continue to plague the Internet and pose a risk to the availability of critical digital systems that we increasingly depend on in our daily lives. Thijs van den Hout and his colleagues outline their contributions and lessons learned from 5 years of research on the topic of collaborative DDoS mitigation, as an improvement on the current strategies.
Cogent (CCOI) recently announced that it was offering secured notes for $206M. The unusual part is what it’s using as security: some of its IPv4 addresses and the leases on those IPv4 addresses.
Alexis Bertholf joins Tom Ammon and Russ White to discuss how we can make network engineering cool again—and to talk about how we got into network engineering.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-226.mp3download
The Academy does not replace this blog, the Hedge, etc. Instead, it’s a place for me to recreate all the training materials I’ve taught in the past, put them in one place, and adding new training material besides. It’s light right now, but I plan to post about once or twice a week.
Note this is a subscription site with paid content and two memberships–six months and yearly.
Get six months free using the coupon code BEAG2DRUP0TORNSKUT.
https://rule11.ac/
The CCNA has a long history as an important certification for network engineers. While the CCST has been created by Cisco “below” the CCNA, or as a different starting point, many network engineers begin their career with the CCNA. Join Jason Gooley, Wendell Odom, Tom, and Russ as we discuss the most recent updates to the CCNA, the way updates to the program are changing, and Jason’s and Wendell’s updated book on the CCNA.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-225.mp3download
Quantum sensing is poised to revolutionize virtually every aspect of our world. Quantum sensing’s distinctive ability to detect magnetic signatures is already aiding in navigation for countless fuel tankers worldwide, providing otherwise unachievable medical scans, and keeping all of our computer clocks in sync.
Surprisingly, most network attacks are not exceptionally sophisticated, technologically advanced, or reliant on zero-day tools that exploit edge-case vulnerabilities.
A growing number of data center operators and equipment vendors are anticipating the proliferation of direct liquid cooling systems (DLC) over the next few years. As far as projections go, Uptime Institute’s surveys agree: the industry consensus for the mainstream adoption of liquid-cooled IT converges on the latter half of the 2020s.
The recent discovery of a backdoor in XZ Utils (CVE-2024-3094), a data compression utility used by a wide array of various open-source, Linux-based computer applications, underscores the importance of open-source software security.
The IETF has had a long tradition of doing its technical work through a consensus process, taking into account the different views among IETF participants and coming to (at least rough) consensus on technical matters.
This is where Two-Factor Authentication (2FA) steps in as a powerful tool to bolster security. Let’s delve into the trends shaping the realm of 2FA and how they enhance digital security.
Global hybrid multi cloud applications (GHMAs) auto scale vertically and horizontally in response to spikes in request traffic and processing load. Auto scaling mechanisms for GHMAs are available on prem, in the public cloud, or in any combination globally.
IBM and Swiss startup LzLabs faced off in a London court on Monday in a dispute over the development of technology that allows the migration of mainframe applications to the cloud.
Zilog’s classic Z80 chip is soon to be dead, though it might not be gone forever if one open source project succeeds in its goal to clone the legendary processor.
The U.K. National Cyber Security Centre (NCSC) is calling on manufacturers of smart devices to comply with new legislation that prohibits them from using default passwords, effective April 29, 2024.
Is Open Source Software (OSS) a market failure? What does OSS add to the market that cannot be accomplished in other ways? What happened to the F (Free)? Join us for this roundtable episode of the Hedge.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-224.mp3download
Someone told me some (or many?) of the links are broken to the History of Networking recordings. I went through the S3 bucket and renamed all the files so there are no spaces (because S3 buckets don’t always work right with spaces), and then checked them all to make certain they work. Along the way I found three or four episodes that were recorded and not on the HoN page, so I added them.
Check out the corrected listing here.
I think I have one more recording that was never edited and published; I will probably put it in the Hedge stream in the next month or two just so it’s out there.
The Stanford Institute for Human-Centered Artificial Intelligence (HAI) has issued its seventh annual AI Index Report, which reports a thriving industry facing growing costs, regulations, and public concern.
At a time when no one expected progress on the U.S. federal privacy front, a new discussion draft for a comprehensive consumer privacy bill has emerged with bipartisan and bicameral support.
There is a new way for folks to track and spy on you. A recent article in the MIT Technology Review described how WiFi tracking has become a usable technology.
How would AI help produce victims? ‘Deep fake’ video technology. We previously saw, in ‘Human Impersonation AI Must be Outlawed,’ how extortion videos could target millions of individuals worldwide simultaneously every day.
A few weeks ago, I got a bit miffed reading yet another article that was too dismissive about memory safety, basically being mostly dismissive about the need for change.
Combined heat and power using waste heat recovery is a natural for AI/data centers deserves more consideration. We hope that we have lit that spark.
Larry Sanger remembers the promise of the web. He co-founded Wikipedia in 2001, with the hope that it could sustain a “free and open” Internet—a place where information, dissent, and creativity could thrive.
Everyone is in a big hurry to get the latest and greatest GPU accelerators to build generative AI platforms. Those who can’t get GPUs, or have custom devices that are better suited to their workloads than GPUs, deploy other kinds of accelerators.
To help both seasoned privacy practitioners and newcomers navigate this thicket, the IAPP has published a fully revised second edition of “Cybersecurity Law Fundamentals,” in which we distill the onslaught of laws, regulations, class-action lawsuits and enforcement actions. Here we summarize some of the trends we have noted.
Production of some models of Z80 processor – one of the chips that helped spark the personal computing boom of the 1980s – is set to end after an all-too-brief 48 years.
On the other hand, the media places less emphasis on negative news such as announcements that Amazon would abandon its cashier-less technology called “Just Walk Out,” because it wasn’t working properly.
And one of the key insights that the Meta AI research team had with the Llama family of models is that you want to optimize for the lowest cost, highest performance AI inference with any model and then deal with the inefficiencies that might result from AI training.
Listen in as Geoff Huston, Tom, and Russ discuss how the IETF, governments, and political movements interact when creating standards and guiding the future of the Internet.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-223.mp3download
Huawei has released details of how it manages its own cloud with a dynamic traffic allocation system optimized by machine learning and developed in response to surging demand for its services during the COVID-19 pandemic.
A jury has ordered Amazon Web Services to pay $525 million for infringing distributed data storage patents in a case brought by a technology outfit called Kove IO.
The BBC has just shared another video from its archives, this one showing a report about computer addicts from way back in 1983, when computers were just starting to find their way into the workplace and home.
Microsoft is currently testing a new way to showcase ads on the Windows 11 Start Menu, and it’s meant to encourage users to download more applications.
Google announced on Wednesday it will invest $1 billion in two submarine cables to create new routes between the US and Japan.
While writing about Git, I’ve noticed that a lot of folks struggle with Git’s error messages. I’ve had many years to get used to these error messages so it took me a really long time to understand why folks were confused.
If the prognosticators at IDC are correct, four years from now as 2028 is coming to a close, the service providers as a group will comprise more than two thirds of server and storage revenues for that year.
Alibaba Cloud has detailed the telemetry tool it uses to look out for glitches in customers’ virtual networks, and revealed it’s reduced the number of personnel dedicated to troubleshooting by 86 percent since developing the system.
We know Google search results are being hammered by the proliferation of AI garbage, and the web giant’s attempts to curb the growth of machine-generated drivel haven’t helped all that much.
Information and decision-making power now flowed straight to the top. Decades later when the first crop was felled, vast fortunes were made, tree by standardized tree. The clear-felled forests were replanted, with hopes of extending the boom.
Eric Chou joins Tom and Russ to talk about the importance of creating content, and the many tools and ideas you can use to get out there and publish. You’ve heard us talk about this a lot–now it’s time to get out there and publish.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-222.mp3download
This Friday, Marlon Bailey and I will be teaching a new four-hour class on coding skills for network engineers over on Safari Books Online through Pearson. From the course description:
Network engineers are increasingly expected to know how to perform basic coding, like building scripts to gather information and build or maintain an automation system. In larger organizations with full-time coders, network engineers are expected to effectively work with coders, on their own turf, to build and maintain network automation systems. All of these tasks require a basic knowledge of the structure and terminology of programming. There are a lot of courses that show you how to build your first program, or how to perform basic tasks using common programming languages—this course is different. This course will help you build a “mental map” of the software development space, gathering ideas and patterns learned across years into a simple-to-understand format. In this course you will learn data structures, program flow control, and—most importantly—how to structure software for efficiency and maintainability over the long haul.
For anyone who doesn’t know Marlon, you can find his LinkedIn profile here.
Register for the class here.
Future AMD processors could feature domain-specific accelerators – even some created by third parties, according to senior execs at the chip shop.
We tolerate such things even though we understand these practices usually harm those who willingly engage in them. Consider it one price we pay for relative freedom. But what should we do when these practices destroy the lives of innocent bystanders?
Thread hijacking attacks. They happen when someone you know has their email account compromised, and you are suddenly dropped into an existing conversation between the sender and someone else.
The first thing to note about the rumored “Stargate” system that Microsoft is planning to build to support the computational needs of its large language model partner, OpenAI, is that the people doing the talking – reportedly OpenAI chief executive officer Sam Altman – are talking about a datacenter, not a supercomputer
Now we’re going to go much deeper into the layers that relate to the PHY, which is PCS, PMA, and Autonegotiation. First though, let’s review the objectives of 1000BASE-T.
macOS has been gaining the unwanted attention of more and more backdoor operators since late 2023. In February 2024, Bitdefender uncovered RustDoor, which was written in Rust and possibly has ties to the operators of a Windows ransomware.
The PCIe 7.0 spec is on track for release next year and, for many AI chip peddlers trying to push the limits of network fabrics and accelerator meshes, it can’t come soon enough
In this article, we report on our longitudinal research study (between 2020 and 2023) of such dangling resource abuse. Across 12 cloud platforms, we identified 20,904 hijacks that hosted malicious content. We detected hijacked domains in 219 Top-Level Domains (TLDs) and abuses on popular clouds.
Three imminent improvements to the Ethernet standard will make it a better alternative to host AI workloads, and that will see vendors back the tech as an alternative to Nvidia’s InfiniBand kit, which is set to dominate for the next two years.
Cloud native architecture is a game changer for security at scale. Whether used on-premises or in the cloud, capabilities to ease the management of IT assets are improving. And while there’s a long way to go in simplifying interfaces and reducing skill-set barriers – this too will come in time.
It’s a tantalizing idea: that the same routers bringing you the internet could also detect your movements. “It’s like this North Star for everything ambient sensing,” says Sam Yang, who runs the health-sensor startup Xandar Kardian. For a while, he says, “investors just flocked in.”
Arista Networks has offered a look at how it expects to roll out Ethernet technology that will underpin the networks required to handle the demands of AI-based workloads.
Driving through some rural areas east of where I live, I noticed a lot of collections of buildings strung together being used as homes. The process seems to start when someone takes a travel trailer, places it on blocks (a foundation of sorts) and builds a spacious deck just outside the door. Over time, the deck is covered, then screened, then walled, becoming a room.
Once the deck becomes a room, a new deck is built, and the process begins anew. At some point, the occupants decide they need a place to store some sort of equipment, so they build a shed. Later, the shed is connected to the deck, the whole thing becomes an extension of the living space, and a new shed is built.
These … interesting … places to live are homes to the people who live in them. They are often, I assume, even happy homes.
But they are not houses in the proper sense of the word. There is no unifying theme, no thought of how traffic should flow and how people should live. They are a lot like the paths crisscrossing a campus—built where the grass died.
Our networks are like these homes—they are not houses so much as historical records of every new idea and vendor marketing drive. There is no architecture, there are many architectures strung together with a set of tightly wound and closely followed processes.
We need to support some new application or service? Throw a new overlay on top. There was a massive failure last night? Let’s spend hours closely examining our process and find some way to prevent the failure by adding a few new steps.
We never ask if our goals are realistic because we don’t have any goal beyond: “Let’s solve this problem right now.” We never ask if there is some future goal might be better served by using this solution or that—the future will take care of itself.
Why do we fail to attend to architecture?
Architecture is hard, and we often fail to correctly anticipate the future. This perceives architecture as a detailed plan—but there’s no reason it should be. An architecture can be a rough, and slow-changing, outline of how the network is laid out, a set of services the network supports, and a set of technologies the network will use to support those services. An architecture recognizes and defines limits as well as capabilities.
Processes are comforting. When things fail, we can always take comfort in saying: “I followed the process!”
We live in a culture of now. All problems take two hours, two days, two weeks, or too long. There is no history, there is no future, there is only an ever-present now. If I cannot have it now, it is not worth having at all.
These problems are hard to solve because they are cultural rather than technical—and the network engineering world has a strong bias towards “don’t tell me how it works, tell me how to configure it.” We present this as a problem-solving mentality, even though it causes more problems than it solves.
We need to rebalance the way we think about architectures and processes—perhaps we would get better results by combining lightweight architectures with lightweight processes, instead of relying on heavy processes with no architecture to build maintainable networks and sustainable lives.
A lot of people are spending time thinking about how to make transport and control plane protocols more energy efficient. Is this effort worth it? What amount of power are we really like to save, and what downside potential is there in changing protocols to save energy? George Michaelson joins us from Australia to discuss energy awareness in protocols.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-221.mp3download
Cloud services are all the rage right now, but are they worth it? There are many aspects to the question, and the answer is almost always going to be “it depends.” Do you really need to spin up capacity more quickly than you can buy hardware and get it running? Do you really need to be able to spin capacity down without leaving any hardware behind? Is cloud really the best use of your team’s time and talent?
David Heinemeier Hansson joins Tom and Russ to talk about the economics and uses of cloud, and why his company has moved away from public cloud services.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-220.mp3download
We’ve been talking about many of the same things in networking since the late 1980s–autonomous, self-driving, autonomic, etc.–and yet … those things all still seem like some sort of Jetson’s cartoon episode. Why aren’t we there yet? Are these even the right goals?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-219.mp3download>
I’m writing a series on network models over at Packet Pushers; links to the first three are below.
Looking back at my career in network engineering, beyond some basic concepts and naming conventions, I cannot remember using the OSI model once. I have used the concept of layering, but never the OSI model specifically.
First, models are not sacrosanct. A model is just a tool. If the model you are using is not working for you, feel free to modify it. I find simpler yet extensible models far more effective than complex models for channeling my thoughts. In the past I have tried building huge models that “put everything in one place,” but they do not work for me.
How does a host differ from a middlebox? Hosts are designed to run applications that create and consume packets rather than quickly forwarding traffic through the network. The primary difference is that the source and destination are not two different ports on the same device but rather a virtual interface representing an application and a physical interface.
Highway 9 Networks recently emerged from stealth mode with $25 million in seed funding and a vision to provide enterprise companies with SaaS-based private mobile networks that would eliminate gaps in coverage by incorporating cellular technology.
Hackers’ advantage: One of the biggest security weaknesses in U.S. digital networks and infrastructure is out-of-date, no-longer-supported technology.
Threat actors have been observed leveraging the QEMU open-source hardware emulator as tunneling software during a cyber attack targeting an unnamed “large company” to connect to their infrastructure.
There are some weighty ironies here. The AI “safety” experts had raised alarm about “implicit bias” in AI, only for Google to release an almost parodically racist chatbot.
Yet another DNS vulnerability has been exposed. The language of the press release revealing the vulnerability is certainly dramatic, with “devasting consequences” and the threat to “completely disable large parts of the worldwide Internet.”
It’s a good rule of nostril that if your litigation department is a source of revenue, your business model stinks.
In his January 12 SpaceX update, Elon Musk said the biggest goal for Starlink from a technical standpoint is to get the mean latency below 20 ms.
In a recent press release, John Deere announced an agreement with Starlink to provide broadband for smart farm equipment in areas where cellular coverage is not strong enough.
What is it that makes a PC an AI PC? Beyond some vague hand-waving at the presence “neural processing units” and other features only available on the latest-and-greatest silicon, no-one has come up with a definition beyond an attempt to market some FOMO.
DORA is a regulation that enhances the operational resilience of information and communication technology (ICT) and third-party providers the EU financial sector.
Authorities with the Los Angeles Police Department are warning residents in Los Angeles’ Wilshire-area neighborhoods of a series of burglaries involving wifi-jamming technology that can disarm surveillance cameras and alarms using a wireless signal.
Carmakers are offering all kinds of over-the-air subscriptions and features, many of which benefit the businesses that use them. But this also opens up a wider attack surface for vehicle attackers.
Most providers will only accept a /24 or shorter IPv4 route because routers have always had limited amounts of forwarding table space. In fact, many hardware and software IPv4 forwarding implementations are optimized for a /24 or shorter prefix length. Justin Wilson joins Tom Ammon and Russ White to discuss why the DFZ might need to be expanded to longer prefix lengths, and the tradeoffs involved in doing so.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-218a.mp3
download
I have written elsewhere about the danger of AI assistants leading to mediocrity. Humans tend to rely on authority figures rather strongly (see Obedience to Authority by Stanley Milgram as one example), and we often treat “the computer” as an authority figure.
The problem is, of course, Large Language Models—and AI of all kinds—are mostly pattern-matching machines or Chinese Rooms. A pattern-matching machine can be pretty effective at many interesting things, but it will always be, in essence, a summary of “what a lot of people think.” If you choose the right people to summarize, you might get close to the truth. Finding the right people to summarize, however, is beyond the powers of a pattern-matching machine.
Just because many “experts” say the same thing does not mean the thing is true, valid, or useful.
AI assistants can make people more productive, at least in terms of sheer output. Someone using an AI assistant will write more words per minute than someone who is not. Someone using an AI assistant will write more code daily than someone who is not.
But is it just more, or is it better?
Measuring the mediocratic effect of using AI systems, even as an assistant, is difficult. We have the example of drivers using a GPS, never really learning how to get anyplace (and probably losing all larger sense of geography), but these things are hard to measure.
However, a recent research paper on programming and security has shown at least one place where this effect can be measured. Noting that most kinds of social research are problematic (they are hard to replicate, it’s hard to infer valid results accurately, etc.), this one seems well set up and executed, so I’m inclined to put at least some trust in the results.
The researchers asked programmers worldwide to write software to perform six different tasks. They constructed a control group that did not use AI assistants and a test group that did.
The result? In almost every case, participants using the AI assistant wrote much less secure code, including mistakes in building encryption functions, creating a sandbox, allowing SQL injection attacks, local pointers, and integer overflows. Participants made about the same number of mistakes in randomness—a problem not many programmers have taken the time to study—and fewer mistakes in buffer overflows.
It is possible, of course, for companies to create programming-specific AI assistants that might resolve these problems. Domain-specific AI assistants will always be more accurate and useful than general-purpose assistants.
Relying on AI assistants improves productivity but also seems to create mediocre results. In many cases, mediocre results will be “good enough.”
But what about when “good enough” isn’t … good enough?
Humans are creatures of habit. We do what we practice. If you want to become a better coder, you need to practice coding—and remember that practice does not make perfect. Perfect practice makes perfect.
Of all the problems with electric cars, perhaps the least expected was the revelation that some home charging points provide a potential point of weakness for malign foreign powers to interfere with our National Grid.
More than 8,000 domains and 13,000 subdomains belonging to legitimate brands and institutions have been hijacked as part of a sophisticated distribution architecture for spam proliferation and click monetization.
MWC Qualcomm is going big on AI at MWC, where it’s showing off a 7 billion parameter large language model running on an Android phone, along with an online hub to help mobile devs blend models into their apps, and AI infused into its latest 5G modem and Wi-Fi 7 silicon.
In the first week of January, the pharmaceutical giant Merck quietly settled its years-long lawsuit over whether or not its property and casualty insurers would cover a $700 million claim filed after the devastating NotPetya cyberattack in 2017.
Law enforcement agencies shut down xDedic, a cybercrime-as-a-service (CaaS) marketplace specifically providing web servers to cybercriminals, back in 2019.
Use of the Rust programming language has been on the rise but is only expected to continue to gather steam as more security-focused organizations call for Rust developers — affectionately known as Rustaceans — to use more memory-safe languages.
If you live in the United States, the data broker Radaris likely knows a great deal about you, and they are happy to sell what they know to anyone.
This paper introduces Morris II, the first worm designed to target GenAI ecosystems through the use of adversarial self-replicating prompts.
On a recent Thursday afternoon, a Consumer Reports journalist received an email containing a grainy image of herself waving at a doorbell camera she’d set up at her back door.
Japan’s government has ordered local tech giants LINE and NAVER to disentangle their tech stacks, after a data breach saw over 510,000 users’ data exposed.
We hear a lot about BGP security incidents–but what is really going on? How often do these happen, and how much damage do they do? Doug Madory, who monitors these things for Kentik, joins Russ White and Tom Ammon to talk about BGP security in the wild.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-218.mp3download
One thing we often hear about automation is that its hard because there are so many different interfaces. On this episode of the Hedge, Daniel Teycheney joins Ethan Banks and Russ White to discuss how they started from a simple idea and ended up building an automation system that does cross vendor boundaries within a larger discussion about automation and APIs.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-216.mp3download
Exclusive Dell’s “return to office” mandate has left employees confused about which offices they can use and the future of their jobs – and concerned the initiative is a stealth layoff program that will disproportionately harm women at the IT giant.
FDC Pat Gelsinger wants to make Intel the world’s second largest chip manufacturer by 2030, and that means serving businesses the x86 giant has traditionally seen as competitors.
Intel revealed a new road map at its Intel Foundry Services (IFS) Direct event that will take the company into 2027. Itメs an extension of the road map Intel laid out nearly three years ago, shortly after Intelメs CEO Pat Gelsinger took the reins of the company.
It is not known who pilfered the information nor their motives, but this leak provides a first-of-its-kind look at the internal operations of a state-affiliated hacking contractor.
Apple has announced a new post-quantum cryptographic protocol called PQ3 that it said will be integrated into iMessage to secure the messaging platform against future attacks arising from the threat of a practical quantum computer.
Juniper Networks, currently in the process of being acquired by HPE, has been accused of violating US securities laws in a shareholder lawsuit.
In the labyrinth of IT systems, logging is a fundamental beacon guiding operational stability, troubleshooting, and security. In this quest, however, organizations often find themselves inundated with a deluge of logs.
You’d think that few types of software are as trustworthy as some of the best antivirus programs, but it turns out that perceptions can be deceiving. Avast, one of the most recognizable antivirus solutions for PCs, was found to be secretly collecting and selling user data to third-party corporations for a period of six years.
Just what “mal-information” means, apart from the other two concepts, remains unclear. Differences between the three terms seem to hinge on the presumed motives of (usually) unknown persons, so clear distinctions between them may not be conceptually useful. We could just as well call it all wrongthink.
This post will list some of the major decisions made and if I endorse them for your startup, or if I regret them and advise you to pick something else.
Databases play a strange role in software development. The vast majority of complex applications use one, but many developers don’t pay a lot of attention to it in their daily work.
DNS abuse is defined as being composed of five broad categories of harmful activity insofar as they intersect with the DNS — malware, botnets, phishing, pharming, and spam (when it serves as a delivery mechanism for the other forms of DNS abuse).
Reading people from the past can sometimes show us where today’s blind spots are–but sometimes we can just find the blind spots of the people who lived then. In this episode of the Hedge, Tom, Eyvonne, and Russ finish going through a selection of quotes from an engineering book published in 1911. This time, we find there are some things to agree with, but also some to disagree with.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-215.mp3
The European Court of Human Rights (ECHR) has ruled that laws requiring crippled encryption and extensive data retention violate the European Convention on Human Rights – a decision that may derail European data surveillance legislation known as Chat Control.
The Electric Power Research Institute (EPRI) says that “better than 80% of all electronic system failures that are attributed to power anomalies are actually the result of electrical wiring or grounding errors or are generated by other loads within the customer’s facility.”
With research making considerable progress in designing quantum computers, it is time to consider the scenario that usable quantum computing will become a reality in the future. In this post, we discuss the testbed that we are setting up to empirically evaluate the impact of quantum-safe cryptography algorithms on DNSSEC.
Late last year, Congress extended Section 702 of the Foreign Intelligence Surveillance Act (FISA) and, in doing so, secured the nation’s warrantless surveillance powers until April 2024. With that month fast approaching, House Republicans have unveiled a new package to reauthorize those same powers, within limits.
Google has announced that it’s open-sourcing Magika, an artificial intelligence (AI)-powered tool to identify file types, to help defenders accurately detect binary and textual file types.
The justification for HPE buying Juniper may be a mundane, economy-of-scale play or a move to gain Juniper’s AI networking technology. Or there may be a vision for something more ambitious.
The Russian launch of a satellite, with nuclear power and the likely ability to disable satellites, underscores how satellites are quite vulnerable to both natural and manmade ruin.
The Australian Square Kilometre Array Pathfinder (ASKAP) – a precursor project for the full Square Kilometre Array – has started work on techniques to help it cope with increased satellite traffic.
Russia, China and other U.S. adversaries are using the newest wave of artificial intelligence tools to improve their hacking abilities and find new targets for online espionage, according to a report Wednesday from Microsoft and its close business partner OpenAI.
The Domain Name System (DNS) is an essential protocol in the architecture of todayメs Internet. It routinely translates domain names into IP addresses and also often handles a multitude of invalid queries.
Lumen Technologies in the last year has doubled down on enterprise, launching its first network-as-a-service offering, the ExaSwitch interconnection platform, among other services.
Cybersecurity researchers have identified two authentication bypass flaws in open-source Wi-Fi software found in Android, Linux, and ChromeOS devices that could trick users into joining a malicious clone of a legitimate network or allow an attacker to join a trusted network without a password.
Network operators increasingly rely on generic hosts, rather than specialized routers (appliances) to forward traffic. Much of the performance on hosts relies on offloading packets switching and processing to specialized hardware on the network interface card. In this episode of the Hedge, Krzysztof Wróbel and Maciej Rabęda join Russ and Tom to talk about hardware offloading.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/kedge-214.mp3download
You can find out more about hardware offloading here.
This year, I’ve had the opportunity to work alongside some of the highest- performing individuals in our profession. I’ve taken that opportunity to observe their work, look for patterns, and to try to identify the attributes that contribute to their success, not only as technologists but as humans.
OpenAI CEO Sam Altman’s dream of establishing a network of chip factories to fuel the growth of AI may be much, much wilder than feared.
Advanced persistent threat (APT) groups are more dangerous than your run-of-the-mill cybercriminals. They, after all, trail their sights not only on financial gain but loftier targets such as wreaking havoc on entire nations.
In this episode of PING, APNIC’s Chief Scientist Geoff Huston discusses the role of the Domain Name System (DNS) in directing where your applications connect to, and where content comes from.
As you awoke one morning from uneasy dreams you found yourself transformed in your bed into a software engineer. A calamity that I find all too familiar.
Whether you want to land a new job or make your contributions count, effective communication goes a long way.
At the beginning of the year, I wrote a bit about the resolution to “stay human” in 2024, in a world that is calling for artificial intelligence to be incorporated into more spheres of life, including law, automated driving, entertainment, and even relationships.
As with many other web3 evangelists, Andreessen Horowitz general partner Chris Dixon has identified some problems with the web.
In this article, we will conduct an in-depth exploration of an impactful vulnerability affecting various container runtimes.
In the February 13th edition of the Wall Street Journal, Professor Thomas W. Hazlett offers a breathless endorsement of market concentration with the T-Mobile acquisition of Sprint, his go-to example.
Network configuration analysis has always been the domain of commercial-grade software. Batfish changes all that with an open source, community-supported tool that can find errors and guarantees the correctness of planned or current network configurations. Ratul Mahajan joins Tom Ammon and Russ White to talk about this new tool, its capabilities, and the importance of network configuration analysis.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-213.mp3
download
You can find out more about Batfish at the project home page, and in this paper by Ratul.
Artificial intelligence and the chips that fuel its evolution have given rise to a new arms race between the US and China.
Alongside concerning recent security news, there has been a media-wide rise of references to ‘credential stuffing’. This is a term that doesn’t convey very much, but as it’s the accepted term inside the infosec community, it’s probably here to stay.
In October, the Consumer Financial Protection Bureau (CFPB) proposed a set of rules that if implemented would transform how financial institutions handle personal data about their customers.
In a far cry from the early 2000s, most U.S. adults today say they use the internet (95%), have a smartphone (90%) or subscribe to high-speed internet at home (80%), according to a Pew Research Center survey conducted May 19 to Sept. 5, 2023.
Cloudflare was a victim of the wide-ranging Okta supply-chain campaign last fall, with a data breach impacting its Atlassian Bitbucket, Confluence, and Jira platforms beginning on Thanksgiving Day.
Honeypots are usually used as an intrusion detection tool. Many security researchers, including Computer Security Incident Response Teams (CSIRTS), deploy honeypots, to learn about tools, tactics, and the attacker’s infrastructure.
AWS could rake in between $400 million and $1 billion a year from charging customers for public IPv4 addresses while migration to IPv6 remains slow.
Sustainability efforts and high-density AI-based applications are sparking new and revamped approaches to data center cooling.
In what is sure to have significant implications for millions of American workers, specifically gig economy workers and contractors, the Department of Labor (DOL) issued its long-awaited final worker classification rule in January.
This week the streets are filling up with futuristic flies. In the old days we killed them with pesticides, and now we pay over $3,500 to become one of them.
But cracking BitLocker? We doubt the company will be bragging too much about that particular application.
Apple has just released Vision Pro, a virtual-reality headset that ushers in a new era of spatial computing. It claims to blend the real and digital worlds, so users can interact in both simultaneously.
How many times have you heard you should “shift left” in the last few years? What does “shift left” even mean? Even if it had meaning once, does it still have any meaning today? Should we abandon the concept, or just the term? Listen in as Chris Romeo joins Tom Ammon and Russ White to talk about the origin, meaning, and modern uselessness of the term “shift left.”
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-212.mp3
download
I’ve been on a bit of a writer’s break after finishing the CCST book, but it’s time to rekindle my “thousand words a day” habit. As always, one part of this is thinking about how I write—is there anything I need to change? Tools, perhaps, or style?
What about the grade level complexity of my writing? I’ve never really paid attention to this, but I’m working on contributing to a site regularly that does. So maybe I should.
I tend to write to the tenth or eleventh-grade level, even when writing “popular material,” like blog posts. The recommended level is around the eighth-grade level. Is this something I need to change?
It seems the average person considers anything above the eighth-grade reading level “too hard” to read, so they give up. Every reading level calculation I’ve looked at essentially uses word and sentence length as proxies for complexity. Long words and sentences intimidate people.
On the other hand, measuring the reading grade level can seem futile. There are plenty of complex concepts described by one- and two-syllable words. Short sentences can still have lots of meaning.
Further, the reading grade level does not tell you if the sentence makes sense. A famous politician recently said, “… it’s time for us to do what we have been doing, and that time is every day.” The reading grade level of this sentence is in the sixth grade—but saying nothing is still saying nothing, even if you say it at a sixth-grade level.
While reading level complexity might be important, it is more important to say something.
Sometimes, using long words and sentences stops people from paying attention to your words. However, replacing long words and sentences with shorter ones sometimes removes your words’ real meaning (or at least flavor). I am not, at this point, certain how to balance these. I suspect I will have to consider the tradeoff in every situation.
When you write—and if you are doing your job as a network engineer well, you do write—you might want to consider the complexity of your writing. I will use the grade level as “another tool” in my set, which means I’ll be thinking about writing complexity more—but I’m not going to allow it to drive my writing style. If I can reduce the complexity of my writing without losing meaning, I may … sometimes … or I might not.
Looking at the other side of the coin—what about reading grade level from a reader’s point of view? Should we only read easy-to-read things? The answer should be obvious: no.
There is a bit of a feeling that text above a certain reading level is “sheer nonsense.” Again, though, the grade level has nothing to do with the value of the content. Sometimes, saying complex things just requires complex text. Readers (all of us) need to learn to read complex text.
Reading grade level is a good tool in many situations—but it is one tool among many.
Everybody likes good news, especially at the beginning of the corporate year, and we are happy to report that TSMC’s revenues in the fourth quarter ended in December 2023 were only down 1.5 percent year on year to $19.62 billion, and were up 13.6 sequentially from the third quarter
HP CEO Enrique Lores admitted this week that the company’s long-term objective is “to make printing a subscription” when he was questioned about the company’s approach to third-party replacement ink suppliers.
The Internet Corporation for Assigned Names and Numbers (ICANN) has proposed creating a new top-level domain (TLD) and never allowing it to be delegated in the global domain name system (DNS) root.
What is cool about DNS over HTTPS is that, well, it uses HTTPS. Because HTTP clients are plentiful and well understood by many developers, it should make for a pretty simple implementation.
However, VPN is no longer good enough to secure remote work. For instance, VPN gives remote employees full network access to corporate resources when they login.
Universally, every person that I put the question to dismissed FWA wireless as a temporary technology with no real long-term legs.
Apple launched the original 128 kB Macintosh around 40 years ago, and in so doing changed the computer industry, in ways that a lot of people still don’t fully understand.
Europe’s aviation safety body is working with the airline industry to counter a danger posed by interference with GPS signals – now seen as a growing threat to the safety of air travel.
And as the wheels come off Moore’s law, and generational process improvements become less impactful, several emerging technologies to boost performance and density are taking precedence.
As the fields of cryptography and cybersecurity advance, homomorphic encryption stands out as a groundbreaking technology.
How much have you thought about the way you learn–or how to effectively teach beginners? There is a surprising amount of research into how humans learn, and how best to create material to teach them. In this roundtable episode, Tom, Eyvonne, and Russ discuss a recent paper from the Communications of the ACM, 10 Things Software Developers Should Learn about Learning.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-211.mp3
download
transcript (machine generated)
A study by Consumer Reports and non-profit The Markup concluded that for the average lone Facebook user, 2,230 companies, and in some cases more than 7,000, will hand over that person’s information to Facebook.
2023’s copious chatter about generative AI has not translated into surging semiconductor revenues across the industry, according to analyst firm Gartner.
According to a report by industry analyst Trendforce, the tech company will up the base memory requirement on Windows 12 to 16GB in accordance with its standard for running its AI assistant Copilot at minimum efficiency.
Imagine downloading an open weights AI language model, and all seems good at first, but it later turns malicious.
The supermassive leak contains data from numerous previous breaches, comprising an astounding 12 terabytes of information, spanning over a mind-boggling 26 billion records.
In order for CPU and AI Accelerators/GPUs to effectively work with each other for larger training models, the communication bandwidth of the PCIe-based interconnects between them needs to scale to keep up with the exponentially increasing size of parameters and data sets used in AI models.
It was one thing to support cell towers when they were used for rural cellphone coverage. But it’s a new equation to be asked to provide faster bandwidth to an ISP that will use the bandwidth to win over local customers.
Surveillance doorbell maker Amazon Ring on Wednesday announced it is discontinuing an option that allowed law enforcement agencies to request video footage without a warrant.
Jay Fink had an interesting little business. If you lived in California, you could give him access to your email account; he’d look through the spam folder for spam that appeared to violate the state anti-spam law and give you a spreadsheet and a file of PDFs.
It is not uncommon these days for threat actors to use malicious search ads to distribute malware. To do that, though, they would need to know how to bypass Google’s security measures by setting up decoy infrastructures.
DDoS attack trends for the second half of 2023 reveal alarming developments in the scale and sophistication of cyberthreats.
Quantum technologies promise all kinds of fascinating possibilities, but they also come with risks. In this episode, André Grilo, founder and CEO of QuantumNova, talks about why we need to start investing in post-quantum cryptography to protect ourselves against post-quantum threats.
Have you ever thought about publishing a book or recording a professional video? It’s not as simple as proposing an idea, doing the work, and becoming famous (or infamous, as the case might be). Eric Chou joins Rick Graziani and Russ to talk about the ins and outs of technical publishing. We are planning a part 2 of this in a few months to cover things we left on the table for later discussion.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-210.mp3download
machine-generated transcript
Pressure to resolve incidents quickly that often comes from peers, leadership, and members of affected teams only adds to the chaos of incident management, causing more human errors. Coordinating incidents such as this through the process of having an Incident Commander role has shown more controllable outcomes for organizations around the world.
The Kimsuky Group, believed to be a North Korea-based advanced persistent threat (APT) group active since 2013, struck again several times this year.
QUIC supports connection migration, allowing the client to migrate an established QUIC connection from one path to the other. QUIC’s path validation mechanism can be used to attack the peer and make it consume an unbounded amount of memory.
The NVM Express consortium has updated its specifications by adding a Computational Storage Feature, creating a standardized way for applications to talk to storage devices that include some processing capability.
Post Office chief exec Nick Read left British politicians shocked with his evidence before a Parliamentary committee yesterday after he admitted he could not say when the public body at the center of the historic miscarriage of justice knew when its system was at fault.
We’re only a few weeks into 2024, and violations of people’s privacy are already making some big headlines! First we had the continued drama with the 23andMe data breach; then a major financial software company was shut down for inappropriately using private information; and then this week, the FTC took an unprecedented step and banned a data broker from selling people’s location data.
The new domain name registration volume rose 10.24% from the third to the fourth quarter of 2023. WhoisXML API researchers uncovered this finding, along with other DNS trends, after analyzing more than 31 million newly registered domains (NRDs) added from 1 October to 31 December 2023 as seen in the Newly Registered Domains Data Feed.
Here is how you know that the way chiplets are linked together to create what might have otherwise been a monolithic device is now more important than the way that the chiplets themselves are designed.
Leichtman Research Group, Inc. (LRG) conducted its annual survey on household broadband usage and found that 90% of U.S. homes now have broadband.
Two weeks before Apple launched the Macintosh, Sir Clive Sinclair launched his unprecedentedly powerful yet affordable Motorola-powered SOHO computer – starting a line of hardware and software that, remarkably, is still going.
Even though it could take significantly longer for quantum computers to become sufficiently powerful to threaten current cryptography, we have to be prepared for a worst-case scenario. In the context of DNS, DNSSEC may no longer guarantee authentication and integrity when powerful quantum computers become available.
Verizon filed an SEC form 8K today, indicating that it would take a $5.8 billion impairment charge in its Verizon Business wireline group in the fourth quarter of 2023.
User interface design is notoriously bad for networking gear–but why, and what can we do about it? Frank Seesink joins Tom and Russ to talk about user interface stupidity.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-209.mp3download
Network engineering is not “going away.” Network engineering is not less important than it was yesterday, last year, or even a decade ago.
But there still seems to be a gap somewhere. There are fewer folks interested than we need. We need more folks who want to work as full-time network engineers, and more folks with network engineering skills diffused within the larger IT community. More of both is the right answer if we’re going to continue building large-scale systems that work. The real lack of enthusiasm for learning network engineering is hurting all of IT, not just network engineering.
How do we bridge this gap? We’re engineers. We solve problems. This seems to be a problem we might be able to solve (unlike human nature). Let’s try to solve it.
As you might have guessed, I have some ideas. These are not the only ideas in the world—feel free to think up more!
If you walk into a robotics class, even an introductory robotics class, you see people … building robots. If you walk into a coding class, even an introductory one, you see people … writing software. If you walk into a network network engineering class you see … someone lecturing about the OSI model, packet formats, or how to configure BGP.
What problems are people learning to solve robotic engineering? How to build a robot and get it to do something to solve a real-world problem. What problems are people learning to code solving? How to tackle some real-world problem.
Sure, the problems being solved at an introductory level might be trivial, like: “Read this file and spit out a sum of the numbers in the fourth column.” But they are still starting, right from the beginning, by taking requirements and converting them into solutions.
What problems are network engineers learning how to solve? How to choose hardware, string it all together, and configure BGP.
Do you see the difference?
All engineers solve problems—it’s the nature of engineering. But are we creating a mindset in prospective network engineers, or even adjacent fields, that we solve real-world problems? Or are we giving them the impression that we solve whiteboard problems by talking about bits, bytes, configurations, and cable types?
Have you ever seen the glazing over of eyes while explaining how you put four transport protocols on top of one another (look at all the pretty tunnels)? How about when you create a chart showing how TCP and QUIC can be “kind-of sort-of” forced into the OSI model? Or when you spin out your BGP packet format charts, showing how we’ve (mis)used address families to carry everything anyone can imagine?
I’ve been teaching this stuff for years (okay, decades). Over time, I’ve moved away from teaching configurations and packet formats. I’ve gone from Advanced IP Network Design to Computer Networking Problems and Solutions. These are very different ways of looking at network engineering.
Focusing on real-world problems would help connect business and other IT folks to the network, connect theory to practice, and people to network engineering. Going home at the end of the day saying, “I solved a problem,” can be satisfying. Going home at the end of the day saying, “I configured BGP?”
Another thing adopting the mindset of solving real-world problems might do is help us lose unnecessary complexity. I know complexity is necessary to build resilient systems; we cannot build what we build without creating and encountering complexity.
But we often run ourselves into the ditch on both sides of the road.
We unintentionally build too complex because we try to make it too simple. Quick, which is simpler: building a data center fabric with one routing protocol or two? A single chassis system or several smaller fixed format devices? A proprietary system or something built on open standards?
How many balloons fit in a bag? (thanks, Don)
Failing to start with the tradeoffs, and thinking through what problem we’re actually trying to solve, leads to unnecessary complexity. Such designs might not immediately fail, but they will fail, and “it’s so complex” just isn’t an excuse.
Don’t even try to tell me there aren’t any tradeoffs. If you think there aren’t any tradeoffs, that just means you haven’t looked hard enough. Go find them, think about them, and document them.
We also build complex things because we think it offers job security, or it’s neat, or we like to feel like the kid who says to the world, “look what I built!”
I know it’s exciting to hear stories about that time someone rescued a network from a major failure—after all, that’s solving a real-world problem. Building a network that just works might be “boring,” but it solves many more real-world problems than raising a network from the dead.
We love our fashionable capes, but … capes can get caught in a nearby jet engine. Lose the cape. In the long run, it’ll make network engineering more attractive as a career field and field of knowledge.
The Bottom Line
No, the sky is not falling. We still need networks, and we still need network engineers.
Yes, there is a problem. Too many companies are going “to the cloud” because they cannot find people qualified to build and maintain their very complex networks. There’s too much centralization and too little oppeness.
So maybe let’s stop saying “we don’t need network engineers.” And maybe let’s really think about how we’re building things. And maybe let’s focus on solving real-world problems, starting from day one in network engineering classrooms.
Network engineering is still cool—let’s go out there believing—and selling—that idea to the world.
Yes, the weekend has pretty much already passed, but still …
The WailingCrab malware has gained notoriety for its stealth. IBM X-Force security researchers recently published an in-depth analysis of the malware, which has been abusing Internet of Things (IoT) messaging protocol MQTT.
SpaceX successfully launched 21 satellites, including the first six Starlink satellites equipped with “Direct to Cell” capabilities.
MTL mode is a technique developed by Verisign researchers that can reduce the operational impact of a signature scheme when authenticating an evolving series of messages.
While Kubernetes adoption continues to soar, it has become a prime target for cyberattacks. Unfortunately, Kubernetes clusters are complex and can be difficult to secure. Safeguarding your Kubernetes environment requires a solid understanding of the common attack chains that pose a threat to your infrastructure.
Going into 2023, the big telcos had publicly announced plans to build 9.4 million fiber passings, but during the year, they collectively pared that back expectations to 6.5 million passings.
A new exploitation technique called Simple Mail Transfer Protocol (SMTP) smuggling can be weaponized by threat actors to send spoofed emails with fake sender addresses while bypassing security measures.
The Atomic Stealer, also known as “AMOS,” first emerged in September this year by spreading on Macs disguised as popular applications. This time around, it has been wreaking more havoc in the guise of a fake browser update dubbed “ClearFake.”
On December 27, The New York Times Company sued Microsoft and OpenAI for violations of their copyright. The Times contends that training chatbots on its content in order to create an information competitor is a violation of its copyright.
Since 2014, more than 800 new domain extensions have been added to the internet. In addition to the ubiquitous .com and country-code extensions such as the United Kingdom’s .uk and Japan’s .jp, unique spaces have been created for industry sectors, special interests, geographical regions and more.
Often the lifestyle entrepreneur builds his brand around projecting success; in fact, his real-life success rests partly on how well he can project it. As seen with founders such as Elizabeth Holmes of Theranos, the ability to attract investors rests on a cult of exclusivity and buzz around a brand’s value.
ChatGPT, the large language model developed by OpenAI, might seem like it generates novel content, but of course we know that it partakes in what’s generally called “scraping.” It takes pre-existing material on the Internet in response to the prompt a human user inserts.
This case had a bit of a weird result—even though the brand owner had a mark that was 20 years old, and the alleged cybersquatter, in the meantime, acquired a domain name on the open market identical to that mark, because the domain name was first registered (by an unrelated party) before the brand owner’s trademark rights arose, there was no relief under federal trademark law.
The Internet of Things (IoT) has been brewing for many years–but how do all these new devices impact your network? Are there new concepts and architectures you need to learn to get a handle on IoT? Jasbir Singh, author of a new book on IoT architecture, joins Tom and Russ for this episode of the Hedge.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-208.mp3download
Is network engineering still cool?
It certainly doesn’t seem like it, does it? College admissions seem to be down in the network engineering programs I know of, and networking certifications seem to be down, too. Maybe we’ve just passed the top of the curve, and computer networking skills are just going the way of coopering. Let’s see if we can sort out the nature of this malaise and possible solutions. Fair warning—this is going to take more than one post.
Let’s start here: It could be that computer networking is a solved problem, and we just don’t need network engineers any longer.
I’ve certainly heard people say these kinds of things—for instance, one rather well-known network engineer said, just a few years back, that network engineers would no longer be needed in five years. According to this view, the entire network should be like a car. You get in, turn the key, and it “just works.” There shouldn’t be any excitement or concern about a commodity like transporting packets. Another illustration I’ve heard used is “network bandwidth should just be like computer memory—if you need more, add it.”
Does this really hold, though? Even if we accept the car and computer memory illustrations and individual routers like these things, is an entire network system like a car? A closer analogy for a network in the world of cars would be an entire transportation system.
You have different kinds of physical transport (rail, over-the-road trucks, air travel, ships, etc.), each with its characteristics, and all of which must be connected to move physical objects from one place to another. There must be some kind of “control plane” that coordinates, shared addressing, formatting rules, etc.
While a single car might, in some sense, be a commodity at this point (and I’ll bet there aren’t many car owners who would wholly agree with that characterization), I don’t see how we could call an entire transportation system a commodity—especially if we want to say “the skills needed to build a transportation system just aren’t needed any longer, there’s nothing more to learn, this is so … boring …”
Let’s dispense with this idea that networks just aren’t needed any longer. We must still build networks that carry traffic between servers, cities, countries, and continents. Building these networks is still a hard problem. Even if there is less room to improve these things than ten or twenty years ago, the problems are still hard. Even if many problems are solved at a broad level, not every problem is solved in every network in the universe.
A more reasonable take on this perspective is that networking skills are diffusing into a larger information technology (IT) skill set. Perhaps IT, in its relative “youth,” divided too sharply and finely—we created too many career fields. What is happening right now, then, is just a kind of right sizing in the market.
Network engineering skills, in fact, do seem to be dispersing to one degree or another. But let’s put this in perspective.
The first point is I’m not convinced there are fewer network engineers. Instead, it’s more likely there are just as many network engineers as there ever have been, if not more. Perhaps, though, “real” network engineering has been growing linearly while all the other IT fields have been growing at a rate faster than linear (I don’t want to say exponential, just something more than linear).
In a world that counts lack of growth as a failure, networking growing at a slower pace than, say, programming seems like a failure from the outside. People like to follow winners; growing is winning; network engineering is not growing as fast as other things, so network engineering is failing.
I dislike the modern progressive mindset—but while I’m working on something in this area, this isn’t the time or place to dive into this topic. Let’s agree that we must let go of the idea: “Growing slower is a failure.”
Returning to the idea of transportation—I will just about bet automobile designers built entire departments in the early days of car manufacturing. Today, there might be just as many automobile designers as ever. They’re just buried in large car manufacturing, servicing, etc., companies, so it feels like there are a lot fewer than there were.
Just because most new engineers must learn many different things, and network engineering skills are diffusing into many different areas of IT, does not mean network engineering is dying, regardless of what it might look like from the outside.
Second, there is nothing wrong with network engineering skills diffusing into the larger IT skill set. Has anyone reading this ever really been a “pure” network engineer? If so, I don’t know whether to envy or feel sorry for you.
When building networks in the military, I had to deal with all the politics of customer relationships and understanding mission needs. When taking cases in technical support, I had to deal with time management and customer-facing skills—and I needed to learn or use coding skills to be an effective network engineer. Today, I do network engineering, like I always have, but I work on security, privacy, DNS, coding, and all sorts of other things.
I cannot think of a time in my career when I would have considered myself a “pure network engineer.” I’ve always had to find and build adjacent skills to design, build, and maintain networks. I would say this is truer today than ever, but I do not believe my skills as a network engineer are any less useful than they have ever been.
Where does all of this leave us?
Let’s continue the discussion in part 2 next week.
Thanks to Mark Prosser for a few links to add to the pile this week.
There’s a rumor flying around the Internet that OpenAI is training foundation models on your Dropbox documents.
Microsoft found that a popular form of video-based training reduces phish-clicking behavior by about 3%, at best. This number has been stable over the years, says Microsoft, while phishing attacks are increasing yearly.
The Internet Architecture Board (IAB) has warned that policy proposals requiring or enabling the automated scouring of people’s devices for illegal material – as floated by the European Union, the United Kingdom, and the United States – threaten the open internet.
Another update of the Ultimate PCAP is available. Again, there are some special new packets in there which I want to point out here. Feel free to download the newest version to examine those new protocols and packets by yourself. Featuring: SNMPv3, WoL, IPMI, HSRP, Zabbix, Pile of Poo, and Packet Comments.
The Genesis Market began operating in 2017, four years after Silk Road closed shop. Like its predecessor, though, the Federal Bureau of Investigation (FBI) and other law enforcement agencies took the Genesis Market down last April.
Miyake events are believed to be several orders of magnitude greater than the Carrington Event. It is not clear what causes the event.
The classical definition of a robot is something that senses, thinks, and actsラthatメs todayメs Internet. Weメve been building a world-sized robot without even realizing it.
The average cost of data breaches has been rising almost steadily since 2017. In 2017, the average cost was “merely” $3.62M. In 2023, it reached an all-time high of $4.45M in 2023. In the past three years, average breach costs increased by 15%.
Lars-Johan Liman, Netnod’s DNS nestor, makes a few personal reflections on the 20th anniversary of Netnod’s deployment of anycast – a technology that is a crucial part of the infrastructure of Netnod’s modern DNS services.
You know those little jokes that centre around a person with a PhD being on a plane, and someone asks for a doctor, and they say they aren’t that kind of doctor but the emergency involves their field of study?
The dark forest theory of the web points to the increasingly life-like but life-less state of being online.Dark Forest Theory of the Internet by Yancey Strickler Most open and publicly available spaces on the web are overrun with bots, advertisers, trolls, data scrapers, clickbait, keyword-stuffing “content creators,” and algorithmically manipulated junk.
After a decade or so of the general sentiment being in favor of the internet and social media as a way to enable more speech and improve the marketplace of ideas, in the last few years the view has shifted dramatically—now it seems that almost no one is happy.
When I first fell in love with the web, it was a radically different place. Aside from the many technical improvements that have been made, I feel like the general culture of the web has changed a lot as well.
And everyone is talking—correctly or not—in the language of therapy, peppering conversations with references to gaslighting, toxic people, and boundaries.
What does it mean to be a network engineer in today’s world of information technology? Phil Gervasi joins Tom and Russ to discuss the ins and outs of network engineering, and what it’s really like to be in this small corner of information technology today.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-207.mp3
download
I’ve reformatted and rebuilt my network troubleshooting live training for 2023, and am teaching it on the 26th of January (in three weeks). You can register at Safari Books Online. From the site:
The first way to troubleshoot faster is to not troubleshoot at all, or to build resilient networks. The first section of this class considers the nature of resilience, and how design tradeoffs result in different levels of resilience. The class then moves into a theoretical understanding of failures, how network resilience is measured, and how the Mean Time to Repair (MTTR) relates to human and machine-driven factors. One of these factors is the unintended consequences arising from abstractions, covered in the next section of the class.
The class then moves into troubleshooting proper, examining the half-split formal troubleshooting method and how it can be combined with more intuitive methods. This section also examines how network models can be used to guide the troubleshooting process. The class then covers two examples of troubleshooting reachability problems in a small network, and considers using ChaptGPT and other LLMs in the troubleshooting process. A third, more complex example is then covered in a data center fabric.
A short section on proving causation is included, and then a final example of troubleshooting problems in Internet-level systems.
I’ve just finished a seven-part series over at Packets Pushers about the process of writing and publishing an RFC. Even if you don’t ever plan to write a draft or participate in the IETF, this series will give you a better idea of the work that goes into creating new standards and IETF documents.
So … you have an idea you think would fit perfectly into the realm of the Internet Engineering Task Force (IETF)—but where do you start?
This, the second, post, will consider document formatting and two of the (sometimes) more difficult sections of an IETF draft to fill in.
There are other seemingly mystical concepts in the IETF process as well—for instance, what is a “document stream,” and what is a document’s “status?”
You’re almost ready to submit a shiny new document to the IETF for consideration, right? Not quite yet—we still need to deal with mandatory sections and language.
You cannot simply post a draft to the IETF repository and expect “someone, somewhere,” to take action.
The working group chairs asked if your draft should become a working group item, and the consensus was to accept! It might seem like your draft is home free at this point—but there is still a lot of work to do.
Once the draft is written, socialized, accepted by a working group, and passes through the IESG telechat and review, what is next?
As we reach the end of what has been a hard two-year stretch for what seems like the entire world, Ethan Banks joins Tom, Eyvonne, and Russ to talk about the importance of taking care of yourself. In the midst of radical changes, you can apply self-discipline to make your little part of the world a better place by keeping yourself sane, fit, and well-rested.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-206.mp3download
transcript
As we close out 2023, some random observations about engineering, culture, and life.
Network engineering needs help. I am hearing, from all over the place, that network engineering is “not cool.” There is a dearth of students entering the pipeline. College programs are struggling, and many organizations are struggling with a lack of engineering talent—in fact, I would guess the most common reason for companies to move to “the cloud” is because they cannot find anyone who knows how to build an operate a network any longer.
It probably didn’t help that for the last few years many “thought leaders” in the network engineering space have been saying there is no future in network engineering. It also doesn’t help that network engineering training has become stilted and … boring. Coders are off talking about how to solve problems. Robotics folks are working on cool projects that solve problems.
Network engineers are being taught how to spend less money and told to “find another career.”
I don’t know how we think we can sustain a healthy world of IT without network engineers.
And yes, I know there are folks who think networking problems are simple, easy enough to solve with some basic software knowhow. I think I have enough knowledge and experience of the wider world of information technology to say those folks are wrong.
I’d actually like to help solve this specific problem. I’ve been looking for a Christian college someplace in the US interested in starting or growing a strong engineering program. Someplace where I join with a team to help build and teach an entire program from the first class to the last. If anyone knows of such a place, get in touch. We need to make network engineering cool again.
How much did you read this year? I read just over 40 books this year, not many of which were technology related. If you don’t read regularly, why not?
How much did you create this year? I wrote one book—the CCST Official Study Guide. I’ve written two dozen articles or so and created a few new slide decks. I’m working on several new live webinars with Pearson through Safari Books Online, including interview skills, open-source labs, some work around coding skills, and a few other things.
It you aren’t creating new things, why not?
Big is, for the most part, bad. I’ve started thinking that one of the worst things about technology-driven culture is how deeply it has enabled and taught—even encouraged—us to be passive-aggressive.
For instance, I’ve been “lifetime banned” from eBay. Why? I’ve no idea—I barely even use eBay. I logged in, listed a few items for sale, and then couldn’t log back in again. I tried to reset my password—the service accepted my new password, but still refused to allow me to log in. No notifications, no email, no … anything. I called customer support and was told I have been “banned for life.” They will not discuss why, only that some “system flagged my account.”
It is just this kind of “the computer says you are a bad person, and we will not explain why” thing that makes people dislike technology companies so deeply.
As always, feel free to get in touch if you have thoughts, want to chat, or have an idea for an episode of the Hedge.
NTT Data has opened a hotel at which it plans to watch people sleep, as part of a plan to gather – and of course sell – data about the snoozing habits of ten million people.
Business and technical leaders should prepare to focus on memory safety in software development, the US Cybersecurity and Infrastructure Agency (CISA) urged on Wednesday.
A proposed fork of the OpenPGP standard, called “LibrePGP” and initiated by GnuPG’s maintainer Werner Koch, has made a series of statements on its own website1 in order to justify its existence.
Cisco has quietly introduced changes to the licensing model for its Catalyst range, and will bring it to more products over time.
ICANN’s response to the European Union’s Network and Information Security Directive (NIS2) is a litmus test on whether its policy processes can address the needs of all stakeholders, instead of only satisfying the needs of the domain industry.
One of the joys of operational privacy professionals is getting that random, Friday afternoon Slack from someone on the product team asking, “Can we [insert questionable action] with our customer data?”
Lackluster security controls in one of Google’s cloud services for data scientists could allow hackers to create applications, execute operations, and access data in Internet-facing environments.
The incident response process can be a maze that security professionals must quickly learn to navigate—which is no easy task. Surprisingly, many organizations still lack a coordinated incident response plan, and even fewer consistently apply it.
The suitability of a data center environment is primarily judged by its effect on the long-term health of IT hardware.
Most of the tech gifted this holiday will end up in a landfill. But Keegan McNamara makes laptops you can pass on to your grandchildren.
This blog acts as a quick guide on network penetration testing, explaining what it is, debunking common myths and reimagining its role in today’s security landscape.
A years-old Bluetooth authentication bypass vulnerability allows miscreants to connect to Apple, Android and Linux devices and inject keystrokes to run arbitrary commands, according to a software engineer at drone technology firm SkySafe.
Google has revealed a new multilingual text vectorizer called RETVec (short for Resilient and Efficient Text Vectorizer) to help detect potentially harmful content such as spam and malicious emails in Gmail.
Carding has been around since the 1980s but has evolved to the point that even less experienced cybercriminals can now launch campaigns.
Enter Cilium’s advanced Border Gateway Protocol (BGP) implementation, powered by the GoBGP control plane, a solution that not only addresses these challenges but also adds unprecedented flexibility to your network configurations.
The most curious part of this is how people working inside the macroculture are the only folks who don’t understand what’s going on.
Efforts to convince remote workers to return to corporate offices appear to have stalled, based on data from the government, academia, and private-sector organizations.
Once in your home, different individuals have differing authority based on who they are. Family members have access to your whole home.
HP is squeezing more margin out of print customers, the result of a multi-year strategy to convert unprofitable business into something more lucrative, and says its subscription model is “locking” in people.
Microsoft helped Chinese state-run media outlets disseminate propaganda as part of previously unreported partnership agreements, documents obtained by the Washington Free Beacon show.
Unfortunately, leadership training, education, and discussion tends to be reserved for people-managers. Of course, leadership skills are important for those directly responsible for teams of people.
Spying and surveillance are different but related things. If I hired a private detective to spy on you, that detective could hide a bug in your home or car, tap your phone, and listen to what you said.
The European Union’s Network and Information Security Directive (NIS1), introduced in 2016, aimed to strengthen cybersecurity among Member States. However, market fragmentation and growing digital threats led to the enactment of the NIS2 Directive.
Attackers could soon begin using malicious instructions hidden in strategically placed images and audio clips online to manipulate responses to user prompts from large language models (LLMs) behind AI chatbots such as ChatGPT.
For this month’s roundtable, Eyvonne, Tom, and I return to Addresses to Engineering Students by Harrington and Waddell. This book, published in 1912, is a “product of its time,” and hence deserves some trigger warnings. But it is also interesting to see how advice given to engineering students over 100 years ago holds up for today. Have engineering challenges, and the engineering life, changed all that much? What kinds of advice stand the test of time, what kinds do not?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-205.mp3download
transcript
On the 26th of January, I’ll be teaching a webinar over at Safari Books Online (subscription service) called Modern Network Troubleshooting. From the blurb:
The first section of this class considers the nature of resilience, and how design tradeoffs result in different levels of resilience. The class then moves into a theoretical understanding of failures, how network resilience is measured, and how the Mean Time to Repair (MTTR) relates to human and machine-driven factors. One of these factors is the unintended consequences arising from abstractions, covered in the next section of the class.
The class then moves into troubleshooting proper, examining the half-split formal troubleshooting method and how it can be combined with more intuitive methods. This section also examines how network models can be used to guide the troubleshooting process. The class then covers two examples of troubleshooting reachability problems in a small network, and considers using ChaptGPT and other LLMs in the troubleshooting process. A third, more complex example is then covered in a data center fabric.
Register here.
Yet despite the constant accretion of new tools to solve new problems, the most common root cause of serious cybersecurity incidents remains failed processes.
The House of Representatives’ failure to spike a federal “kill switch” mandate means that outside of a political miracle, all new vehicles from 2026 onward will be required to incorporate “advanced drunk and impaired driving prevention technology.”
Gone are the days when a car was a dumb machine you turned on and drove from A to B. Today it’s a smartphone on wheels, and your data is possibly being taken for a ride.
APT29, believed to be an espionage group from Russia, became known for launching targeted attacks against organizations in Ukraine.
Mozilla has slapped its “Privacy Not Included” labels on several products from Google, Amazon and Microsoft – just in time for Christmas shopping.
Despite more than a decade of reminding, prodding, and downright nagging, a surprising number of developers still can’t bring themselves to keep their code free of credentials that provide the keys to their kingdoms to anyone who takes the time to look for them.
Special report Web advert blockers and other Chrome extensions will stop working by June 2024 unless they’ve been revamped to keep up with Google’s changes to its ubiquitous browser.
The Federal Bureau of Investigation (FBI) shut down BreachForums, a forum for English-speaking black hat hackers, on 21 March 2023, following the arrest of its owner Conor Brian Fitzpatrick.
A new study has demonstrated that it’s possible for passive network attackers to obtain private RSA host keys from a vulnerable SSH server by observing when naturally occurring computational faults that occur while the connection is being established.
This post covers an interesting case of suspected abuse in a generic Top-Level Domain (gTLD) registry between February and April 2023. It is a good example of an edge case, where the decision on whether or not to mitigate was not clear-cut, and different levels of evidence were available at different times.
For example, one thing to ask is: to what extent is the Internet resilient to this kind of event? In earlier analyses, to the extent we’ve been able to measure it, the answer has largely been: very. So let’s take a look at whether the same holds this time around.
Is a public cloud like AWS or Microsoft’s Azure the right place to host every deployment workload at every stage of its life? To be honest, I once thought that that was true – at least 95% of the time.
Terry Slattery joins Tom and Russ to continue the conversation on network automation—and why networks are not as automated as they should be. This is part one of a two-part series; the first part of this conversation was posted as episode 203.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-204.mp3download
rough transcript
Bad queries tend to propagate to the root zone due to the hierarchical nature of DNS, so studying traffic at a root server can provide key insights into overall network usage.
This blog covers an interesting case of suspected abuse in a gTLD registry between February and April 2023.
YouTube wants its pound of flesh. Disable your ad blocker or pay for Premium, warns a new message being shown to an unsuspecting test audience, with the barely hidden subtext of “you freeloading scum.”
The shift towards chiplet architecture is inevitable for almost all high-end CPUs/GPUs, accelerators, and networking silicon vendors. It is not a question of ‘if’ but ‘when’.
The Global Coalition on Telecommunications (GCOT) purports to be about synching up how the five countries approach telecoms. The scope of corporation includes information sharing, joint R&D, funding alignment, the development of standards, skills, supply chain diversification, security, and 6G, so says the release.
Securing mainframes remains top of mind, with 61% of mainframe and IT professionals ranking security as the top problem they are facing, according to BMC’s annual survey of mainframe users for 2023.
Gartner has raised the specter of departments outside of tech running their own IT functions under the guise of low-code and digital democratization.
Though it’s tasked with regulating the information technologies of the future, the Federal Communications Commission remains stuck in the past.
Cybercriminals are leveraging the growing popularity of artificial intelligence to perpetrate attacks, capitalizing on the surge in interest following the release of chatbot technologies like ChatGPT.
In response to five class-action lawsuits, a Washington appeals court has decided that Honda and several other automakers did nothing wrong by storing text messages and call records from connected smartphones.
Even as the notoriously risk-averse Food and Drug Administration embraces artificial intelligence, however, another federal regulatory agency—the Securities Exchange Commission—has cracked down on AI.
Tracked as CVE-2023-23583 (CVSS score: 8.8), the issue has the potential to “allow escalation of privilege and/or information disclosure and/or denial of service via local access.”
Terry Slattery joins Tom and Russ to continue the conversation on network automation—and why networks are not as automated as they should be. This is part one of a two-part series; the second part will be published in two weeks as Hedge episode 204.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-203.mp3download
transcript
Year after year network engineering media, vendors, and influencers talk about the importance of network automation—and yet according to surveys, most network operators still have not automated their network operations. In this episode of the Hedge, part 2 of 2, Chris Grundemann and Scott Robohn join the Hedge to give their ideas on why network automation isn’t happening, and how we can resolve the many blockers to automation.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-194.mp3
However, unlike most of the world, which is taking a flexible, adaptive Zero Trust Model approach of continuous controls for cyberdefense, the EU government is pursuing a vastly expanded version of the failed Common Criteria certification model coupled with regulatory extremism and exceptionalism strategies.
Enabled by SD-WAN, internet-first networking strategies are now the order of the day for wide-area connectivity and have been for some time.
The European Union’s Digital Services Act comes into effect today, August 25, and it’s unclear if the hoped-for consumer protections are going to have their desired impact.
Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows.
I like monitoring stuff. That’s what I do at work and when my home ISP started giving me random problems I decided it would be nice to monitor my home network as well.
Although we cannot fix humans, we can put extra measures in place to minimize the risk of having wrongly issued certificates operational in the wild. In comes Certificate Transparency (CT), a concept introduced by Google in 2013.
Year after year network engineering media, vendors, and influencers talk about the importance of network automaion—and yet according to surveys, most network operators still have not automated their network operations. In this episode of the Hedge, part 1 of 2, Chris Grundemann and Scott Robohn join the Hedge to give their ideas on why network automation isn’t happening, and how we can resolve the many blockers to automation.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-193.mp3
download
To find out more about the Network Automation Forum and their upcoming meeting, check out their web site.
Addiction and addiction recovery are not a "normal" Hedge topic, but addiction afflicts many people in Information Technology. We're all "hard driven" types, who feel failure keenly, and we tend to spend more time working than is probably healthy for us. Brett Lovins has been through addiction and recovery, and joins Tom Ammon, Russ White, and Eyvonne Sharp to talk about this high impact topic.
While power is crucial for data centers, it's also something network engineers don't talk about a lot. In this episode of the Hedge, Sarah Martin from HED Design joins us to talk about the history, current state, and future of power in data centers.
What impact would Electromagnetic Pulses (EMP) from a large-scale sunspot have in the modern world? One this episode of the Hedge, Ulrich Speidel and Jaap Akkerhuis join George Michaelson and Russ White to discuss space weather and its impact on communication systems. Note this is a joint episode with Ping, APNIC's podcast. Because this is a joint recording, the format is a little different than normal.
When network engineers think of a data center, we think of fabrics and routers and switches. There is a lot more to a data center, though—there is power, building construction, environmentals, and a lot of others. What possible jobs are out there in the data center space for people who want to work in IT, but don't either want to code or build networks? Carrie Goetz, author of Jumpstart Your Career in Data Centers joins Tom Ammon and Russ White to tell us about a few, and about the importance of other careers in the data center.
It's the last show of the month, which means it is time for a roundtable! Today we are discussing three news stories, including Amazon's Sidewalk Labs, a court case in California involving Cisco and the Great Firewall of China, and yet another data breach.
Buffer bloat causes permanent delay at multiple points along the path between a server and client—but it is hard to measure and resolve. Bjørn Teigen joins Tom and Russ on this episode of the Hedge to discuss the problem, solutions based in routers, and research into how to solve the problem at the host. You can find Bjørn's recent paper in this area here, and he blogs here.
The idea of a root of trust is somewhat foreign to network engineers—what is it, and why would it be important? Michael and Marcus from Hedgehog join Tom Ammon and Russ White to discuss how hardware roots of trust work, what problems they are designed to solve for network hardware, and the current state of this technology.
To help organizations avoid the potential perils that the .zip and similarly confusing ngTLD extensions (i.e., .app, .cab, .cam, .mobi, .mov, .pub, .rip, and .win) may pose, the WhoisXML API research team scoured the DNS for such domains created between 1 January and 31 May 2023 to see if any of them should be considered suspicious and treated with caution.
When you write some code and put it on a spacecraft headed into the far reaches of space, you need to it work, no matter what. Mistakes can mean loss of mission or even loss of life.
That’s right, no need to be picky — any CA can sign any domain name, so you can pick from literally hundreds since that is the number of trusted CA root certificates baked into your browser or included in most operating systems.
Computers only have a history stretching back some 60 or 70 years—and yet much of that history has already been lost in this mist of time. Are we focusing so deeply on the future that we have forgotten our past? What might we learn from the past, even the recent past, and how does forgetting our past impact the future. Federico Lucifredi joins Tom Ammon and Russ White to discuss some of his projects finding, repairing, and operating old personal computers.
It's roundtable time at the Hedge! This month, Tom, Eyvonne, and Russ kick off the conversation talking about the value (and some dangers) of open source software. Fake Agile is up next—what does it really mean to be agile, and can organizations use agile tools without being truly agile? Finally, cloud computing, vendors, and skills come to the fore.
What's next for network engineering? While we normally think of answers to this question in terms of technology, Mike Bushong joins this episode of the Hedge to argue the future is in operations—and operational excellence. Join Mike, Tom, and Russ as we discuss how the importance of operating a network is impacting the design of hardware, software, and networks.
Artificial intelligence (or, at least, the Chat GPT program) makes stuff up, out of what seems to be a spirit of fun, or perhaps a desire to please.
The ad-tech industry is incredibly profitable, raking in hundreds of billions of dollars every year by spying on us.
This memo contains the thoughts and recountings of events that transpired during and after the release of information about the NSA by Edward Snowden.
First, there have been advances in capabilities for post-quantum computing. Second, the National Institute of Standards and Technology (NIST) will complete final rounds for selection of these new cryptographic algorithms in 2024.
Organizations get bombarded with countless attacks from every direction, including via their supply chain. FortifyData’s recent record of the top third-party data breaches in 2023 brings to light how multidirectional threat sources can be.
A report from Verizon Business's 16th annual Data Breach Investigations Report (DBIR) reveals a startling surge in the frequency and cost of cyberattacks.
The Internet has become very centralized in the last five to ten years, causing a lot of concern among among many in the Internet community. While we cannot turn back the clock, we can try to chart a path forward to reduce the tendency towards centralization. Join Dirk Dirk Kutscher, Lixia Zhang, Alvaro Retana, Tom Ammon, and Russ White on this episode of the Hedge as we discuss the work the Distributed Internet Research Group (DINRG) is doing to create a more decentralized Internet.
That is because IoT is a fundamentally different technology than existing systems—a technology with plenty of attack surfaces. Each sensor and device connected to an IoT network presents a possible security risk, opening up an attack vector into an individual or company's hardware, software, and/or data.
Like their mathematical counterparts, the unsolved problems in brand protection will present significant benefits for any service providers able to develop and offer comprehensive solutions.
The most annoying thing about ReDoS vulnerabilities is that they’re not caused by careless coding but by an obscure edge case in the regex engine. I place the blame squarely on the regex library and not the developer who used it.
I've updated the generic icon set I use in all my presentations to include a Wi-Fi router, an antenna, and a few other things. You can always find them on this page, as well.
When processing multiple transactions at the same time, the database needs to decide whether the transactions can see each other’s changes, how much they can see, etc.
While there are an estimated 30,000 daily cyber attacks on business websites, there are roughly ten times as many attacks against social media accounts every single day, equating to roughly 1.4 billion accounts every month.
Resecurity threat researchers discovered a new ransomware they’ve dubbed “Nevada” being sold on the RAMP underground community.
It's time for Eyvonne, Tom, and Russ to talk about some current stories in the world of networking—the May roundtable. Yes, I know it's already June, and I'm a day late, but ... This month we talk about the IT worker shortage, Infiniband, and the "next big thing."
So draw up a place to sit and hang out with us as we chat.
The net’s long decline into “five giant websites, each filled with screenshots of the other four” isn’t a mystery. Nor was it by any means a forgone conclusion. Instead, we got here through a series of conscious actions by big businesses and lawmakers that put antitrust law into a 40-year coma.
The federal government should not have warrantless, backdoor access to private communication systems like Twitter.
My experiences in the War on Terror provided me with a glimpse of the AI revolution that is now remaking America’s political system and culture in ways that have already proved incompatible with our system of democracy and self-government and may soon become irreversible.
America has a monopoly problem. Most industries in the United States have consolidated in recent decades,1 and markups and profits have dramatically increased since around 1980.
If the fabric is error-free, and can send and receive between hosts at interface speed with no buffering or delay, a case can be made for a different kind of stream protocol, which implies perhaps less overhead per host to manage that stream of data.
The real problem Altman is trying to solve—and everyone knows this—is how to use the power of the federal government to prevent competitors from upsetting OPENAI’s current market position.
Even if we assume that the tendency towards pseudoscience and poor research isn’t inherent to the culture of AI research and just take for granted that, in a burst of enlightened self-awareness, the entire industry is going to spontaneously fall out of love with nonsense ideas and hyperbolic claims, the secrecy should still bother us.
As Tesla CEO and Twitter mogul Elon Musk tells it, I may be unproductive — despite the multiple articles and extensive work I produce each week — and immoral.
Communities installing WiFi that spans an entire property. From tennis courts to pools, from fields to lakes, Hotwire says the new hybrid work-from-home lifestyle means homeowners are working from everywhere within a community.
BGP is the Internet’s de facto routing protocol – but relatively few have a deep understanding of its vulnerabilities.
Since its invention by Bob Metcalf and David Boggs back in 1973, Ethernet has continuously been expanded and adapted to become the go-to Layer 2 protocol in computer networking across industries.
However, it is important to acknowledge that passwords have long been identified as one of the weakest elements in the security chain.
Ready to live on the edge? In my last network design post we talked about remote access VPN but in this instalment, we will take a detailed look at designs for the network edge.
Intel has launched a field-programmable gate array—Agilex 7 with R-Tile—that features PCIe 5.0 and CXL capabilities for processing networking workloads.
Speaking of the existential threat of AI is science fiction, and bad science fiction for that matter because it is not based on anything we know about science, logic, and nothing we even know about ourselves.
In a recent workshop I attended, reflecting on the evolution of the Internet over the past 40 years, one of the takeaways for me is how we’ve managed to surprise ourselves in both the unanticipated successes we’ve encountered and in the instances of failure when technology has stubbornly resisted to be deployed despite our confident expectations to the contrary!
In this episode of PING, Verisign Fellow Duane Wessels discusses notable changes in the DNS root zone in the last 13 years.
As technical people, we spend immense time and energy mastering the nuances of specific technologies. Esoteric knowledge is our currency, and we often measure our personal value against the yardstick of technical nuance
The term ‘platform engineering’ refers to the activity of designing and developing toolchains and internal work processes that enable the employees of an organisation to be self-sufficient in all software engineering activities.
Open source repositories — such as Python’s PyPI, the Maven Java repository, and the Node Package Manager (npm) for JavaScript — typically have a skeleton crew of engineers and volunteers to manage and secure the infrastructure
What has been happening in the world of network automation—and more to the point, what is coming in the future? Josh Stephens from Backbox joins Tom Ammon, Eyvonne Sharp, and Russ White to discuss the current and future network operations and automation landscape.
You can read Backbox’s report on network automation here.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-180.mp3download
When it comes to understanding what exactly confidential computing entails, it all begins with a trusted execution environment (TEE) that is rooted in hardware.
So, just for fun, we pulled out the trust Excel spreadsheet and tried to estimate what the feeds and speeds of the MI300 and the MI300A GPUs, the latter of which will be at the heart of the El Capitan system might be. Y
The popular PC storage manufacturer, Western Digital, has confirmed that it experienced a network security breach earlier this year, in which an unauthorized third party gained control of several of its systems.
How bad is the human security weakness problem? Verizon’s 2022 Data Breaches Investigations Report says 82 percent of data breaches have human involvement.
On 13 April 2023, through our recently launched Threat Intelligence Data Feeds (TIDF), we identified more than 1 million suspicious and malicious domains that figured in phishing, malware distribution, spam, and other cyber attacks, such as brute-force and distributed denial-of-service (DDoS) attacks.
Although honeypots are an effective solution for tracking attackers and preventing data theft, they have yet to be widely adopted due to their setup and maintenance difficulties.
If you want to get a sense of what companies are really doing with AI infrastructure, and the issues of processing and network capacity, power, and cooling that they are facing, what you need to do is talk to some co-location datacenter providers.
IBM and its IT infrastructure spinoff Kyndryl were this week taken to court by an axed exec who had put decades of her life into the tech giant.
The advancements of coherent passive optical networks (CPON) will lead to a robust and noticeable boost to the customer experience in businesses and the home.
Publicly listed technology companies under pressure to make deep job cuts can underestimate the often negative impacts redundancies may cause, both financially and culturally, as well as the harm to shareholder returns.
It’s easy to think high-tech companies have a security advantage over other older, more mature industries.
A Social engineering attack is the process of exploiting weaknesses in human psychology to manipulate and persuade others to perform in a way that is harmful. Prior to the digital age, criminals would carry out these attacks in person, in what was known as a confidence game.
WhoisXML API sought to discover how the closure of the two banks and similar recent events are reflected in the DNS.
In early March, my colleague Merve Hickok testified before the House Oversight Committee at the first hearing on AI policy in this Congress.
SONiC is a long-standing open source network operating system. While it cannot (quite) compete with a full-blown commercial network operating system, SONiC+FR/R can solve a lot of the problems network operators face today. Mike V Dvorkin joins Tom Ammon and Russ White to talk about the current state and future of SONiC.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-179.mp3download
The Internet of Things is still “out there”—operators and individuals are deploying millions of Internet connected devices every year. IoT, however, poses some serious security challenges. Devices can be taken over as botnets for DDoS attacks, attackers can take over appliances, etc. While previous security attempts have all focused on increasing password security and keeping things updated, Kathleen Nichols is working on a new solution—defined trust transport in limited domains.
Join us for this episode of the Hedge with Kathleen to talk about the problems of trusted transport, the work she’s putting in to finding solutions, and potential use cases beyond IoT.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-178.mp3download
You can find Kathleen at Pollere, LLC, and her slides on DeftT here.
Cybersecurity researchers have uncovered weaknesses in a software implementation of the Border Gateway Protocol (BGP) that could be weaponized to achieve a denial-of-service (DoS) condition on vulnerable BGP peers.
Enter OpenTelemetry, which provides a vendor-neutral standard for telemetry data, as well as the necessary tools to collect and export data from cloud-native applications.
DevEx drives business performance through increased efficiency, product quality, and employee retention.
Last January, thousands of users of two popular open source libraries, “faker” and “colors,” were shocked to see their applications breaking and showing gibberish data after being infected with a malicious package.
Netskope, a leader in Secure Access Service Edge (SASE), today unveiled new research confirming that attackers are finding new ways to evade detection and blend in with normal network traffic using HTTP and HTTPS to deliver malware.
In keeping with WhoisXML API’s mission to make the Internet a transparent and safe place for users, we expanded the list of IoCs in hopes of identifying social media pages that could already be serving or used to serve as fraud vehicles.
According to research carried out across a sample of over failed 17,000 hard drives, the failure occurred after only two years and 6 months. Does that make the HDD one of the weakest components inside your PC?
The Global Digital Compact (GDC) is a proposed initiative by the United Nations (UN) to address the global challenges and opportunities arising from the digital revolution.
What makes Wi-Fi 6E such a game changer is that it maximizes both user and IT experiences by offering enterprises more capacity and increased channel width.
Are you responsible for the safety and reliability of IT infrastructure and applications? You’ll absolutely need regular and accurate assessments.
BEC scams are bound to continue affecting organizations worldwide, given the continued rise in the number of complaints the FBI IC3 receives with each passing year.
One might make a de minimis argument that there is so much training data that the amount of any particular input document in any output is too small to matter.
On the 18th and 22nd (Thursday and Monday) I’m teaching the two-part series on Data Center Fabrics and Control Planes over at Safari Books Online. This is six hours total training covering everything from Clos fabrics to eVPN.
Register here.
If you register for the course you can access a recording at a later date. From Safari:
This class consists of two three-hour sessions. The first session will focus on the physical topology, including a short history of spine-and-leaf fabrics, the characteristics of fabrics (versus the broader characteristics of a network), and laying out a spine-and-leaf network to support fabric lifecycle and scaling the network out. The first session will also consider the positive and negative aspects of using single- and multi-forwarding engine (FE) devices to build a fabric, and various aspects of fabric resilience. The second session will begin with transport considerations and quality of experience. The session will then consider underlay control planes, including BGP and IS-IS, and the positive and negative aspects of each. Routing to the host and the interaction between the control plane and automation will be considered in this session, as well. EVPN as an overlay control plane will be considered next, and finally the relationship between security and control plane design will be examined.
The past decade has seen numerous reports of so-called cloud “repatriations”–the migration of applications back to on-premises venues following negative experiences with, or unsuccessful migrations to, the public cloud.
While agile software development is often associated with specific methodologies, such as Scrum, Kanban, and Extreme Programming it is not enough to just follow such a methodology.
The heady, exciting days of ChatGPT and other generative AI and large-language models (LLMs) is beginning to give way to the understanding that enterprises will need to get a tight grasp on how these models are being used in their operations or they will risk privacy, security, legal, and other problems down the road.
When deploying changes to an application, there are several strategies you can use.
The sad story of OAuth 2.0 and open standards.
Payment Card Industry Data Security Standard (PCI DSS) was developed and established to foster a safe cardholder data practice in the industry.
While the DNS (Web2) has been a reliable and trusted internet standard for decades, Web3 platforms (such as ENS, Handshake and Unstoppable) are a relatively new technology deployment that presents unique and different features.
In this blog post, we at the University Grenoble Alpes (France) analyse that event from the RIPE Atlas point of view and, more broadly, evaluate the extent of DNS manipulation when sending queries to DNS root servers.
Amazon Web Services has spent the past decade and a half testing this principle, and is being tested now as companies are skittish that national economies are going to push the world into recession.
Bluetooth, the technology that powers the wireless data connections between billions of devices, is going to become even more capable, with big increases planned for the data bandwidth of Bluetooth LE.
Just a few short years ago, lateral movement was a tactic confined to top APT cybercrime organizations and nation-state operators. Today, however, it has become a commoditized tool, well within the skillset of any ransomware threat actor.
Unsuspecting website visitors are often unaware when they have landed on a spoofed page or are re-directed to malware-hosting web servers designed to steal their sensitive data and information.
Ever wondered where the personally identifiable information (PII) phishers steal from victims end up? More likely than not, they’re put up for sale on the ever-growing number of online stolen card shops.
So when we got a call last week from someone asking us how big are Nvidia’s server and networking businesses in a finer-grained detail than just the broad “Compute & Networking” and “Datacenter” categories that Nvidia talks about, we didn’t hesitate to load up our spreadsheet for Big Green and take a stab at it.
Satellite comms firm Viasat has successfully hurled ViaSat-3 Americas into orbit, the first of three satellites designed to offer high speed global broadband coverage.
On this episode of the Hedge, Mike Dvorkin joins Russ White to talk about the cloud, tradeoffs, rethinking the cloud value proposition, and the road to becoming an architect. A key point—it is harder to fix hardware in production than it is to fix software in production.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-177.mp3download
There has always been some concern about undersea fibers. Countries fear that sabotage of the fibers connected to their shores could result in being isolated from the Internet.
Do your employees use unauthorized SaaS apps? The average organization has over 100 SaaS apps, many unsanctioned by IT, posing a serious security risk.
A proposed permanent network of electromagnetic monitoring stations across the continental US, operating in tandem with a machine learning (ML) algorithm, could facilitate accurate predictions of geomagnetic disturbances (GMDs).
We may be seeing an equally dramatic transformation of chip design right now, this time with the use of AI to drive designs.
But for now it”s exciting to see what ChatGPT has already been able to do. At some level it”s a great example of the fundamental scientific fact that large numbers of simple computational elements can do remarkable and unexpected things.
He”s sharing the story of JSON, his discovery of JavaScript”s good parts, and his approach to finding a simple way to build software.
Back in January of this year, we studied the infrastructure of Ducktail, a malware that trailed its sights on Facebook business owners and advertisers.
The Philippines is an archipelago comprising three major island groups: Luzon, Visayas, and Mindanao with 7,641 islands at high tide and a population of 113 million spread across roughly 2,000 of those islands.
Cable operators are eager to take advantage of the forthcoming DOCSIS 4.0 rollout, as a survey from ATX Networks found nearly half (48%) of cable companies plan to activate DOCSIS 4.0 in their hybrid-fiber coaxial (HFC) networks by the end of 2025.
While Prolexic’s overall service and mitigation stacks are not changing, the new offering allows customers to define and adjust their own access control rules and provides analytics of existing ones.
However, alongside these more “traditional” or perhaps “structural” security concerns that cannot be swiftly shaken off, countries in the region have increasingly had to deal with the additional burden of cybersecurity threats.
Distributed denial-of-service (DDoS) is the attack method businesses are most concerned about, believing it will have the largest impact on the business.
A prominent example of a PET is fully homomorphic encryption, often mentioned in the same breath as differential privacy, federated learning, secure multiparty computation, private set intersection, synthetic data, zero knowledge proofs or trusted execution environments.
We already know that software can displace people. In 2019, Wells Fargo predicted that efficient software would replace 200,000 jobs in the banking industry.
There were a few efforts to flesh out what 6G might look like but they didn”t really get much further than “5G done properly” with a bit of utopian AI and ubiquitous sensing thrown in to sex it up a bit.
It’s time for the April Hedge roundtable! This month Eyvonne, Russ, and Tom are talking about OpenAI, the hype around AI, the “pause letter” and the lack of a real conversation, and the rising costs of building and operating a data center. As always, let us know if you have topics you’d like to hear us talk about, or guests you’d like to hear.
Thanks for listening!
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-176.mp3download
Tech companies are embedding these deeply flawed models into all sorts of products, from programs that generate code to virtual assistants that sift through our emails and calendars.
On the morning of October 14, 2020, I caught a firsthand glimpse of what itâ€s like for a traditional media outlet to go up against the vast agglomeration of economic and digital power known as Big Tech—and to do so without the benefit of what economist John Kenneth Galbraith defined as countervailing power.
Former Google CEO Eric Schmidt said that artificial intelligence could hurt American politics and needs to be reined in.
The National Assemblyâ€s decision to greenlight the bill followed months of debate about one section in particular — Article 7 — which permits the use of AI-assisted video surveillance technology by law enforcement during and up to six months after the Games.
Calling a business, civic organization, or even school a family may be well-intended but comes with unintended consequences that do an injustice to the necessary commitments that should be made to our actual families.
If normal means mass layoffs, empty office buildings, confusing return-to-office policies, AI panic, and the whiplash-y feeling that just when employees were starting to redraw some boundaries between work and home, an economic downturn has forced society to fret even more about work.
On April 11th, 2023, China’s top internet regulator proposed new rules for generative AI.
Many people stare down face recognition technology every day as they unlock their smartphones. But this technology also has applications in peopleâ€s places of work.
A variety of digital tools are being used to monitor workers across various industries, some of which use artificial intelligence (AI) to try to gain insights into workers†performance.
But increasing use of AI by employers has led some to question the fairness, quality and accuracy of hiring decisions made in this way – even as others tout AI as an improvement over human involvement.
In a 2023 survey of cybersecurity leaders, 51% said they believe an AI-based tool like ChatGPT will be used in a successful data breach within the next year.
When folks ask me for an estimate of the cost of building aerial fiber, I always say that the cost is dependent upon the amount of required make-ready needed. Make-ready is well-named – itâ€s any work that must be done on poles to be ready to string the new fiber.
On 10 February 2023, Reddit announced it suffered a security incident where a phishing campaign led an employee to a website that imitated the network’s intranet gateway.
This video looks at various Kubernetes vulnerabilities and their severity scores to help you understand how to evaluate CVEs so you can prioritize remediation. It also shows different options and sources of CVEs.
It is almost 25 years since the Internet was privatized by the U.S. government. ICANN was formed by Esther Dyson and Jon Postel as a California-based non-profit with the responsibility to administer the Internet.
The series glamourized Annaâ€s fraudulent endeavors and depicted her as clever, interesting, and mysterious; someone who we wanted to figure out and understand.
Even if cyber attack tactics, techniques, and procedures (TTPs) have become increasingly sophisticated over the years, age-old phishing remains the most-used attack vector to this day.
On a specific date and time in 2038, the old-world model of time in 32 bits as a positive integer value ‘wraps around†(when an integer value is too big for the container assigned in the computer) and returns nonsensical results.
Today, Microsoft is excited to announce that we are shifting to a new threat actor naming taxonomy aligned to the theme of weather.
From the coverage that ChatGPT, developed by OpenAI, has been receiving since its launch in November 2022, you would be forgiven for thinking that is the only technology story around.
The Domain Name System (DNS) root zone will soon be getting a new record type, called ZONEMD, to further ensure the security, stability, and resiliency of the global DNS in the face of emerging new approaches to DNS operation.
When the economy starts contracting, career advisors start talking about the importance of “soft skills.” What are “soft skills,” exactly—and why are they “soft?” Mike Bushong joins Tom Amman and Russ White to talk about why these skills are important, why they are not “soft,” and how we should talk about people skills instead. They are superpowers,” and there isn’t anything “soft” about them.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-175.mp3
download
The Cisco Certified Design Expert (CCDE) exam was launched in 2007, but not many people know what the main objectives of the certification were at the time. Who better to enlighten us on some of the thought process and reasons behind the exam being created than one of the original development team? In this podcast, we are extremely humbled to be joined by networking industry legend, Russ White who spoke about his career, how he got into networking and some insights on the CCDE concept and how it came to fruition in the early 2000s!
One of the biggest advantages of IPv6, from a network administration perspective, is the ease of renumbering. While IPv4 networks can be renumbered using DHCP, the process of changing the address of every device on a network is always fraught with unexpected challenges. People (like me) have a habit of manually assigning printers and network attached storage devices a fixed address so they will be easy to find and use.
ChatGPT has broken through the hype barrier and brought AI hype to the larger world. But what does AI mean to network engineers? We’ve talked about AI driven network management for years, and commercial products abound, but what does it really mean to move from the automation driven configuration to AI driven decision-making? Javier Antich joins Tom Ammon and Russ White for this episode of the Hedge to talk about cloud AI for network engineers.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-174.mp3download
You can learn more about cloud AI in Javier’s new book.
Four major US mobile operators have agreed to a series of undertakings designed to address concerns over airline safety and to allow them to use their C-band spectrum to its full extent.
The result of this effort, Intel Max Series GPU formerly known by the code name Ponte Vecchio, packs 100 billion transistors and 47 tiles onto five process nodes. Beyond that, they include two packaging innovations, EMIB 2.5D and Foveros 3D technology, and stack tiles atop one another for greater processor density.
According to various statistics, there are somewhere around 330 billion emails being sent every day, approximately 3.82 million per second. Who reads all these emails?
In the ongoing AI revolution, images and text are yesterdayâ€s news, leaving audio as a new frontier to explore, and incredible progress has already been made. Here are six examples of AI audio generation that will leave you speechless.
The secret to unlocking the full potential of quantum networking may be hiding at the center of a diamond, according to Amazon Web Services. This week, AWS popped the question to De Beers subsidiary Element Six in the hope of finding it.
Year-over-year global VC funding dropped precipitously in Q1 2023, with at least $76 billion (£61 billion) doled out to companies at all startup stages. That may sound like a lot but it’s a 53 percent drop from the same time last year, reports funding tracker Crunchbase.
People once prioritized logging in as much as logging out, but now, according to freelance UI designer Jesse Showalter, access to content is of utmost importance, even at the cost of constantly sharing our data. Logging out, by contrast, carries little value for companies or consumers.
Shorter certificate life cycles bring about benefits to improve security and reduce the risks associated with long-lived certificates.
Kumorai is a startup that aims to simplify the deployment and operation of compute, networking, and security infrastructure across public clouds.
Humans have always been interested in making machines that display intelligence.
One of the most effective ways for CISOs and CIOs to make the best use of their limited resources to protect their organizations is by conducting a cyber risk assessment.
Query name minimization (qmin) is a privacy feature that limits the amount of information sent in DNS queries to enhance privacy (RFC 9156).
Today, we are excited to announce the deps.dev API, which provides free access to the deps.dev dataset of security metadata, including dependencies, licenses, advisories, and other critical health and security signals for more than 50 million open source package versions.
Analysts from Dellâ€Oro Group warned 2023 could be ripe for CPE inventory corrections, thanks in part to lower than expected broadband deployment targets and a slowdown in activity that normally drives broadband growth.
Ciena is taking a new approach to routing with its freshly unveiled WaveRouter platform, aiming to meet the demands of the converged metro network in the multi-cloud era.
What it is about is how very few companies have access to the raw AI models that are transforming the world, the curated datasets that have been purged of bias (to one degree or another) that are fundamental to training AI systems using machine learning techniques, the model weights and checkpoints that are key to tuning a model, and the money to either build or rent the capacity to bring the neural network software and the data together to train an AI model.
Intel has announced a new processor with 144 cores designed for simple data-center tasks in a power-efficient manner.
Data center fires aren’t common, but they can be devastating. As use of lithium-ion batteries grows, enterprises need to be aware of the risks, Uptime Institute warns.
Russian intelligence services, together with a Moscow-based IT company, are planning worldwide hacking operations that will also enable attacks on critical infrastructure facilities.
Back in the old days, there was a CPU and chip designers crammed everything into that single CPU, which made sense for the greatest number of customers offset against the additional cost of adding extra functionality.
A picture is said to be worth a thousand words. A graph can be worth a thousand numbers.
Business software often is hard to implement. That means it takes a lot of work to get it into a usable state after purchasing it.
Quantum computing as a term has been banded around for years now as something between bleeding edge tech and theoretical academia. Itâ€s often sprinkled in when futurologists vaguely sketch out what the future might look like, along with neural lace brain attachments and nano-robots.
The Threat Intelligence Platform (TIP) research team used these as jump-off points to scour the DNS for connected domains and IP addresses that could be part of the ransomware affiliates†infrastructure.
Due to their powerful computing capabilities, the Cloud Security Alliance (CSA) has estimated that by April 2030, RSA, Diffie-Hellman (DH), and Elliptic-Curve Cryptography (ECC) algorithms will become vulnerable to quantum attacks.
The central bankers of the world want to curb inflation by putting a serious crimp in demand, and it looks like they may get what they want – sort of – in 2023 when it comes to datacenter infrastructure.
Liberty-owned UK broadband pusher Virgin Media has fallen on its face this morning, with users across the country reporting complete broadband failure for a number of hours, among them some of the reporters on this news desk.
Multicast hasn’t ever really “gone viral” (In modern terms!) throughout the Internet—in fact, it’s not widely used even in networks supporting enterprises. why not? Join Dirk Trossen, Russ White, and Tom Ammon as we discuss the many facets of multicast, and what the future holds.
Dirk’s paper on multicast can be found here.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-173.mp3download
Last year, around the Thanksgiving holiday, Ohio businessman Michael Larkin received a request for video from his Amazon Ring security system from Hamilton city police.
Once upon a time there live a tribe who lived on the plains. They were an adventurous tribe, constantly wanting to explore. At night they would see the moon drift lazily overhead, and became curious.
If I’ve written in this space before about “convenience of the employer” rules a lot of late, it’s because they are so pernicious. These rules essentially require taxpayers who switch from working in-person in one state to working remotely in another to continue paying income taxes to the state they used to work in, not the one they currently work in.
A federal judge yesterday ruled that Google intentionally destroyed evidence and must be sanctioned, rejecting the company’s argument that it didn’t need to automatically preserve internal chats involving employees subject to a legal hold.
From a national security perspective, banning TikTok seems to be a reasonable step in protecting U.S. citizens. After all, TikTok is merely a video sharing app that is widely used by children; thus, its ability to harm us far outweighs its utility.
And so as he prepared to face the powerful House Energy and Commerce Committee, Chew enlisted all the right people to help him get ready.
The newest generation of artificial intelligence products has inspired waves of excitement and funding since this past fall, when generative-A.I. apps like ChatGPT and DALL-E 2 debuted. But there’s a reason that many of the use cases the technology’s boosters have suggested feel like fixes in search of problems. This is solutionism.
Late posting due to a conference this weekend …
The rapid rise in IT power density, however, now means that plausible design assumptions regarding future power density and environmental conditions are starting to depart from these standard, narrow ranges.
Globalization is over, at least for the chip industry, and this will mean higher chip prices, according to semiconductor contract manufacturer giant TSMC.
Are your online customers being lured away? Learn why retailers must prevent audience hijacking tactics to keep shoppers focused and not distracted by unwanted or malicious in-browser interruptions.
I surveyed the status of RPKI ROA registration for IXPs operating in the Asia Pacific region and several IXPs in the European region on 17 February 2023. My first impression is that both regions lack a sense of unity, with RPKI ROA registration being inconsistent.
Active DNS measurement is fundamental to understanding and improving the DNS ecosystem. However, the absence of an extensible, high-performance and easy-to-use DNS toolkit has limited both the reproducibility and coverage of DNS research.
A group monitored as REF2924 by Elastic Security Labs is wielding novel data-stealing malware — an HTTP listener written in C# dubbed Naplistener by the researchers — in attacks against victims operating in southern and southeast Asia.
The number of victims affected by a mass-ransomware attack, caused by a bug in a popular data transfer tool used by businesses around the world, continues to grow as another organization tells TechCrunch that it was also hacked.
Last week I shared how IPng Networks deployed a loadbalanced frontend cluster of NGINX webservers that have public IPv4 / IPv6 addresses, but talk to a bunch of internal webservers that are in a private network which isnâ€t directly connected to the internet, so called IPng Site Local [ref] with addresses 198.19.0.0/16 and 2001:678:d78:500::/56.
The prized retro audio components are mostly manufactured in Russia and China. Now, a small Georgia company is rebooting US production.
Researchers recently spotted phishing attacks using supposed ChatGPT sites to phish for personally identifiable information (PII), specifically credit card data.
Since cellular communications†inception, SIMs have been required so that remote devices can achieve authentication when connecting to a network. Protecting the security credentials stored has been fundamental, yet these must be easily issued to subscribers for placing into their devices.
The most common transport encryption protocols are Secure Sockets Layer (SSL) and its successor, Transport Layer Security (TLS).
In our latest report our head security engineer, Thomas Perkins, has revealed the excessive data collection of TikTok and that the app connects to mainland China based infrastructure.
The risk score for the average company worsened in the past year as companies fail to adapt to data exfiltration techniques and adequately protect Web applications.
This fundamental shift in policy raises a critical question: How can the government enforce such requirements? Experience across the regulatory landscape offers some cautionary lessons.
It’s roundtable time at the Hedge! Eyvonne Sharp, Tom Ammon, and I start the conversation talking about the SONiC open source NOS, and then wander into using open source, build versus buy, and finally complexity in design and deployment.
Thanks for listening–if you have an idea for a Hedge episode, would like to be a guest, or know someone you think would be a good guest, let one us know!
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-172.mp3
download
Middleboxes are used in modern networking to sniff out attack traffic (IDS), block unwanted traffic (stateful packet filters), and share load among several different servers. Encryption, however, is making it hard for the middleboxes to do their job. Paul Grubb joins Tom Ammon and Russ White to discuss zero knowledge middle boxes, which allow operators to enforce arbitrary policies on the underlying traffic of an encrypted connection without decrypting it.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-171.mp3download
To find out more about Paul’s work in this and other areas, please see Paul’s research page, this article on zero-knowledge middleboxes, and this research paper on zero knowledge middle boxes.
Fujitsu’s Arm-based A64FX processor may have driven the most powerful supercomputer in the world, but it looks like its successor will be a more general-purpose chip that will focus on energy efficiency.
Hi everyone! In this article we’re going to take a look at the different rendering pattern options available nowadays for web applications.
Spurred by unprecedented unit pricing, the IPv4 market in North America experienced its second-best year ever in market history.
Getting a new technology out to consumers will usually require good people and boat loads of resources – including money. Generally, lots of money.
The Global Domain Report 2023 shows the domain industry is absorbing the shock waves, proving that the market is resilient and domains are solid assets for digitalization.
A proposed rule change at the Federal Communications Commission (FCC) would expand the definition of a data breach for communications carriers. If approved by the agency, the rule would cover any incident that affects the confidentiality of customer information, even if no harm to customers results.
Threat actors with a connection to the Chinese government are infecting a widely used security appliance from SonicWall with malware that remains active even after the device receives firmware updates, researchers said.
Akamai has just mitigated a distributed denial of service (DDoS) attack of epic proportions. While it was short-lived, it was very intense, and it most likely could have easily taken the target server offline.
While compatible with RDP connection and local desktop logins, they offer no protection to remote command line access tools like PsExec, Remote PowerShell and their likes.
Is the current arrangement of keys on the keyboard the most efficient and intuitive solution? Open source aims to address this question with a circular one-handed keyboard.
Software-defined WAN offers a lot of potential benefits including price, efficiency, and performance, but itâ€s not right for all sites.
But given the expansive capabilities of today’s technology, combined with how integrated it is in every aspect of our lives, there’s a danger of either purposefully or inadvertently collecting unnecessary and private data.
You may be wondering what folks mean when they talk about a [BGP Free Core], and also you may ask yourself why would I decide to retrofit this in our network.
To that end, three vendors have announced new capabilities in the high-speed networking game. So, letâ€s run them down.
Privacy experts can now rely on a new standard, the ISO/IEC 27559:2022 privacy-enhancing data deidentification framework, in an area that has been the subject of much discussion and development.
Artificial Intelligence is being heavily hyped right now, especially in light of the newer generative AI systems (like ChapGPT). What is the reality behind the hype? Jonathan Bartlett, fellow at the Discovery Institute, joins us for a discussion on AI reality for this episode of the Hedge.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-170.mp3download
I’m teaching How the Internet Really Works over on Safari Books Online on the 24th of March—in a couple of weeks. From the description:
This live training will provide an overview of the systems, providers, and standards bodies important to the operation of the global Internet, including the Domain Name System (DNS), the routing and transport systems, standards bodies, and registrars. For DNS, the process of a query will be considered in some detail, who pays for each server used in the resolution process, and tools engineers can use to interact DNS. For routing and transport, the role of each kind of provider will be considered, along with how they make money to cover their costs, and how engineers can interact with the global routing table (the Default Free Zone, of DFZ). Finally, registrars and standards bodies will be considered, including their organizational structure, how they generate revenue, and how to find their standards.
Register here.
Featuring 18 different participating member companies, the Ethernet Alliance interoperability demo in booth #5417 spans diverse Ethernet technologies ranging from 10 Gigabit Ethernet (GbE) to 800GbE
Every few months, an important ceremony takes place. It’s not splashed all over the news, and it’s not attended by global dignitaries. It goes unnoticed by many, but its effects are felt across the globe. This ceremony helps make the internet more secure for billions of people.
Major cloud platforms, such as Google Cloud Platform (GCP), fail to adequately log the event data that could facilitate the detection of compromises and the forensic analysis during post-compromise response, according to an analysis.
Software dependencies, or a piece of software that an application requires to function, are notoriously difficult to manage and constitute a major software supply chain risk. If you’re not aware of what’s in your software supply chain, an upstream vulnerability in one of your dependencies can be fatal.
As a primary working interface, the browser plays a significant role in today’s corporate environment. The browser is constantly used by employees to access websites, SaaS applications and internal applications, from both managed and unmanaged devices.
For years, the domain registrar and Web hosting company GoDaddy has experienced a cyber barrage of extraordinary scale, it has confirmed — affecting both the company and its many individual and enterprise clients.
The massive breach at LastPass was the result of one of its engineers failing to update Plex on their home computer, in what’s a sobering reminder of the dangers of failing to keep software up-to-date.
The Cyble analysis identified 10 indicators of compromise (IoCs) for this threat—six malware hashes and four URLs.
As global conflicts continue, cyber has become the fifth front of warfare. The world is approaching 50 billion connected devices, controlling everything from our traffic lights to our nuclear arsenal.
For decades, scholars and litigators have been talking about imposing legal liability on the makers of insecure software. But the objections of manufacturers were too strong, concerns about impeding innovation were too great, and the conceptual difficulties of the issue were just too complex.
So, who will the winners and losers in this new world be? According to Entner, “itâ€s not set in stone yet.†He noted the result partially depends on whether DOCSIS 4.0 is able to deliver better reliability than DOCSIS 3.1.
A never-before-seen complex malware is targeting business-grade routers to covertly spy on victims in Latin America, Europe, and North America at least since July 2022.
Network Address translation is one of those phrases that strikes fear into the hearts of some network engineers … and joy into the hearts of others! Steinn Bjarnarson joins us to discuss the history of NAT, its uses, its misuses, and how NAT fits into the big picture of network design today. Steinn just finished writing a paper on the history of NAT.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-169.mp3download
Privacy campaigners say such systems could be used as tools of oppression. In Moscow, Vyborov and countless others now face that oppression on a daily basis.
The general problem statement for technological standards is how to avoid the power imbalance of a single source for essential goods and services; in other words, standards are a line of defense against concentration risk. Interoperability is the goal, and multiple suppliers is the proof.
In this episode, they focus particularly on how social media has become a place where predators will search and highlight childrenâ€s vulnerabilities — which so many young people share online.
Tech policy, however, has its own set of “culture war issues” including net neutrality and encryption that largely serve as a distraction from the real issues at stake. Victims of child porn are now caught in the fray.
A major escalation in official online censorship regimes is progressing rapidly in Brazil, with implications for everyone in the democratic world. Under Brazil’s new government headed by President Lula da Silva, the country is poised to become the first in the democratic world to implement a law censoring and banning “fake news and disinformation” online, and then punishing those deemed guilty of authoring and spreading it.
In addition to federal agencies, could the major accounting firms provide algorithmic audits as they do in auditing financial statements of publicly listed companies?
The click-based economy has made the world more efficient in some ways, but it turned this miraculous global information databank into a frenzied real estate auction with every website scrabbling to climb to the top of the search results, collect the most clicks, and retain the most eyeballs.
A former ASML worker accused of stealing trade secrets for advanced chip-making equipment from his employer is now suspected of spying for the Chinese government.
China’s attempts to influence technical standards groups have mostly been uncoordinated, unsophisticated and unsuccessful – but the US needs to keep watch on Beijing’s activities, especially at the International Telecommunications Union.
https://cacm.acm.org/magazines/2023/3/270206-a-turning-point-for-cyber-insurance/fulltext
Insuring against the consequences of cybersecurity seems too good to be true given the underlying problem has perplexed researchers and practitioners for going on 50 years.
https://cacm.acm.org/magazines/2023/3/270207-mapping-the-privacy-landscape-for-central-bank-digital-currencies/fulltext
Payment records paint a detailed picture of an individual’s behavior. They reveal wealth, health, and interests, but individuals do not want the burden of deciding which are sensitive or private.
https://cacm.acm.org/magazines/2023/3/270211-the-ai-tech-stack-model/fulltext
Presently, enterprises have implemented advanced artificial intelligence (AI) technologies to support business process automation (BPA), provide valuable data insights, and facilitate employee and customer engagement.
https://www.theregister.com/2023/02/22/google_milestone_quantum/
Google is claiming a new milestone on the road to fault-tolerant quantum computers with a demonstration that a key error correction method that groups multiple qubits into logical qubits can deliver lower error rates, paving the way for quantum systems that can scale reliably.
https://telecoms.com/520115/mwc-2023-whats-the-point-of-5g/
Four years into the 5G era, the technology is still struggling to find an identity. 3G was about the introduction of mobile data, which matured in the form of 4G, but what is 5G all about?
https://www.theregister.com/2023/02/24/europe_gigabit_transformation_consultation/
The European Union yesterday decided it’s time to start “laying the ground for the transformation of the connectivity sector” in the region with three initiatives – one of which codifies the idea that Big Tech should pay for the networks that carry its traffic.
https://circleid.com/posts/20230222-brand-impersonation-online-is-a-multidimensional-cybersecurity-threat
Brand impersonation happens much more often than people realize. In CSC’s latest Domain Security Report, we found that 75% of domains for the Global 2000 that contained more than six characters from the brand names were not actually owned by the brands themselves.
https://circleid.com/posts/20230221-european-union-wants-to-fix-the-gdpr
In light of this, the European Commission is proposing a new law before the summer to improve how EU countries’ privacy regulators enforce the GDPR.
https://www.bloomberg.com/news/articles/2023-03-01/chatgpt-and-ai-are-all-companies-want-to-talk-about-in-earnings-calls
A lot of the companies tossing around the phrase AI are just taking advantage of the hype. Some are speaking aspirationally about how they see AI transforming their businesses — one day, some day.
https://www.theregister.com/2023/03/03/online_privacy_tracking/
But according to a trio of privacy researchers, opting out doesn’t always work – visitor data still gets collected.
https://telecoms.com/520384/mwc-2023-recap-whats-the-point-of-telecoms/
When we asked the operator figure what the point of telecoms is they said it’s “very uncertain”. The danger of becoming a ‘dumb-pipe’ utility seems greater than ever.
https://circleid.com/posts/20230227-domains-under-the-most-abused-tlds-same-old-dns-abuse-trends
While threat actors can use any domain across thousands of top-level domains (TLDs), they often have favorites. For instance, you may be familiar with Spamhaus’s 10 most-abused TLDs for spamming.
https://www.freecodecamp.org/news/oss-security-best-practices/
Typosquatting, also known as URL hijacking, is a form of cyber attack where an attacker registers a domain name that is similar to a well-known website, but with a slight typo.
https://www.theregister.com/2023/02/28/mit_researchers_interference_busting_radios/
Radio interference can be a pain to deal with, regardless of whether it’s a rogue baby monitor interrupting your Wi-Fi or a stadium full of smartphone signals drowning each other out.
https://circleid.com/posts/20230228-internet-shutdowns-on-the-rise-worldwide-says-report
From the Middle East to South Asia to Africa, shutdowns are becoming a norm of authoritarianism—an accepted means of silencing criticism, stifling dissent, and controlling the population.
It’s roundtable time! In February’s roundtable, Eyvonne joins Tom and Russ to talk about Network as a Service, innovation, and marketing. Then we jump into the topic of the year at this point—ChaptGPT. Finally, we talk about proposals to eliminate noncompete agreements in the United States. What would this mean? Would it be better for tech, or worse?
As always, you can listen to the show on just about any podcatcher, you can listen right here, or you can download the show to listen later.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-168.mp3download
A decade ago, waferscale architectures were dismissed as impractical. Five years ago, they were touted as a fringe possibility for AI/ML. But the next decade might demonstrate waferscale as one of only a few bridges across the post-Mooreâ€s Law divide, at least for some applications.
This is not a ‘silver bullet’, however. In comparison to the sophisticated deception available in traditional IT security, deception in ICS still faces some challenges.
As a numbers guy, Iâ€m always intrigued by the Ookla Speedtest Global Index since it provides an interesting look at broadband speeds in the U.S. and around the world.
Two new separate sets of research released this month underscore real, hidden dangers to physical operations in today’s OT networks from wireless devices, cloud-based applications, and nested networks of programmable logic controllers (PLCs) — effectively further dispelling conventional wisdom about the security of network segmentation as well as third-party connections to the network.
As organizations strengthen their defenses and take a more proactive approach to protection, attackers are adapting their techniques and increasing the sophistication of their operations.
As the security of the Android Platform has been steadily improved, some security researchers have shifted their focus towards other parts of the software stack, including firmware.
Some of Europeâ€s biggest telcos have outlined their goals for the progression of Open RAN technology this year and beyond, including a suggestion of commercial launches in the near future.
Networks connected to the Internet rely on other networks – a.k.a, Autonomous Systems, or ASes – to transmit data. Consequently, the connectivity of a network depends on the connectivity of other networks. AS Hegemony is a metric to evaluate these interdependencies based on BGP data collected from public large-scale measurement platforms (RIPE RIS and Route Views).
Most recently, one tinkerer named Peter Fairlie took to YouTube armed with a Flipper Zero to answer a repeatedly asked question: can the device change a traffic light from red to green? As it turns out, the answer is “yes,” but not in the way you might think.
Roughly 109,000 technology industry employees from 392 companies have been laid off since the start of the year, according to the industry employment tracking website Layoffs.Fyi.
The next time you buy a flashy new outfit after browsing Instagram, or tap the heart button on a particularly compelling TikTok video, you might discover that the person who posted it isn’t real—and you might not care at all.
Privacy regulations around the world frequently include requirements for websites and apps to obtain informed consent from users prior to collecting, processing, or sharing their personal information, or to provide easy opportunities for users to opt-out of certain uses of their data.
DNS over HTTPS, or DoH, is designed to protect the end user’s DNS queries from last mile providers—but recursive servers (or resolvers) also have full access to what a user is asking for. How can users preserve their privacy against data collection at recursive servers? ODoH provides one answer. Listen in as Tom Ammon, Chris Wood, and Russ White discuss how ODoH works, and what this means for user privacy.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-167.mp3download
My monthly post is up over at Packet Pushers—
Machine learning systems “learn” from existing data pools and user interactions and are given “guardrails” by the system’s designers. Let’s look at some possible attack vectors and failure modes of these systems, specifically how training data, interaction with users, and the choice of guardrails might interact with security and privacy.
In Emoi Services LLC v. Owners Insurance Company, the Ohio Supreme Court recently found software is an intangible item that cannot experience direct physical loss or damage and, therefore, the plaintiffâ€s inability to access or use its software during a ransomware attack was outside the scope of its “businessowners” policy.
Searching Google for downloads of popular software has always come with risks, but over the past few months, it has been downright dangerous, according to researchers and a pseudorandom collection of queries.
Here’s a provocative question: Is it possible, given the vast array of security threats today, to have too many security tools?
This debate has proved futile for two reasons. First, the characteristics of any specific application will dictate which venue is more expensive — there is no simple, unequivocal answer. Second — the question implies that a buyer would choose a cloud or on-premises data center primarily because it is cheaper. This is not necessarily the case
The RISC-V architecture looks set to become more prevalent in the high performance computing (HPC) sector, and could even become the dominant architecture, at least according to some technical experts in the field.
Major US carriers are exaggerating the availability of fixed wireless services and leaving under-served communities at risk of missing out on billions in federal funding that would pay for improved services.
But not all small ISPs are expanding, or are only expanding in small increments. Today I want to talk about the reasons Iâ€ve been given by ISPs that have decided to not expand.
It was another bad week for tech professionals amid further bloodletting by an industry feeling the squeeze of inflation and higher interest rates as Microsoft, Zoom and Yahoo all dished out the pink slips.
To measure the impact of sound on office workers, researchers asked 231 of the agencyâ€s employees working in four buildings across the US to wear two devices for three days.
As adults, many people hold onto items with the thought they might need it in the future, or they hope their children will want it one day.
This post is an introduction and comparison of network automation tools Paramiko, Netmiko, NAPALM, Ansible and Nornir.
In our paper, ‘Mind Your MANRS: Measuring the MANRS Routing Ecosystem‘, we at CAIDA (UC San Diego), in collaboration with Georgia Tech, and IIJ Research Lab, provided the first independent look into the MANRS ecosystem by using publicly available data to analyse the routing behaviour of participant networks.
This week, Chris joins us again to talk about Multiplexed Application Substrate over QUIC Encryption, or masque, which is a more generalized privacy proxy. You can find more about masque at the IETF WG page.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-166.mp3download
I’m teaching a course on router internals over at Safari Books Online on the 24th (in 10 days). From the descriptions:
A network device—such as a router, switch, or firewall—is often seen as a single “thing,” an abstract appliance that is purchased, deployed, managed, and removed from service as a single unit. While network devices do connect to other devices, receiving and forwarding packets and participating in a unified control plane, they are not seen as a “system” in themselves.
The course is three hours. I’m in the process of updating the slides … or rather, I need to get to updating the slides in the next couple of days.
Register here.
Threat actors have been targeting Zoom and its users since the platformâ€s launch, and itâ€s easy to see why—the latest stats show it accounts for 3.3 trillion annual meeting minutes worldwide.
To get a sense of how fragile the innovation business is, keep in mind the popular wisdom that teaches us how nine out of ten startups will fail.
Over a 30-month period, cybercriminal gangs and threat groups posted more than 200,000 advertisements seeking workers with skills in software development, maintaining IT infrastructure, and designing fraudulent sites and email campaigns.
On 24-27 April, a 33-year-old international organisation of ICT organisations will convene a meeting at London under ETSI auspices after a four-year hiatus.
As the topic of domain-driven design (DDD) recently came up at my current job, I decided to get more familiar with the topic by reading Eric Evanâ€s book “Domain-Driven Design: Tackling Complexity in the Heart of Softwareâ€. This was a mistake.
Big Tech results reinforced concerns a boom in cloud services is easing, limiting a lucrative source of profit when a slowing economy has hit the companies’ other businesses and prompting a bet on artificial intelligence as the next growth driver.
And all of that is on a computer, on a network, and attached to the Internet. Like everything else, these systems will be hacked through vulnerabilities in those more conventional parts of the system.
The unemployment rate in the technology job market decreased for the second month in a row, dropping to 1.5% in January from 1.8% in December.
Wi-Fi 6 hardware is now common, and thereâ€s a good chance you have both a Wi-Fi 6 network and Wi-Fi 6 compatible devices. But people are already talking about something new: Wi-Fi 6E, which promises to reduce Wi-Fi congestion further.
Anybody who can read a financial report knows they are paying too much for compute, storage, networking, and software at Amazon Web Services
In a letter to the US Environmental Protection Agency (EPA) Monday a small group of Democrats called on the agency to enact policies designed to force US crypto-mining operations to report their annual energy consumption.
The way things sit now, if you were somehow allergic to computers, you’d be hard pressed to really banish them from your life, no matter where you found yourself.
Organizations using older versions of VMWare ESXi hypervisors are learning a hard lesson about staying up-to-date with vulnerability patching, as a global ransomware attack on what VMware has deemed “End of General Support (EOGS) and/or significantly out-of-date products” continues.
With reports that more than half of US states have banned or restricted access to TikTok on government devices, many cybersecurity professionals are asking, “How can you take a well-intentioned policy from vision to execution?” The answer is operational governance.
Enterprise spending on cloud infrastructure services slowed in the fourth quarter of 2022, but that didn’t stop the big three platforms from taking two-thirds of the entire market.
Have you ever wondered about Starlink and similar Low Earth Orbit (LEO) satellite systems? How are they different from geosynchronous satellites? What about the delay of sending traffic through satellites? And the future of satellites? Join Tom Ammon, Dan York, and Russ White as we discuss the ins and outs of satellite technologies.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-165.mp3download
Yann LeCun, Metaâ€s chief AI scientist, is not impressed by ChatGPT, the wildly popular artificial intelligence technology that is making headlines daily.
German antitrust enforcers known for leveling charges against high-profile tech companies have a new target for accusations of dominant market position abuse: PayPal.
Data anonymization is an important tool for organizations to protect the personal data of individuals, while averting the onerous requirements of the EU and U.K.
Phishing is a big deal, with a State of Phishing report from security firm SlashNext claiming that there were more than 255 million phishing attacks in 2022, a 61% increase from the year before.
The goal of the CGA is to highlight and reduce damages done to all utilities when working underground.
More than 91% of malware utilizes DNS communication at some point during its attack lifecycle, making DNS an invaluable choke point in the fight against cyber threats.
When it comes to operating systems and now CPU instruction sets, there is proprietary, there is licensable and modifiable with a standard base of functionality with room for some originality, and there is true open source.
Since 2017, China has held at least seven of these competitions—called Robot Hacking Games—many with multiple qualifying rounds.
Extortion, and especially “sextortion†emails, are becoming more frequent, and they can be extremely alarming when received. Such emails work by using threats to extort money, evoking intense fear.
2022 was an impactful year in the fight against ransomware. Ransomware attackers extorted at least $456.8 million from victims in 2022, down from $765.6 million the year before.
ECTA also denounced the Commission for not subjecting its proposals to public consultation, and for attempting to overrule the European Electronic Communications Code (EECC). It called on the Commission to rework the proposals to account for the positive impact made by altnets on investment and citizens†interests. It also demanded that the Commission prepare an impact assessment and conduct a public consultation.
These panic-inducing scenarios are familiar to most modern IT and security leaders and share something in common. Each hypothetical breakdown is the result of employees — and the digital public as a whole — being lulled into a false sense of security regarding their online behaviors.
Analyst Gartner predicts that worldwide shipments of PCs, tablets and mobile will drop 4.4% this year, which would mean the second consecutive year of decline. But there is perhaps some light at the end of the tunnel.
Hundreds of CISOs, CSOs, and security leaders, whether from small or large companies, don’t know either. No matter the organization’s size, the certifications, tools, people, and processes: secrets are not visible in 99% of cases.
Itâ€s been a bad few months for password managers — albeit mostly just for LastPass. But after the revelations that LastPass had suffered a major breach, attention is now turning to open-source manager KeePass.
For this week’s episode of the Hedge, Tom Ammon and Russ White are joined by Chris Romeo to talk about the importance of the human element in threat modeling. If you’ve ever wondered about the importance of threat modeling or how to get started in threat modeling, this episode will guide you on your way.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-164.mp3download
The Internet Systems Consortium (ISC) has released patches to address multiple security vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 Domain Name System (DNS) software suite that could lead to a denial-of-service (DoS) condition.
Going into 2023, phishing is still as large a concern as ever. “If it ainâ€t broke, donâ€t fix it,†seems to hold in this tried-and-true attack method.
This follow-up post describes what techniques exist to enumerate subdomains in a DNSSEC-enabled zone and what countermeasures exist to prevent it. DNSSEC itself is not explained further, however, some relevant record types are briefly described.
In 1987 economics Nobel Laureate Robert Solow said that the computer age was everywhere—except in productivity data. A similar thing could be said about AI today: It dominates tech news but does not seem to have boosted productivity a whit.
Names such as Novelli, orangecake, Pirat-Networks, SubComandanteVPN, and zirochka are unlikely to mean anything to a vast majority of enterprise security teams.
Decision-makers might wonder — is investing time and resources in Resource Public Key Infrastructure (RPKI) worth it? What is the effectiveness of RPKI Route Origin Validation (ROV)? In the last year, a number of interesting reports were published.
In pursuit of ever-higher compute density, chipmakers are juicing their chips with more and more power, and according to the Uptime Institute, this could spell trouble for many legacy datacenters ill equipped to handle new, higher wattage systems.
Today Kaspersky researchers reported on a new domain name system (DNS) changer functionality used in the infamous Roaming Mantis campaign.
Academic researchers have discovered serious vulnerabilities in the core of Threema, an instant messenger that its Switzerland-based developer says provides a level of security and privacy “no other chat service†can offer.
Blockchain domain names, domains that are stored on blockchain or cryptocurrency exchanges, are part of a growing, unregulated, and decentralized internet.
I know there is instant hope among students that this software can churn out the dreaded school essay – but that doesnâ€t look likely.
In this post, you will learn about the single most important and useful tool in Computer Networks – Wireshark.
Amid volatile times and gloomy predictions for 2023, low-code/no-code (LCNC) adoption continues to grow rapidly.
There is a ton of data captured, but the main takeaway seems to be around the additional cybersecurity threats presented by the boom in IoT products – with households filling up with connected gizmos, it would appear hackers are being provided with extra vectors of attack to try and scam people or steal data.
But want to know what long-term problem is keeping the smart members of the network leadership of enterprises up at night? Itâ€s an empty chair. Their chair, at the table that makes the plans that set network requirements and directions today and for years to come.
It’s one of those episodes where Tom, Eyvonne, and Russ just sit around and talk about the news of the day. We cover three topics in this show. The first is Netops, automation, and where this is all going. The second is on the FCC mapping process and the reality of broadband in the US. The third—perhaps a little controversial—is about IT work habits, innovation, and adding value.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-163.mp3download
As this technology is perfected, AI writing may render most of the English composition curriculum and other writing skills irrelevant. Like penmanship being displaced by word processors, and memorization by books or databases, writing itself may soon be seen as an archaic novelty.
How to properly balance the commercial rights of a complainant with the free speech rights of a respondent has challenged a generation of Uniform Domain Name Dispute Resolution Policy (UDRP) panelists.
New York City Mayor Eric Adams responded to criticism over increasing the use of facial recognition technology by declaring, Big Brother is protecting you!
Whether someone will get a loan for buying a house is dependent on the opaque policy instantiated in some black box algorithm. Ditto whether someone’s parole application will get approved, some startup entrepreneur will get capital for his venture, or someone on an organ donation waitlist will get his life-saving treatment.
Blaise Arcas, the head of Google’s AI group in Seattle, recently argued that although large language models (LLMs) may be driven by statistics, statistics do amount to understanding.
Crypto bros still blather on about how their Bitcoin, Ethereum or what have you will go to the Moon. They also insist that with their diamond hands, they’re going to Hold On for Dear Life (HODL) no matter what happens.
I believe the conventional idea of “writing a program” is headed for extinction, and indeed, for all but very specialized applications, most software, as we know it, will be replaced by AI systems that are trained rather than programmed.
omona College business and investments prof Gary Smith warns Salon readers not to be too gullible about what human-sounding chatbots really amount to.
I don’t know about you, but there are days when I wake up with an urgent need to escape from this digital jungle, this plastic world, in which we have exchanged feelings for tons of made-up ones and zeros.
However, since growing online content consumption put networks under increasing pressure during the peaks of the Coronavirus lockdowns, some political support in Europe seems to have been garnered (e.g. France, Italy, and Spain).
On the other hand, the digital sphere has become a dangerous space. The Ukrainian war pulled cyber into real military fighting.
The recent adoption at the end of December of the new EU Directive for a high level of cybersecurity across the Union—commonly referred to as “NIS2â€â€”paved the way for important updates to the domain name system (DNS).
Domain names are associated with the full spectrum of internet content, from legitimate use by brands or individuals, to infringing or criminal activity. CSC has observed that certain TLDs get used more for egregious content.
Heata has developed a novel way to use the waste heat generated by servers: mounting them on domestic hot water tanks to cut energy bills for homeowners.
It’s time for you and your colleagues to become more skeptical about what you read. That’s a takeaway from a series of experiments undertaken using GPT-3 AI text-generating interfaces to create malicious messages designed to spear-phish, scam, harrass, and spread fake news.
Randy Anders is VP of North American sales with HughesNet for Business. He said HughesNet has been providing SD-WAN to enterprise customers for several years, using its GEO satellite connectivity.
The US Federal Aviation Administration (FAA) has given airlines until February 2024 to fix altimeters that may clash with C-band 5G spectrum.
Itâ€s a good idea to use one of the best password managers to keep your logins safe, but now a security company is warning that one of the most popular password managers in the world is not safe to use.
In early January, development-pipeline service provider CircleCI warned users of a security breach, urging companies to immediately change the passwords, SSH keys, and other secrets stored on or managed by the platform.
Security teams have traditionally used mean time to repair (MTTR) as a way to measure how effectively they are handling security incidents. However, variations in incident severity, team agility, and system complexity may make that security metric less useful.
In a recent paper, my fellow researchers from Freie Universität Berlin, The Fraunhofer Institute for Open Communication Systems, and HAW Hamburg and I revisited QUIC connection setup performance.
Getty Images is suing Stability AI, creators of popular AI art tool Stable Diffusion, over alleged copyright violation.
United Kingdom leaders are pushing forward with a massive online censorship bill that, thanks to the lobbying of a group of lawmakers over the weekend, has been made significantly harsher with threats of imprisonment for tech platform managers who run afoul of the complicated regulations.
The laptops of 2023 will get new chips and new graphics. Many will get new touchpads, some will get new fans, and a few will get funky styluses. But some of the coolest, weirdest, and most exciting updates are coming to screens.
Encrypt everything! Now! We don’t often do well with absolutes like this in the engineering world–we tend to focus on “get it down,” and not to think very much about the side effects or unintended consequences. What are the unintended consequences of encrypting all traffic all the time? Geoff Huston joins Tom Ammon and Russ White to discuss the problems with going dark.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-162.mp3download
I’m teaching a three-hour webinar on infrastructure privacy this coming Friday. From the description—
Privacy is important to every IT professional, including network engineers—but there is very little training oriented towards anyone other than privacy professionals. This training aims to provide a high-level overview of privacy and how privacy impacts network engineers. Information technology professionals are often perceived as “experts” on “all things IT,” and hence are bound to face questions about the importance of privacy, and how individual users can protect their privacy in more public settings.
There is a recording for anyone who registers.
Register here.
Want to be Bigger? Faster? Stronger? Such questions are a staple in exercise and health media, but those same questions are raised in the tech industry as well.
TAU-SAT3, launched Tuesday on a SpaceX rocket from Cape Canaveral in Florida, will pave the way towards quantum communication via a nanosatellite, Tel Aviv University reported on Wednesday.
If you deal with Web Performance, youâ€ve probably heard about HTTP resource prioritization. This is especially true since last year, as Chromium added so-called “Priority Hints†with the new fetchpriority attribute, which allow you to tweak said prioritizations.
Last Fall, SpaceX broadened the definition of Gen2 to include three configurations, designated F9-1, F9-2, and Starship.
eBPF brought with it a vast amount of software, including software-defined networking (SDNs), observability projects, and security-based software.
Historically, the only option to connect processor cores and memory have been proprietary interconnects such as InfiniBand, PCI Express and other protocols that connect compute clusters with offloads but for the most part that wonâ€t work with AI and its workload requirements.
Over the next few months, we found as many car-related vulnerabilities as we could. The following writeup details our work exploring the security of telematic systems, automotive APIs, and the infrastructure that supports it.
Within seven years of this pamphlet, Congress passed the Telecommunications Act of 1934, which put some regulatory restraints on the large Bell Telephone monopoly that was gobbling up telephone systems across the country.
Confidential computing segregates data and code from the host computer’s system and makes it harder for unauthorized third parties to access the data.
Three big analyst firms published stats this week that made for grim reading. The consensus from Gartner, IDC, and Canalys is that fourth quarter shipments came in at somewhere around 65-68 million units, down almost 30% compared to last year.
Public announcement of the 433-qubit IBM Quantum Osprey processor at the 2022 IBM Quantum Computing Summit on Nov. 9 represents another evolutionary milestone in the development of universal quantum computers.
A research paper that claimed a quantum breakthrough that could “challenge RSA-2048” encryption received significant attention in the past week, followed by significant criticism as experts weighed in.
ReversingLabs urges organizations, specifically npm and PyPI package users, to double down on securing their networks, and part of that could be better detection and blocking of access to suspicious and malicious web properties related to threats like IconBurst and Material Tailwind.
Having been involved in this sector for over fifteen years now, the rate of change in the market dynamics continues to surprise me—from its early years when MarkMonitor and NetNames clearly led the space for several years, then seeing well-funded startups such as Yellow Brand Protection and Incopro challenge that, followed by a period of heavy M&A, it is now extremely diverse.
Last week, Ireland’s Data Protection Commission fined Meta 390 million euros — 210 million euros against Facebook and 180 million euros against Instagram.
Encrypt everything! Now! We don’t often do well with absolutes like this in the engineering world–we tend to focus on “get it down,” and not to think very much about the side effects or unintended consequences. What are the unintended consequences of encrypting all traffic all the time? Geoff Huston joins Tom Ammon and Russ White to discuss the problems with going dark.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-161.mp3download
Undersea cables between the U. S. and Cuba have long been intertwined with politics.
People like to tout NISTâ€s SP 800-207 [Zero Trust Architecture] as the hot new thing, but the fact is, zero trust network models have been around for over a decade.
As Russian ground troops prepared to enter Ukraine in February 2021, Ukrainian governmental departments, online media organizations, financial firms, and hosting providers were slammed with a surge of distributed denial-of-service (DDoS) attacks.
Prosecutors said the five IT officials of the public administration department had failed to check the security of the system and update it with the most recent antivirus software.
What exactly is the edge? What makes something an edge appliance? These are trickier questions than you might think, and depending on who you ask — and honestly, what theyâ€re trying to sell you — the answers can vary wildly.
Youâ€ve likely been hearing about the World Wide Web Consortiumâ€s (W3C) Web Authentication (WebAuthn) and considering whether youâ€re ready to implement it in your environment.
In this episode of PING, Luuk Hendricks and Willem Toorop from NLNet Labs discuss applying Express Data Path (XDP) to the DNS protocol.
A recent report spelled it out in stark detail. Across all industries, the average ransom paid is a hefty $812,360. Yet for manufacturing, that average skyrockets to a stunning $2,036,189 — about two and a half times the average.
This article is a continuation of a series that presents the Overlay Multilink Network Interface (OMNI) and Automatic Extended Route Optimization (AERO) services.
Quantum computing has a crucial weakness that may severely delay, if not kill outright, its chances of becoming a way of running algorithms that classical computers cannot handle: its susceptibility to noise.
Organizations tolerate all this complexity (and the delays and costs that come with it) since they see no alternative. But what if there was an easier way? Iâ€ll examine the two fundamental shifts driving software development and IT operations and see why current processes are so cumbersome.
WhoisXML APIâ€s IP intelligence now includes Regulatory Compliance IP Data Feeds available as separate IP geolocation and IP netblocks files.
While the vast majority of software in usage today doesnâ€t use a microservice architecture, it has been hailed as the best way to build “cloud native†software for almost a decade now.
Instead of jumping straight from a 32GB DIMM to a 64GB one, DDR5, for the first time, allows for half steps in memory density. You can now have DIMMs with 24GB, 48GB, 96GB, or more in capacity.
Integer factorization has been one of the most important foundations of modern information security.
Cloud might seem shiny and new—but that’s just the way it looks on the outside. Most cloud services are still built on decades old technology, from networking to file access. Avishai Ish-Shalom joins Tom Ammon and Russ White to discuss the impact of changes in hardware on the design of operating systems, and think through how things will need to change to continue the drive for more performance.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-160.mp3download
original article on USENIX here
The change of the year is always a good time to reflect. This year I’ve made major changes in my physical environment by reshaping many of the things about this house we recently moved to in Knoxville. Besides ripping out the entire kitchen, replacing all the floors, and reworking the fireplace, it was a good chance to rethink the office I work in every day. I’m rather persnickety about the lighting, layout, and tools I use (although a lot of people still think I’m crazy for using fairly standard tools, like Word, for writing).
This is my space, pretty much—
I use an adjustable height desk where I’m either leaning or standing—if I want to sit to read something, I normally grab a tablet and sit in the red chair off to the side, or even go someplace else in the house. I prefer not to read on my main computer screen most of the time. I normally keep ambient light to a minimum, and turn my monitor brightness down to pretty minimal, as well—below 20%.
I’m currently running an LG 38in curved monitor. I don’t game, so I care a lot more about resolution than refresh rate, etc. My main driver is a Microsoft Surface 8, topped out in specs, with a thunderbolt dock to support all the externals. I’m typing on a Drop ALT with 68g Zilentv2 switches. The smaller keyboard keeps the Wacom pad close by, making it easier to switch between keyboard and pointer. Smaller keyboards like this are perfectly useable if you map all the function and other special purpose keys onto a separate layer, and then place your layer control keys wisely. I’ve been thinking about switching to a more ergonomic keyboard, but I’ve not made my mind up yet.
For audio and video gear above the monitor I used two desk-clamp photography stands on the back of the desk, along with a long cheesebar. The cheesebar holds the Logitech webcam connected to my work machine, which is off to the side, the Dell Ultrasharp 4k, the ball mount for a digital camera (for recordings), and an AT4053 shotgun mic. On the side of the desk is a boom arm with a Blue Baby Bottle mic.
The two mics feed into an Antelope Zen Go interface, which allows me to do some minor eq and such before my voice hits the computer. I used to do all this onboard the computer itself using a Focusrite Clarett, but its a lot simpler to push some audio processing onto the interface itself with the Zen Go. These kinds of DSP-onboard interfaces tend to be hard to get up and running, by the way. I worked with an Apollo interface for a solid month before giving up and switching to the Zen Go.
Beside the Zen is a little Tascam recorder; the primary mic is routed through the Zen to this recorder so I don’t need to record on the computer itself (though most of the time I do just record in Audition). I find that when I’m doing training recording that will be edited and combined later, it’s better to pull as much processing off the main computer as possible to improve the quality and performance of the screen capture process … so I record voice on the Tascam, video on a separate digital camera, and just the screen capture on the computer.
I do have a set of Meze classic headphones hooked up to the Zen Go, but I mostly listen to meetings and music throughout the day on a Klipsch Three.
Audio wise, I put up a set of acoustic panels along one wall. I’m certain I could do more here, but the panels plus the carpeted floor seem to do okay for keeping the audio sounding pretty clean.
Lights… I’ve switched back and forth between GVM and Neewer over the years. Right now I’m using two Neewer flat panel lights, one of which provides ambient light by bouncing off the ceiling—this is the only ambient light I normally have turned on. There’s another LED panel with a diffuser to my front acting as a key, and a spot with a strong diffuser as far away on my right as I can get it.
Well, that’s my working environment for the moment … if you have questions about why I chose specific pieces of gear, etc., please feel free to drop a comment here, or pm me on LinkedIn.
In this last episode of 2022, Tom, Eyvonne, and Russ sit around and talk about some interesting things going on in the world of network engineering. We start with a short discussion about SONiC, which we intend to build at least one full episode about sometime in 2023. We also discuss state and antipatterns, and finally the idea of acquiring another company to build network resilience.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-159.mp3download
Today, we released the latest issue of The Domain Name Industry Brief, which shows that the third quarter of 2022 closed with 349.9 million domain name registrations across all top-level domains, a decrease of 1.6 million domain name registrations, or 0.4%, compared to the second quarter of 2022.
Since 2019, unpatched ESXi servers have been targets of ongoing in-the-wild attacks based on two vulnerabilities in the ESXiâ€s OpenSLP service: CVE-2019-5544 and CVE-2020-3992.
In many cases, once a high-risk security vulnerability has been identified in a product, a bigger challenge emerges: how to identify the affected component or product by its assigned name in the National Vulnerability Database (NVD).
A developer’s cryptographic signing key is one of the major linchpins of Android security. Any time Android updates an app, the signing key of the old app on your phone needs to match the key of the update you’re installing.
Hashing is one of the pillars of cybersecurity. From securing passwords to sensitive data, there are a variety of use cases for hashing.
Cloud gaming needs wide access to 5G networks to thrive. Performance requirements for streaming the latest AAA titles on mobile devices are already high and are likely to increase as the industry adopts AR and VR devices, with the future growth of AR and VR devices also incentivizing telecom providers to bundle and/or upsell.
Did you know over 93% of all malware employs DNS as a mechanism to identify and contact its command and control (C2) to receive instructions? This is why a truly holistic cybersecurity strategy must include protection from malicious domains.
Today, we are glad to release the third version of the threat matrix for Kubernetes, an evolving knowledge base for security threats that target Kubernetes clusters.
The software industry is making headway against a group of pernicious vulnerabilities that are responsible for the vast majority of critical, remotely exploitable, and in-the-wild attacks, software-security experts said this week.
PCI DSS 4.0 was released in March 2022 and will replace the current PCI DSS 3.2.1 standard in March 2025. That provides a three-year transition period for organizations to be compliant with 4.0.
Arista Networks has a new high-end data-center switch as well as several smaller ones designed to provide more configuration and upgrade choices to fit the specific needs of individual organizations.
However, I’m going to ask an awkward question, one that has been burning in my mind for a while. What really happens to that data once you click “delete” on a cloud service?
Ofcomâ€s data shows that 97 percent of UK homes now have access to superfast broadband, defined as a downstream connection of 30 Mbps or more. While 27 percent of those who can access superfast broadband have yet to take up such services, Ofcom doesnâ€t seem particularly keen to persuade them to do so.
The European Telecommunications Standards Institute (ETSI) has unveiled a new Industry Specification Group (ISG) to undertake preliminary work on the potential use of terahertz frequencies in 6G communications.
NuGet, PyPi, and npm ecosystems are the target of a new campaign that has resulted in over 144,000 packages being published by unknown threat actors.
DDoS attacks continue to be a persistent threat to organizations of all sizes and in all markets. Roland Dobbins joins Tom Ammon and Russ White to discuss current trends in DDoS attacks, including the increasing scope and scale, as well as the shifting methods used by attackers.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-158.mp3download
Simply put, we have been right all along, and we now have the conflicting circuit court precedent to prove it. The Supreme Court needs to consider the Fourth Circuitâ€s arguments and address this split between circuits.
Do we let Big Tech have access to our private communications and free email accounts because itâ€s so easy? Once youâ€ve said yes — and who among us has not? — itâ€s not a stretch to think that Big Data already has almost all your information, so why get picky at the next juncture?
Internet infrastructure services—the heart of a secure and resilient internet where free speech and expression flows—should continue to focus their energy on making the web an essential resource for users and, with rare exceptions, avoid content policing.
Then Elon announced Apple, the most powerful company in the world, threatened to remove Twitter from the app store.
A California judge has cleared the way for a potentially massive class-action lawsuit against Google, which stands accused – again – of anticompetitive practices surrounding its Play store.
There is a growing trend in American culture of what the literary theorist Peter Brooks calls “storification.â€
Targeted advertisingâ€s days may be numbered. The Wall Street Journal and Reuters report that the European Data Protection Board has ruled that Meta cannot continue targeting ads based on userâ€s online activity without affirmative, opt-in consent.
The Council of the European Union this week adopted new language for regulations governing internet systems that may put the security of your browser at greater risk.
Since the dawn of digital marketing, people have been asked to provide their personal information in exchange for information online. This “information swap” is still a common digital tactic.
In this article, I will explain how SSHFP DNS records can help mitigate such risks and share the results of our large-scale analysis.
A vulnerability in IBM Cloud databases for PostgreSQL could have allowed attackers to launch a supply chain attack on cloud customers by breaching internal IBM Cloud services and disrupting the hosted system’s internal image-building process.
Amazon Web Services has signaled that the future of cloud computing cannot rely alone on general-purpose chips with its new Graviton3E silicon, joining AMD and Intel in introducing specialized central processing units that are meant to perform certain applications faster and more efficiently.
A recent statement from Italyâ€s data protection authority, the Garante, opens a new chapter in the never-ending story of profiling cookies.
While analyzing its capabilities, Akamai researchers have accidentally taken down a cryptomining botnet that was also used for distributed denial-of-service (DDoS) attacks.
Biometrics is supposed to be one of the underpinnings of a modern authentication system. But many biometric implementations (whether that be fingerprint scanes or face recognition) can be wildly inaccurate, and the only universally positive thing to say about them is they’re better than nothing.
Geolocation providers usually focus on locating end user devices at the edge of the Internet. But what about the machines that make up the infrastructure in the middle?
There are certainly plenty of myths in the industry about OpenRAN, and today I hope to eradicate one of them: OpenRAN will be deployed anywhere and everywhere, including the busy city centres.
The SMO provides a central interface for application configuration and provisioning. It also automates both infrastructure management processes and the creation of new services through southbound APIs (O2-IMS & O2-DMS).
There is a common misconception that all problems have clear, straightforward solutions — as long as you look hard enough. While this is a bold and ambitious goal, it’s misguided when applied to cybersecurity.
How valuable is it to keep older solutions like this running? Well, organizations don’t enjoy running old legacy systems just for the pleasure of it, but they’re often forced to keep them running because it’s their only option, or at least the only cost-effective option available to them.
Securing critical infrastructure is complicated because of the vast network of facilities and management systems. Threats targeting this sector can have dire consequences, and when attacks do happen, they’re often accompanied by a media storm.
The European tech industry saw $400 billion in value wiped out this year and an 18% decline in venture capital funding, according to a report from venture capital firm Atomico.
Fondly referred to as “spinning rust†among some computer nerds, mechanical hard drives seem almost quaint compared to hyper-fast SSDs. Yet, the idea that mechanical hard drives are ready for the trash pile may be more than a little premature.
Conventional wisdom says that trying to attach system memory to the PCI-Express bus is a bad idea if you care at all about latency. The further the memory is from the CPU, the higher the latency gets, which is why memory DIMMs are usually crammed as close to the socket as possible.
Vendor lock-in has been an issue in networking for the entire time I’ve been working in the field—since the late 1980s. I well remember the arguments over POSIX compliance, SQL middleware standards, ADA, and packet formats. It was an issue in electronics, which is where I worked before falling into a career in computer networks, too. What does “vendor independence” really mean, and what are the ways network operators can come close to having it? Frank Seesink joins Russ White and Tom Ammon to rant about—and consider—solutions to this problem.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-157.mp3download
The Hedge December update contains information about upcoming episodes and training—listen in for the inside scoop!
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-dec22.mp3download
My next live training course is coming up on the 16th of December: Troubleshooting. This is one of those classes where I’m taking formal training from a former life (electronic engineering) and applying it to the networking world. From the description—
Troubleshooting is a fundamental skill for all network engineers, from the least to most experienced. However, there is little material on correct and efficient troubleshooting techniques in a network engineering context, and no (apparent) live training in this area. Some chapters in books exist (such as the Computer Networking Problems and Solutions, published in December 2017), and some presentations in Cisco Live, but the level of coverage for this critical skill is far below what engineers working in the field to develop solid troubleshooting skills.
This training focuses on the half-split system of troubleshooting, which is widely used in the electronic and civil engineering domains. The importance of tracing the path of the signal, using models to put the system in context, and the use of a simple troubleshooting “loop” to focus on asking how, what, and why are added to the half-split method to create a complete theory of troubleshooting. Other concepts covered in this course are the difference between permanent and temporary fixes and a review of measuring reliability. The final third of the course contains several practical examples of working through problems to help in applying the theory covered in the first two sections to the real world.
Sign up here.
Nearly every application has at least one vulnerability or misconfiguration that affects security and a quarter of application tests found a highly or critically severe vulnerability, a new study shows.
75% of lookalike domains are registered with unrelated third parties and target these companies.
China’s antitrust watchdog, the State Administration for Market Regulation (SAMR), has proposed a revision of the nation’s competition law that targets tech firms.
A new report claims that Metaâ€s tracking Pixel has been used to collect your financial information when using popular tax filing services to send in your return.
Did you know that a Magniber ransomware infection can cost you a ransom of as much as US$2,500?
New York State has banned a practice becoming more common in the crypto-mining industry – the rescuing and repurposing of mothballed fossil fuel plants to exclusively provide energy for mining digital currency.
DDoS attacks target certain networks, flooding them with unwanted traffic from many different sources and causing interruptions to online services for legitimate users.
John the Ripper (JtR) is a popular password-cracking tool. John supports many encryption technologies for Windows and Unix systems (Mac included).
While in the near future most devices in the car will be connected through zonal switches, cameras are the exception. They will continue to connect to processors over point-to-point protocol (P2PP) links using proprietary networking protocols such as low-voltage differential signaling (LVDS), Maximâ€s GMSL or TIâ€s FPD-Link.
Before we start, let’s get one thing perfectly clear: The entire and only reason for writing reports like this one is to avoid repeating the same mistake—no more, no less. Assigning guilt, placing blame, exposing incompetence, or getting people fired is not CSRB’s job. It investigates; the rest of us act.
U.S. regulators have imposed a ban on electronic equipment created by several major Chinese tech corporations, citing national security concerns.
Modularization is a crucial part of network design because it supports interchangeability, reduces the size of failure domains, and controls security domains. One critical aspect of modularization is functional separation, which argues for separating services onto specific physical and logical resources. Kevin Myers joins Tom Ammon and Russ White on this episode of the Hedge to discuss the theory and importance of functional separation in network design.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-156.mp3download
So in terms of the daily lived experience of most people reading this, truly autonomous vehicles just aren’t going to happen.
When the federal government gets together with social media giants to censor critics of the government, is that free speech or censorship?
If you own an advanced Android phone, you may find that Google Assistant will interrupt conversations to offer its own “insights”. Google is also pursuing “prebunking” of what it considers “misinformation” with preemptive propaganda campaigns.
The outcomes of such a system are incentives to not be the new person on a team, to not ask questions, to not work on new and unfamiliar efforts, and to not work together at all generally. Those behaviors become embedded in an organization’s DNA, despite whatever is advertised publicly.
Today’s business headlines herald a harsh reality for Big Tech: tumult at Twitter; meltdown at Meta; atrophy at Alphabet; adjustments at Amazon. Layoffs, sliding stock and shrinking valuations are hallmarks of the moment.
To understand the sudden downfall of the now-collapsed crypto exchange FTX, you have to go back to the beginning.
Twitter was their home. Elon broke into their home. Then he kicked out their friends, and told everyone left to do their laundry.
Internet users are being tricked into installing browser extensions that can hijack their web searches.
An offshore company that is trusted by the major web browsers and other tech companies to vouch for the legitimacy of websites has connections to contractors for U.S. intelligence agencies and law enforcement, according to security researchers, documents and interviews.
Silicon Valley startup Eliyan thinks its technology for enabling chiplet-based designs can best those from semiconductor giants Intel and TSMC by providing better performance, higher efficiency, fewer manufacturing issues, and more supply chain options.
While the number of cleartext passwords is an improvement compared with the 96,361 passwords exposed in 2020 and the more than 100,000 sent in the clear in 2019, there is still room for improvement, says Jessica Bair Oppenheimer, director of technical alliances at Cisco Secure.
Qualcomm and Arm have been engaged in one of those very entertainingly bitter court fist-fights that the industry throws up when friends fall out over money.
Unbound 1.16.0 adds support for Extended DNS Errors (EDEs) as codified in RFC 8914.
I suspect this reflects a significant change in the economics of the sector. For the last 20 years, Silicon Valley has had the wind at its back thanks to rapid adoption of new technologies like the internet and smartphones. As a result, the industry fared better than the broader economy during and after the 2008 recession.
By playing unexpected moves outside of KataGo’s training set, a much weaker adversarial Go-playing program (that amateur humans can defeat) can trick KataGo into losing.
New research released this week reveals the process used by third party advertisers to target online users can be viewed or manipulated by online adversaries using only their target’s email address.
On August 4, 2022, Microsoft publicly shared a framework that it has been using to secure its own development practices since 2019, the Secure Supply Chain Consumption Framework (S2C2F), previously the Open Source Software-Supply Chain Security (OSS-SSC) Framework.
This raises an important question: How do you take what is good about these patterns for creating innovation? Specifically, how do you apply open source principles and practices as appropriate? That’s what we’ve sought to accomplish with Red Hat Research.
Thousands of smartphone applications in Apple (AAPL.O) and Google’s (GOOGL.O) online stores contain computer code developed by a technology company, Pushwoosh, that presents itself as based in the United States, but is actually Russian, Reuters has found.
Thatâ€s opened major questions about how these now-forever-roaming workers are connected to information resources and to each other.
A novel attack method has been disclosed against a crucial piece of technology called time-triggered ethernet (TTE) that’s used in safety-critical infrastructure, potentially causing the failure of systems powering spacecraft and aircraft.
Network engineers normally use and support DNS as a service, but don’t tend to deploy, manage, and interact with DNS servers at an application level. For this episode of the Hedge, Andreas Taudte joins Tom Ammon and Russ White to discuss the many lessons learned from planning and deploying DNS as a service.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-155.mp3download
A long time ago, I supported a wind speed detection system consisting of an impeller, a small electric generator, a 12 gauge cable running a few miles, and a voltmeter. The entire thing was calibrated through a resistive bridge–attach an electric motor to the generator, run it at a series of fixed speed, and adjust the resistive bridge until the voltmeter, marked in knots of wind speed, read correctly.
The primary problem in this system was the several miles of 12 gauge cable. It was often damaged, requiring us to dig the cable up (shovel ready jobs!), strip the cable back, splice the correct pairs together, seal it all in a plastic container filled with goo, and bury it all again. There was one instance, however, when we could not get the wind speed system adjusted correctly, no matter how we tried to tune the resistive bridge. We pulled things apart and determined there must be a problem in one of the (many) splices in the several miles of cable.
At first, we ran a Time Domain Reflectometer (TDR) across the cable to see if we could find the problem. The TDR turned up a couple of hot spots, so we dug those points up … and found there were no splices there. Hmmm … So we called in a specialized cable team. They ran the same TDR tests, dug up the same places, and then did some further testing and found … the cable was innocent.
This set up an argument, running all the way to the base commander level, between our team and the cable team. Who’s fault was this mess? Our inability to measure the wind speed at one end of the runway was impacting flight operations, so this had to be fixed. But rather than fixing the problem, we were spending our time arguing about who’s fault the problem was, and who should fix it.
When I read this line in a recent CAIDA research paper–
“Measurement is political, and often adversarial.”
It rang very true. In Internet terms, speed, congestion, and even usage are often political and adversarial. Just like the wind speed system, two teams were measuring the same thing to prove the problem wasn’t their’s–rather than to figure out what the problem is and how to fix it.
In other words, our goal is too often Mean Time to Innocence (MTTI), rather than Mean Time to Repair (MTTR).
MTTI is not enough. We need to work with our application counterparts to find and fix problems, rather than against them. Measurement should not be adversarial, it should be cooperative.
We need to learn to fix the problem, not the blame.
This is a cultural issue, but it also impacts the way we do telemetry. For instance, in the case of the wind speed indicator, the problem was ultimately a connection that “worked,” but with high capacive reactance such that some kinds of signals were attenuated while others were not. None of us were testing the cable using the right kind of signal, so we all just sat around arguing about who’s problem it was rather than solving the problem.
When a user brings a problem to you, resist the urge to go prove yourself–or your system–innocent. Even if your system isn’t the problem, your system can provide information that can help solve the problem. Treat problems as opportunities to help rather than as opportunies to swish your superhero cape and prove your expertise.
https://www.darkreading.com/risk/build-security-around-users-a-human-first-approach-to-cyber-resilience
User-first security must begin with an understanding of how people use computing technology. We have to ask: What is it that makes users vulnerable to hacking via email, messaging, social media, browsing, file sharing?
How does the industry effectively assess software security, enabling an approved list (allowlist) of software and libraries on distributed systems across multiple industries?
The COVID pandemic pushed a lot of school coursework to the internet, with an increased reliance on true/false and multiple-choice tests that can be taken online and graded quickly and conveniently.
Top chipmakers Nvidia, Intel, ARM, and AMD are providing the hardware hooks for an emerging security concept called confidential computing, which provides layers of trust through hardware and software so customers can be confident that their data is secure.
Rather than ensuring security, the focus across the software development life cycle (SDLC) is beating the competition to market. In fact, innovation is often seen at odds with security — the former believed to be fast-paced and productive, and the latter a roadblock that stifles quick-moving application development.
Responding to a recent surge in AI-generated bot accounts, LinkedIn is rolling out new features that it hopes will help users make more informed decisions about with whom they choose to connect.
Several models have been proposed to the Multi-State Information Sharing and Analysis Center (MS-ISAC) and other ISACs for a role in software assurance for supply chains using the Software Bill of Material (SBOM) information and associated digital signatures.
A lack of precision in our terminology leads to misunderstandings and confusion about the activities we engage in, the information we share, and the expectations we hold.
As has happened with other Web technologies designed for legitimate use, the InterPlanetary File System (IPFS) peer-to-peer network for storing and accessing content in a decentralized fashion has become a potent new weapon for cyberattacks.
Tests show that deploying malware in a persistent manner on load balancer firmware is within reach of less sophisticated attackers.
This fall, Microsoft claimed to have addressed anticompetitive cloud infrastructure complaints from a few smaller cloud services providers in Europe.
The findings suggest a loose but visible alignment between Russian government priorities and activities and ransomware attacks leading up to elections in the six countries.
Meta, formerly Facebook, once seemed an impenetrable fortress, but it’s now showing big cracks.
As a security researcher, common vulnerabilities and exposures (CVEs) are an issue for me — but not for the reason you might think.
That will be one of the reasons crypto has been plummeting for most of this year but recent events have intensified the sense of crisis.
Applications generally assume the network provides near-real-time packet transmission without regard for what the application is trying to do, what kind of traffic is being transmitted, etc. Back in the real world, its often important for the network to coordinate with applications to more efficiently carry traffic offered. The Path Aware Research Group (PANRG) in the Internet Research Task Force (IRTF) is looking at the problems involved in understanding and signaling the path characteristics to applications.
In this episode of the Hedge, Brian Trammel joins Tom Ammon and Russ White to discuss the current work on path aware networking.
November update on upcoming shows and training. My upcoming training on Safari Books Online is here.
The recent rise of HTTP request smuggling has seen a flood of critical findings enabling near-complete compromise of numerous major websites. However, the threat has been confined to attacker-accessible systems with a reverse proxy front-end… until now.
Eternity typically keeps its activities on the down low—in the Dark Web. Still, we sought to determine if LilithBot and Eternity also engaged in dealings on the Surface Web.
The Financial Conduct Authority, the UK's financial services regulator, has begun discussions with the aim of understanding the impact of Big Tech on industry competition.
Tom, Eyvonne, and Russ hang out at the hedge on this episode. The topics of discussion include our perception of security—does the way IT professionals treat security and privacy helpful for those who aren't involved in the IT world? Do we discourage users from taking security seriously by making it so complex and hard to use? Our second topic is whether multicloud is being oversold for the average network operator.
Data security in the public cloud has been a concern since the computing medium emerged in the mid-2000s, but cloud providers are allaying fears of theft with a new concept: confidential computing.
Fewer than half of 5G users say they've experienced improvements in speed or reliability over 4G according to a new survey, but that is not going to stop some in telecoms pushing ahead with efforts to deliver an enhanced version branded 5.5G.
So we should all be concerned that Mark Cox, a Red Hat Distinguished Software Engineer and the Apache Software Foundation (ASF)'s VP of Security, this week tweeted, "OpenSSL 3.0.7 update to fix Critical CVE out next Tuesday 1300-1700UTC."
DevOps, SecDevOps, GitDevOps—stick DevOps on the end of anything, and it will sound cool, generation FOMO in thousands (maybe millions). What does DevOps really mean to network engineers, though? In this episode of The Hedge, we discuss examples of how the Three Ways, (described in Part One of The DevOps Handbook) of Flow, Feedback, and Continual Learning with Joel King, a leading light in this field.
If you advertise routes through a provider to the global Internet, you might be wondering if you should go through the trouble of registering in the RPKI and advertising ROAs. What is the tradeoff for the work involved in what seems like a complex process? Cecelia Testart joins Jeremy White and Russ White to discuss recent work in measuring the value of the RPKI.
What would the Internet look like—or what kinds of services would need to be developed and deployed—to make boradband class service available to every user? What could this kind of development do to drive entire societies forward? Micah Beck, from the University of Tennessee, joins Tom Ammon and Russ White to discuss universal broadband on this episode of the Hedge.
What's going on with the Hedge? What am I teaching this coming month? Listen to this short update to find out all the news.
Who's using the cloud? Is cheap complexity harmful? Are mainframes dead? Is this the end of specialized networking hardware? Is it a good idea to have server folks build networks? On this episode of the Hedge, Tom, Eyvonne, and Russ go "guestless" in a roundtable about various topics and ideas in the networking world.
Indeed, Juniper Research predicts that operator 5G FWA revenue will reach $24 billion worldwide by 2027, driven essentially by the use of the technology as a fibre replacement for consumer services.
Floppy disks may have gone the way of the dodo and joined other extinct media such as punched cards and paper tape, but some people are apparently still using them, and one company even continues to sell them.
Many companies also have changed how they operate, from having to deal with a more remote hybrid workforce to adapting to supply chains that have yet to completely rebound from the battering they took during the pandemic.
Arm says Nvidia’s Grace processor will be among the first chips to use its upcoming Neoverse V2 CPU cores.
The early deceased Heinz Rutishauser (1918–1970) of ETH Zurich is considered the most important Swiss pioneer from the early era of computer science.
According to Dell’Oro, datacenter switching set a new record for revenues for any second quarter in history and also for any first six months of any year since it has been keeping records.
It seems like only yesterday we started talking about the Site Reliability Engineer, and their place in the IT ecosystem. Over the last several years, the role of the SRE has changed—and it's bound to continue changing. On this episode of the Hedge, Niall Murphy joins Tom Ammon and Russ White to discuss the changing role of the SRE, and what the SRE could be.
Smartphone shipments are forecast to shrink globally by 6.5 percent this year as many households feeling the pinch of inflation decide to prioritize paying for food, energy and other essentials over refreshing handsets.
SmartNICs have long been the domain of hyperscale and cloud datacenters, but they remain relatively uncommon in enterprise environments due in large part to the lack of software compatibility.
The last few years have demonstrated that breaches occur, no matter how much security organizations put in place.
It seems like only yesterday we started talking about the Site Reliability Engineer, and their place in the IT ecosystem. Over the last several years, the role of the SRE has changed—and it's bound to continue changing. On this episode of the Hedge, Niall Murphy joins Tom Ammon and Russ White to discuss the changing role of the SRE, and what the SRE could be.
In the last post on this topic, I concluded that IP addresses are protected information—operators should handle users’ IP addresses according to privacy best practices. But I also concluded that because IP addresses used for forwarding.
https://www.theregister.com/2022/08/01/column_7nm_chips_china/ After decades trailing the rest of the world in leading-edge chip making, Chinese sand stamper Semiconductor Manufacturing International Corporation (SMIC) has quietly got into the 7nm business. That's a huge and unexpected leap. Has the West's embargo of the latest fab furniture failed?
https://www.theepochtimes.com/semiconductors-emerge-as-battleground-in-us-china-race-to-make-global-tech-norms-in-their-image_4648523.html Although the United States and China are not engaged in traditional warfare, they are engaged in a war of ideas, trade, and technology, especially in semiconductor hegemony, where both sides are battling for supply and advancement.
https://www.piratewires.com/p/american-hustle-microchip-edition Trade was global, the world was inextricably connected, and your job’s in China now but you should thank us, actually, because everything is cheap and fast and out-of-work factory workers can simply learn to code.
CXL is supported by pretty much every hardware vendor and built on top of PCI Express for coherent memory access between a CPU and a device, such as a hardware accelerator, or a CPU and memory.
Challenges pertaining to outdated infrastructure could easily be compounded by the fact that many IT and security teams don’t seem to have a plan in place to mobilize if and when a cyberattack occurs.
Chinese military researchers are threatening that Musk's Starlink satellites must be destroyed.
I've rebuilt my data center fabrics live training class, adding a lot of new material across the board, and adding a few new topics. To cover all this new material, the class has been expanded from three to six hours. I'm teaching it for the first time on the 29th and 30th of this month.
Register here.
Lots of interesting stuff coming up this month on the Hedge, and here at Rule11 ... listen here to find out all about upcoming episodes and training.
You can register for the DC fabric training I mention in this update here.
How much of the traffic on the Internet is wasted—traffic no-one really wanted, and yet is being carried and paid for by providers and end users? In a world increasingly concerned about the waste of precious resources, this is an important topic to consider. Leslie Daigle joins Russ White and Tom Ammon on this episode of the Hedge to discuss the kinds of traffic she's seeing hit their large-scale honey-trap, and the implications for the Internet.
However, a recent study from cybersecurity training platform Hoxhunt revealed that the skill of distinguishing between legitimate and phishing emails varies based on job functions.
How will the market change in the future? Estimates of cloud market share are highly variable, with one of the biggest challenges being that different providers report different products and services in the “cloud” revenue category.
All companies should be using two-factor authentication at least to secure their systems, but relying on text messages alone is foolish, cybersecurity experts say.
The software world is known for overdue projects, costs overrun, lots of defects, and lots of failure all the way around. Many other engineering fields have stricter requirements to take on projects and liability insurance driving correct practice and care. The networking world, and the larger IT world, however, has neither of these things. Does this make IT folks less likely to "do the right thing," or is the self-regulation we have today enough? Join Tom Ammon, Eyvonne Sharp, and Russ White as they discuss the possibilities of professional liability in information technology.
I dabble with DNS for work, and I’m frequently checking if CNAMEs are properly configured. CNAMEs are Canonical NAMEs, kind of like nicknames, that indicate that one domain name is a nickname for another domain name.
Overall, A and MX queries are successfully resolved most frequently, while AAAA and PTR manifest lower success rates. Specifically, the failure rate of AAAA queries is surprisingly over 64.2% — two out of three AAAA queries failed.
Growth in hyperscaler data centers and processor-intensive enterprise workloads, such as high-performance computing (HPC) and AI, is set to drive broadscale adoption of SmartNICs.
We don't often do a post-mortem on the development and deployment of new protocols ... but here at the Hedge we're going to brave these deep waters to discuss some of the lessons we can learn from the development and deployment of IPv6, especially as they apply to design and deployment cycles in the "average network" (if there is such at thing). Join us as James Harr, Tom Ammon, and Russ White consider the lessons we can learn from IPv6's checkered history.
The US Federal Trade Commission on Thursday announced an effort to formulate privacy rules to deter unwelcome online monitoring and shoddy data security.
Cloud computing has security issues. The problem is underscored by the complexity of cloud and the lack of visibility into what’s happening with workloads inside software containers that host the components of modern applications.
Cisco's enterprise-class firewalls have at least a dozen vulnerabilities — four of which have been assigned CVE identifiers — that could allow attackers to infiltrate networks protected by the devices, a security researcher from vulnerability management firm Rapid7 plans to say in a presentation at the Black Hat USA conference on Aug. 11.
Forty years ago there was an implied loyalty between companies and employees—but that world is long gone. As much as companies would like their employees to be loyal, layoff culture has crept into every corner of the modern world, especially as we move into an economic downturn. Giovanni Messina joins Russ White and Tom Ammon to talk about being prepared to be laid off, including such topics as being financially prepared, building skills for the long term, and finding community.
From the question pile: Route servers (as opposed to route reflectors) don't change anything about a BGP route when re-advertising it to a peer, whether iBGP or eBGP. Why don't route servers cause routing loops (or other problems) in a BGP network?
Route servers are often used by Internet Exchange Points (IXPs) to distribute routes between connected BGP speakers. BGP route servers
Shouldn't using route servers in a network—pontentially, at least—cause routing loops or other BGP routing issues?
I recorded the beginnings of a BGP training series over at Packet Pushers a short while back; they've released these onto youtube (so you can find the entire series there). I'm highlighting one of these every couple of weeks 'til I've gone through the entire set of recordings. In this recording, I'm talking through some more interesting aspects of BGP peering, including challenges with IPv6 link local nexthops, promiscuous peering, and capabilities.
The distributed, peer-to-peer (P2P) InterPlanetary File System (IPFS) has become a hotbed of phishing-site storage: Thousands of emails containing phishing URLs utilizing IPFS are showing up in corporate inboxes.
Walmart's advice to companies trying to control the hefty cost of running workloads on the three largest cloud providers comes down to one word: choice.
With nearly half of all breaches involving external attackers enabled by stolen or fake credentials, security firms are pushing a high-fidelity detection mechanism for such intrusions: canary tokens.
IPv6 is still being deployed, years after the first world IPv6 day, even more years after its first acceptance as an Internet standard by the IETF. What is taking so long? George Michaelson (APNIC) joins Tom Ammon and Russ White on this episode of the Hedge to discuss the current pace of IPv6 deployment, where there are wins, and why things might be moving more slowly in other areas.
While RFC9199 (are we really in the 9000's?) is targeted at large-scale DNS deployments--specifically root zone operators--so it might seem the average operator won't find a lot of value here.
This is, however, far from the truth. Every lesson we've learned in deploying large-scale DNS root servers applies to any other large-scale user-facing service. Internally deployed DNS recursive servers are an obvious instance, but the lessons here might well apply to a scheduling, banking, or any other multi-user application accessed from a lot of places by a lot of different users. There are some unique points in DNS, such as the relatively slower pace of database synchronization across nodes, but the network-side lessons can still be useful for a lot of applications.
Hackers are now moving faster than ever when it comes to scanning vulnerability announcements from software vendors.
However, open source has an urgent security problem. Open source is more ubiquitous and susceptible to persistent threats than ever before.
You’ve done everything to secure your network, and you still face threats. That’s what most enterprises say about their network security, and they’re half right.
Wide area networks in large-scale cores tend to be performance choke-points—partially because of differentials between the traffic they're receiving from data center fabrics, campuses, and other sources, and the availability of outbound bandwidth, and partially because these routers tend to be a focal point for policy implementation. Rachee Singh joins Tom Ammon, Jeff Tantsura, and Russ White to discuss "Shoofly, a tool for provisioning wide-area backbones that bypasses routers by keeping traffic in the optical domain for as long as possible."
Why does BGP use TCP for peering? What happens if two BGP speakers begin the peering process at the same time? In this video, recorded for Packet Pushers, I start looking at the BGP peering process.
Have you ever taught a kid to ride a bike? Kids always begin the process by shifting their focus from the handlebars to the pedals, trying to feel out how to keep the right amount of pressure on each pedal, control the handlebars, and keep moving … so they can stay balanced. During this initial learning phase, the kid will keep their eyes down, looking at the pedals, the handlebars, and . . . the ground.
After some time of riding, though, managing the pedals and handlebars are embedded in “muscle memory,” allowing them to get their head up and focus on where they’re going rather than on the mechanical process of riding. After a lot of experience, bike riders can start doing wheelies, or jumps, or off-road riding that goes far beyond basic balance. Network engineer—any kind of engineering, really—is the same way.
This legislation dutifully provides trial lawyers with endless opportunities to sue Big Tech companies for something indefinable: childhood addiction to websites and phone apps. It puts the state government in charge of defining such addiction.
Recently Google employee Blake Lemoine caused a media storm over the LaMDA chatbot he was working on, that he claims is sentient (it feels things like a human being).
The problem with blockchain is that it’s not an improvement to any system—and often makes things worse.
Chris Siebenmann has written a short blog piece that reflects on the trend to see Certificate Transparency (CT) as the answer to ‘the problem’; the problem being how to tell if a validly signed and current certificate has somehow had to be repudiated.
For US$2,500, threat actors can employ Matanbuchus, a malware-as-a-service (MaaS) package found delivering Cobalt Strike beacons through phishing and spam messages.
As global and societal events such as supply chain shortages occur, there’s a corresponding increase in fraud related to fake domain registrations (websites) that capitalize on the event—creating unsafe situations for consumers.
Regional Internet Registries (RIRs) assign and manage numbered Internet resources like IPv4 address space, IPv6 address, and AS numbers. If you ever try to get address space or an AS number, though, it might seem like the policies the RIRs use to determine what kin and scale of resources you can get are a bit arbitrary (or even, perhaps, odd). Aftab Siddiqui joins Russ White and Tom Ammon to explain how and why these policies are set the way they are.
The Chinese regime and other malign actors are trying to exert their influence over global technological standards, but the UK government’s response has been “incoherent and muted,” a committee of MPs has warned.
Researchers have discovered a new attack technique that exploits the speculative execution feature of modern CPUs to leak potentially sensitive information from the kernel's memory.
The findings, which NJIT researchers will present at the Usenix Security Symposium in Boston next month, show how an attacker who tricks someone into loading a malicious website can determine whether that visitor controls a particular public identifier, like an email address or social media account, thus linking the visitor to a piece of potentially personal data.
There is a rising concern about the security of open source projects—particularly in terms of open source software supply chain. Alistair Woodman, who works closely with multiple open source software projects, joins Tom and Russ to discuss the reality of securing open source projects. The final answer? Essentially, buyer—or in the case of open source software, user—beware.
After more than a decade when cryptocurrencies and related technologies have surged, boomed, and busted in a regulatory vacuum, lawmakers in both the US and Europe are writing new rules for a sector that has grown dangerously large in both value and reach,
With the emergence of privacy regulations that assign penalties based on a business’ profit, or those that calculate a value for each compromised record, it is possible to calculate the cost of a breach based on those metrics.
What is the most expensive component in the more generic, non-accelerated servers that comprise the majority of their server fleets? Main memory, correct again.
Most network engineers take it as a "given" that the robustness principle is the "right way" to build protocols and networks—"be conservative in what you send, and liberal in what you receive." The idea behind the robustness principle is that implementations should implement specifications as accurately as possible, but they should also accept malformed and otherwise erroneous data, process the best they can, and drop the bits they cannot process. This should allow the network to operate correctly in the face of defects and other failures. A recent draft, draft-iab-protocol-maintenance/, challenges the assumptions behind the robustness principle. Join Tom and Russ as they discuss the robustness principle and its potential problems.
While this talk is titled privacy for providers, it really applies to just about every network operator. This is meant to open a conversation on the topic, rather than providing definitive answers. I start by looking at some of the kinds of information network operators work with, and whether this information can or should be considered "private." In the second part of the talk, I work through some of the various ways network operators might want to consider when handling private information.
We kick off this edition of the weekend reads with a few articles on security. Misconfigured cloud storage buckets and a failure to implement good password practices are, as always, a major source of security issues.
We found that only 15 websites were following best practices. The remaining 105 either leave users at risk for password compromise or frustrated from being unable to use a sufficiently strong password (or both).
A misconfigured Amazon S3 bucket resulted in 3TB of airport data (more than 1.5 million files) being publicly accessible, open, and without an authentication requirement for access, highlighting the dangers of unsecured cloud infrastructure within the travel sector.
An unlucky fat-fingering precipitated the current crisis: The client had accidentally deleted the private key needed to sign new firmware updates.
Zero-day defects exist in every projects, whether they are open or closed source. John Fraizer and Alistair Woodman join Tom Ammon and Russ White to discuss an old defect John found in the FRR code, the history of this defect, and the problems inherent in finding and resolving defects in large, diverse code bases.
For decades, hopeful techies have been promising a world where absolutely every object you encounter—bandages, bottles, bananas—will have some kind of smarts thanks to supercheap programmable plastic processors.
To be clear, current artificial intelligence systems are decades away from being able to experience feelings and, in fact, may never do so.
The fact that LaMDA in particular has been the center of attention is, frankly, a little quaint. LaMDA is a dialogue agent. The purpose of dialogue agents is to convince you that you are talking with a person.
IPv6's designers built the concept of Unique Local Addresses, or ULAs, into the addressing architecture to make network address translation unnecessary for IPv6 deployments. As with many other plans of mice and men, however, the unintended consequences of what is a good idea tend to get in the way. Nick Buraglio joing Eyvonne Sharp, Tom Ammon, and Russ White to discuss the many problems of IPv6 ULA, why it isn't practical in most network deployments, and the larger question of how standards bodies sometimes fail to consider the unintended consequences of a good idea.
Research by Citrix shows business leaders don't entirely trust their employees when it comes to hybrid work.
The best result for big tech is if laws are absent or useless. The latest survey of big tech lobbying in the US reveals a flotilla of nearly 500 salespeople/lawyers touring the US state legislatures, trying to either draw up tech friendly legislation to insert into privacy bills, water then down through persuasion, or just keep them off the books.
Last month, the 11th Circuit Court of Appeals held that several parts of Florida’s social media law, S.B. 7072, were likely unconstitutional.
The Iranian state-sponsored threat actor tracked under the moniker Lyceum has turned to using a new custom .NET-based backdoor in recent campaigns directed against the Middle East.
A service level agreement (SLA) is a contract between a cloud provider and a user. The SLA describes the provider’s minimum level of service, specified by performance metrics, and the compensation due to the user should the provider fail to deliver this service.
Grooming techniques used in various frauds are getting more common and more elaborate. Fraudsters are coming up with narratives that involve complicated lies and may have different stages, depending on the type of fraud.
Over the last several years various Chinese actors (telecom operators and vendors) have been pushing for modifications to IPv6 to support real-time applications and other use cases. Simon Sharwood wrote an article over at the Register on their efforts and goals. While this effort began with big IP, moved into new IP, and has been called many other names. These efforts are being put forward in various venues like the IETF, the ITU, etc. Simon Sharwood, who writes for the Register, joins Tom Ammon and Russ White to discuss these efforts.
Since BGP is designed to be an overlay protocol, it doesn't really have good mechanisms for carrying routes within an autonomous system. In this video, I'm discussing some of the techniques developed to carry routes within an AS, including route reflectors.
I'm moderating a panel at the upcoming IEEE Conference on Network Softwarization. This is one of the various "good sources" out there for understanding what might be coming in the future for computer networks. The conference is hybrid, so you can register and watch the sessions live from the comfort of your home (or office).
I'm moderating the distinguished experts panel on the afternoon of the 30th.
Please register here.
Gentle reminder that I'm teaching a three-hour webinar on Safari Books this coming Friday on Internet operations. The course is roughly divided into three parts.
The first part covers DNS operations, including a high-level overview of how DNS works and some thoughts on how DNS providers "work" financially. The second part is a high-level overview of packet transport, focusing on routing, the different kinds of providers, and how each of of the different kinds of providers "work" financially. The third part is a collection of other odds and ends.
You can register here.
Anyone who registers is able to watch a recorded version of the training afterwords.
I'm teaching part 2 next month, which I call Navigating the DFZ.
Seven months from now, assuming all goes as planned, Google Chrome will drop support for its legacy extension platform, known as Manifest v2 (Mv2). This is significant if you use a browser extension to, for instance, filter out certain kinds of content and safeguard your privacy.
But both the tools used and the threat posed by common cybercriminals pale in comparison to the tools used by more professional groups such as the famous hacking groups and state-sponsored groups.
A European team of university students has cobbled together the first RISC-V supercomputer capable of showing balanced power consumption and performance.
One of the many reasons engineers should work for a vendor, consulting company, or someone other than a single network operator at some point in their career is to develop a larger view of network operations. What are common ways of doing things? What are uncommon ways? In what ways is every network broken? Over time, if you see enough networks, you start seeing common themes and ideas. Just like history, networks might not always be the same, but the problems we all encounter often rhyme. Ken Celenza joins Tom Ammon, Eyvonne Sharp, and Russ White to discuss these common traits—ten things I know about your network.
How do you balance loyalty to yourself and loyalty to the company you work for?
This might seem like an odd question, but it's an important component of work/life balance many of us just don't think about any longer because, as Pete Davis says in Dedicated, we live in a world of infinite browsing. We're afraid of sticking to one thing because it might reduce our future options. If we dedicate ourselves to something bigger than ourselves, then we might lose control of our direction. In particular, we should not dedicate ourselves to any single company, especially for too long.
In the hands of police and other government agencies, face recognition technology presents an inherent threat to our privacy, free expression, information security, and social justice.
From social credit scores and online censorship to electronic billboards that display a citizen's "violations" like jaywalking, surveillance is a part of everyday life for millions of Chinese people.
But there's a much bigger threat to democracy coming out of Silicon Valley and it's this: America's largest financial and tech increasingly act as independent countries, routinely exporting jobs, money and technology to our most significant global adversary.
Alongside the announcement of Ryzen 7000 processors, AMD revealed a new technology coming to the platform: Smart Access Storage.
The web of global intermediary liability laws has grown increasingly vast and complex as policymakers around the world move to adopt stricter legal frameworks for platform regulation.
Like other kinds of computing, if you put garbage data into a machine learning training run and then pour new data through it, what comes out as the answer is puréed garbage.
Multi-factor testing is one of the most important jobs a vendor takes on—and one of the most underrated. Testing across all possible configurations and use cases is nearly impossible. Brooks Westbrook joins Tom Ammon and Russ White on this episode of the Hedge to talk about the complexity of multi-factor testing and some of the consequences of that complexity.
My video on BGP convergence elicited a lot of . . . feedback, mainly concerning the difference between convergence in a data center fabric and convergence in the DFZ. Let's begin here—BGP hunt and the impact of the MRAI are very real in the DFZ. Withdrawing a route can take several minutes.
What about the much more controlled environment of a data center fabric?
Several folks pointed out that the MRAI is often set to 0 in DC fabrics (and many implementations by default). Further, almost all implementations will use an MRAI of 0 for the first received update, holding the second and subsequent advertisements by the MRAI. Several folks also pointed out that all the paths through a DC fabric are the same length, so the second part of the equation is also very small.
These are good points—how do they impact BGP convergence? Let's use the network below, a small slice of a five-stage butterfly fabric, to think it through. Assume every router is in a different AS, so all the peering sessions are eBGP.
This edition of weekend reads begins with a few straight security stories of interest. I knew key loggers existed in the wild, but the logging of keystrokes before a web form is submitted is apparently a lot more common than I realized—
They found that 1,844 websites gathered an EU user's email address without their consent, and a staggering 2,950 logged a US user's email in some form. Many of the sites seemingly do not intend to conduct the data-logging but incorporate third-party marketing and analytics services that cause the behavior.
Illustrating that security is often a game of "whack-a-mole," web skimmers are obfuscating their operation—
Microsoft security researchers recently observed that web skimming campaigns now employ various obfuscation techniques to deliver and hide skimming scripts.
We all intuitively know the DNS is complex—and becoming more complex over time. Describing just how complex, however, is difficult. Siva Kesava and Ryan Beckett just published a research paper taking on the task of describing DNS complexity, particularly in light of the new DNAME record type. It turns out its complex enough that you can no longer really validate zone files.
This lesson in Russ White’s BGP course gets into withdrawing a route, MRAI time, implicit withdraws, BGP Hunt, graceful restart, and other topics.
Original link at Packet Pushers here
Leading off this weekend, an article by Simon Sharwood on the impact of the centralization of the Internet. I wrote a somewhat longer article on the Public Discourse a while back on the same topic.
The internet has become smaller, the result of a rethinking of when and where to use the 'net's intended architecture. In the process it may also have further concentrated power in the hands of giant technology companies.
Is softwarization really going to change the way we build networks from the ground up? I suspect things will change, but they've always changed. I also suspect we'll be hearing about how software is going to eat the world ten years from now, and IPv6 still won't be fully deployed.
DOCSIS 4.0 is set to deliver faster speeds for cable network operators, but the next generation technology will also spur an operational sea change, telecom consultant Sean McDevitt told Fierce.
One of the mainstays of scripting—and now network management—are increasingly focused on making things "easier" for the human operator. Does this focus on making things "easier" for the operator produce a better experience, though? Or does it create frustration as humans try to "outguess" the computer's programming and process? Join Tom Ammon and Russ White as they discuss the problems with scripting, automation, and ease-of-use.
The steepening trajectory towards event-driven and real-time API architecture is imminent.
The idea of this declaration has a lot to do with the “Past of the Internet.” When the Internet was developing in the 1980s and 1990s, it was seen primarily as a tool that would expand individual freedoms worldwide, strengthen democracy, and create prosperity through innovation and economic progress.
I’m not sure that most people understand the extent to which our online experience has moved to the cloud – and this movement to the cloud means we’re using a lot more bandwidth than in the recent past.
Inventories are generally hard, and hence don't tend to be where you'd like to spend your time. The importance of having a good inventory, however, can hardly be overstated. Malcom Booden joins Tom Ammon and Russ White to talk about the importance of inventories and inventory ideas.
Over at Packet Pushers—
Russ White’s BGP series continues with a discussion of building loop-free paths with the Border Gateway Protocol (BGP). Topics include AS (Autonomous System) paths, loop prevention, why loop checks are inbound, and more on IBGP and EBGP.
Cloudflare, a company that specializes in web security and distributed denial of service (DDoS) attack mitigation, just reported that it managed to stop an attack of an unprecedented scale.
Cloud operators provide price incentives so that users gravitate towards newer generations (and between server architectures). Figure 1 shows lines of best fit for the average cost per virtual central processing unit (vCPU, essentially a physical processor thread as most processor cores run two threads simultaneously) of a range of AWS virtual instances over time.
Passwordless sign-ins are already a practical reality, but they're sometimes clunky — and three of the biggest tech companies believe they can reduce the friction.
Mentoring is a topic we return to time and again—because it's one of the most important things we can talk about in terms of building your people skills, your knowledge, and your career. On this episode of the Hedge, Guedis Cardenas joins Tom Ammon and Russ White to talk about open source mentoring. We discuss how this is different than "regular" mentoring, and how it's the same. Join us as we talk about one of the most important career and personal growth things you can do.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
There are cases where an operator does not traffic to be forwarded to them through some specific AS, whether directly connected or multiple hops away. For instance, AS65001 and AS65005 might be operated by companies in politically unfriendly nations. In this case, AS65001 may be legally required to reject traffic that has passed through the nation in which AS65005 is located. There are at least three mechanisms in BGP that are used, in different situations, to enforce this kind of policy.
In January a federal judge denied Facebook’s motion to dismiss the Federal Trade Commission’s amended complaint seeking to force the company to sell off Instagram and WhatsApp.
Tech companies earn staggering profits by targeting ads to us based on our online behavior. This incentivizes all online actors to collect as much of our behavioral information as possible, and then sell it to ad tech companies and the data brokers that service them.
And often, when doing business in these countries, company’s interests in revenue and profits conflict with America’s national security interests, a conflict that profit always seems to win.
Video meetings dampen brainstorming because we are so hyper-focused on the face in that box that we don’t let our eyes and minds wander as much, a new study found.
Have you recently been on a video confefence call, hit the "mute" button and then offered up some nasty comments about a client or a colleague — or even the boss?
Comcast and other broadband providers are utilizing 10G technology in their quest to deliver “multigigabit symmetrical speeds” to the consumer market.
A short update on upcoming classes and episodes of the Hedge for May, as well an update on what I'm working on and other places where I'm publishing material.
On the 27th of May, I'll be teaching a three-hour course called How Routers Really Work? From the course description:
This training will peer into the internal components of a router, starting with an explanation of how a router switches packets. This walk through of a switching path, in turn, will be used as a foundation for explaining the components of a router, including the various tables used to build forwarding tables and the software components used to build these tables.
Sign up here.
Have you ever thought about getting a college degree in computer networking? What are the tradeoffs between this and getting a certification? What is the state of network engineering at colleges—what do current students in network engineering programs think about their programs, and what they wish was there that isn't? Rick Graziani joins Tom Ammon and Russ White in a broad ranging discussion on network engineering and college. Rick teaches network engineering full time in the Valley.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
In this post I'm going to cover local preference via communities, longer prefix match, and conditional advertisement from the perspective of AS65001 in the following network—
My third article on privacy and networking is up over at Packet Pushers—
Here’s a question for network or application folks tasked with protecting user and/or customer privacy: Is an IP address personally identifiable information (PII)? While there are many kinds of PII in networks (see the last column for more details), the IP address is just about the most common.
Our current encryption standards protect our bank accounts, financial markets, and most of our infrastructure, not to mention the logistics/supply-chain management system in the US Defense Department. But what happens when quantum computers can decipher the current asymmetric encryption that protects our vital systems?
Local governments all over the country are choosing ISP partners and making grants from ARPA funds to help bring better broadband. Today’s blog is a warning to handle the awards of such monies in a way as to be safe from challenges from ISPs you don’t choose to fund.
In a resounding victory for companies whose business model depends on web scraping, the U.S. Ninth Circuit Court of Appeals held this week that such activity does not violate the U.S. Computer Fraud and Abuse Act.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
In this post I'm going to cover AS Path Prepending from the perspective of AS65001 in the following network—
Agencies of the US Government have issued a joint warning that hackers have revealed their capability to gain full system access to industrial control systems that might help enemy states sabotage critical infrastructure.
Whether you consider them black swan cyber events or not, the SolarWinds attack and the Log4Shell exploit stressed some of the key ways in which organizations can prepare themselves and prevent crises.
The serious lesson from that is to acknowledge but forgive errors. "He's said, many times, that he knew at that moment it was going to be OK," Ellis says. "Creating a safe culture requires a lot of practices, and one of them is closure. Humor is a great way to provide closure because you rarely laugh about something that is still creating tension."
The US Federal Communications Commission recently asked for comments on securing Internet routing. While I worked on the responses offered by various organizations, I also put in my own response as an individual, which I've included below.
The FR Routing project is a fully featured open-source routing stack, including BGP, OSPF, and IS-Is (among others), supported by a community including NVDIA, Orange, VMWare, and many others. On today's episode of the Hedge, Tom Ammon and Russ White are joined by Donald Sharp, Alistair Woodman, and Quentin Young to update listeners on projects completed and underway in FR Routing.
My second post on privacy for network engineers is up over at Packet Pushers—
Given the arguments from the first article in this series, if privacy should be and is essential—what does the average network engineer do with this information? How does privacy impact network design and operations? To answer this question, we need to look at two other questions.
Quantum computing startups are all the rage, but it’s unclear if they’ll be able to produce anything of use in the near future.
A few years ago, Ken Crum started getting uncomfortable with how much of his life seemed to be online. The long-time computer programmer was particularly concerned by what companies appeared to know about him.
In a future release of Windows 11, you’re going to see significant security updates that add even more protection from the chip to the cloud by combining modern hardware and software.
ISDN, while an old technology, is still around in many parts of the world. When will it go away? George Michaelson joins Tom Ammon and Russ White to discuss the end of ISDN. The conversation then veers into old networking technologies, and the importance of ISDN in setting the terms and ideas we use today—ISDN is one of the key technologies around which network engineers built their mental maps of how to build and maintain networks.
I'm teaching a three-hour webinar on troubleshooting on the 22nd of April:
This training focuses on the half-split system of troubleshooting, which is widely used in the electronic and civil engineering domains. The importance of tracing the path of the signal, using models to put the system in context, and the use of a simple troubleshooting “loop” to focus on asking how, what, and why are added to the half-split method to create a complete theory of troubleshooting. Other concepts covered in this course are the difference between permanent and temporary fixes and a review of measuring reliability. The final third of the course contains several practical examples of working through problems to help in applying the theory covered in the first two sections to the real world.
This is offered on Safari Books Online through Pearson. I think that if you register for the course, you can watch a recording later.
Register here.
You can register for my network troubleshooting course here. Information about the IEEE Network Softwarification Conference can be found here.
Our upcoming episodes for this month are George Michaelson on the death of ISDN and old networks; an update on the FR Routing project; and Rick Graziani on college and network engineering. Thanks for listening to the Hedge!
These guidelines are not about finding a perfectly secure solution but about practical, immediate possible actions with respect to email, instant messaging, voice and video chats, and other important security measures to consider.
The governance of an IXP can deeply affect its development. The difficulty of stating a clear management policy for IXP is the main challenge that limits the growth, sustainability and success of IXPs. In the past years, there have not been enough initiatives that support creating such policies for IXP management.
European telecommunication service providers are being pushed to pick up the pace regarding 5G adoption. However, the next-gen technology requires immense data capacity and transmission speeds, thus setting up the new infrastructure is no easy task for telcos.
DC fabric design is more of an art than a science—a lot of factors come into play, such as future growth, lifecycle management, security, and costs. How can network engineers balance these various factors—how do they even know what questions to ask? Brooks Westrbook joins Tom Ammon and Russ White to discuss three- and five-stage DC fabric design, OPEX, CAPEX, and other topics on this episode of the Hedge.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
In this post, I'll cover the first of a few ways to give surrounding autonomous systems a hint about where traffic should enter a network. Note this is one of the most vexing problems in BGP policy, so there will be a lot of notes across the next several posts about why some solutions don't work all that well, or when they will and won't work.
There are at least three reasons an operator may want to control the point at which traffic enters their network, including:
An FBI intelligence memo from March 18 obtained by CBS has revealed that currently 140 or more Russian–based IP addresses are conducting “abnormal scanning activity” of companies in the U.S. energy sector.
In this second part, I lay out a set of recommendations for ways to help ensure that these entanglements of industry and academia don’t grant companies undue influence over the conditions of knowledge creation and exchange.
AvosLocker is a ransomware-as-a-service (RaaS) gang that first appeared in mid-2021. It has since become notorious for its attacks targeting critical infrastructure in the United States, including the sectors of financial services, critical manufacturing, and government facilities.
Another year of massive growth in the number and speed of connections to the global Internet—what is the impact on the global routing table? Goeff Huston joins Donald Sharp and Russ White to discuss the current state of the BGP table, the changes in the last several years, where things might go, and what all of this means. This is part two of a two-part episode.
Assume AS65001 is some form of content provider, which means it offers some service such as bare metal compute, cloud services, search engines, social media, etc. Customers from AS65006 are connecting to its servers, located on the 100::/64 network, which generates a large amount of traffic returning to the customers. From the perspective of AS hops, it appears the path from AS65001 to AS65006 is the same length—if this is true, AS65001 does not have any reason to choose one path or another (given there is no measurable performance difference, as in the cases described above from AS65006’s perspective). However, the AS hop count does not accurately describe the geographic distances involved...
A Chinese national was recently caught entering China with 160 Intel processors strapped to his body, an act that customs officials amount to smuggling.
In 2022, Facebook has 2.91 billion active users, making it the most-used social media platform. But to me, it will always pale in comparison to early MySpace.
As a CSIRT consultant, I cannot overemphasize the importance of effectively managing the first hour in a critical incident.
Another year of massive growth in the number and speed of connections to the global Internet—what is the impact on the global routing table? Goeff Huston joins Donald Sharp and Russ White to discuss the current state of the BGP table, the changes in the last several years, where things might go, and what all of this means. This is part one of a two-part episode.
Sorry for the short notice ... I'm teaching a three-hour webinar on DC fabrics and control planes this coming Friday, the 25th, through Safari Books Online. This course covers the basics of spine-and-leaf fabrics, as well as some high level information on various DC fabric control plane options (BGP, RIFT, and IS-IS). Please register here.
If you work in advertising or marketing, you’re probably aware of Apple’s privacy efforts over the last year. Apple now requires apps ask customers if they want to 'opt-in' to allow behavioral data tracking.
Among gamers and parents and even within the medical community, there’s disagreement about whether gaming addiction is real.
When discussing our relationship with technology, for whatever reason—whether it’s due to aimless maximum engagement algorithms, the ruthless economic incentive structure of the global market, or just our own sheer inability to think critically in the face of incessant propaganda—we’re led to believe that there are only two possible paths from here: 1. Integration with Technology or 2. Luddism.
We should instead be choosing authentication processes that appropriately match site risks; using a password should be the last thing you want to rely on.
Public companies would have to report material cybersecurity incidents no later than four business days after they occur if a rule proposed by the Securities and Exchange Commission (SEC) on Wednesday takes effect.
Researchers have disclosed a new technique that could be used to circumvent existing hardware mitigations in modern processors from Intel, AMD, and Arm, and stage speculative execution attacks such as Spectre to leak sensitive information from host memory.
What is the Internet Architecture Board (IAB) of the IETF? What role does the IAB play in the larger ecosystem of building and deploying standard protocols? In this episode of the Hedge, Tom and Ethan "flip roles" with Russ to ask these questions.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
There are many reasons an operator might want to select which neighboring AS through which to send traffic towards a given reachable destination (for instance, 100::/64). Each of these examples assumes the AS in question has learned multiple paths towards 100::/64, one from each peer, and must choose one of the two available paths to forward along. This post wil consider selecting an exit point from the perspective of two more autonomous systems.
The big ISPs all lobbied hard against the net neutrality rules, but the CEO of every big ISP was on the record at least once saying that the net neutrality rules were not a big deal and that they could live with net neutrality. So why did the big carriers lobby so hard about what the FCC was doing?
VESA, which makes the DisplayPort spec, today announced a certification program aimed at helping consumers understand if a DisplayPort 2.0 cable, monitor, or video source can support the max refresh rates and resolutions the spec claims.
Over the past week, the Akamai researchers said, they have detected multiple DDoSes that used middleboxes precisely the way the academic researchers predicted. The attacks peaked at 11Gbps and 1.5 million packets per second.
Can computation be drawn into the network, rather than always being pushed to the edge of the network? Taking content distribution networks as a starting point, the COIN research group is looking at ways to make networks more content and computationally aware, bringing compute into the network itself. Join Alvaro Retana, Marie-Jose Montpetit, and Russ White, as we discuss the ongoing research around computing in the network.
At the most basic level, there are only three BGP policies: pushing traffic through a specific exit point; pulling traffic through a specific entry point; preventing a remote AS (more than one AS hop away) from transiting your AS to reach a specific destination. In this series I'm going to discuss different reasons for these kinds of policies, and different ways to implement them in interdomain BGP.
The notion that email security should be prioritized is emphasized during this time where more and more businesses are still working in a remote or hybrid dynamic environment.
After quizzing 8,000 job applicants and 2,250 hiring managers in the U.S., Germany, and Great Britain, researchers at Harvard Business School, working with the consultancy Accenture, discovered that many tens of millions of people are being barred from consideration for employment by résumé screening algorithms that throw out applicants who do not meet an unfeasibly large number of requirements, many of which are utterly irrelevant to the advertised job.
We developed attacks that exploit the transparency of the DNS lookups to tunnel injection payloads over DNS records. These attacks exploit two key factors. Firstly, DNS resolvers do not alter the DNS records received in lookups, so the malicious payload is preserved intact
In today's Internet, packets are at the core of information flows. Routers only know (very minimally) about what is in the packets they're carrying around. Caching and content distribution networks (CDNs) are used to place information at various locations throughout the 'net for users to access, making the distribution of this information more efficient. Information Centric Networking "flips the script," making named information, rather than packets, the core construct of networks.
To some degree, cyber AI suffers from the pressures exerted by the quest for never-ending sales growth.
The websites for several banks in Ukraine, the Ministry of Defense, and Armed Forces were hit with a distributed denial-of-service (DDoS) attack on Feb. 15.
Threat actors are using software and developer infrastructure, platforms, and providers as valuable entry points into governments, corporations, and critical infrastructure.
Cybercriminals and nation-state actors adapted to defenders' tactics and became more efficient in 2021, with attackers relying more on data leaks combined with ransomware to extort increasing sums of money from companies — and in some cases using data leaks without encrypting data to force a company to pay, according to two analyses published this week.
Marketing is an underappreciated (and even demonized) part of the process in creating and managing networking products. Cathy Gadecki of Juniper joins Russ White and Tom Ammon on this episode of the Hedge to fill in the background and discuss the importance of marketing, and some of the odd corners where marketing impacts product development.
The main purpose of algorithms, like digital programs and datacenters more broadly, is not to make money or influence thoughts, but to control people—in a direct and alien way hostile to our core beliefs and principles.
But as I testified to the Senate last week, you can basically reidentify anything. “Anonymity” is an abstraction.
Many people think that NoSQL databases are the “next big thing” in technology, and that we should write all of our core applications using them. However, NoSQL databases actually predate relational databases, and common relational databases were established to solve the problems that NoSQL brings.
A new DeadBolt ransomware group is encrypting QNAP NAS devices worldwide using what they claim is a zero-day vulnerability in the device's software.
A simulated phishing attack against more than 82,000 workers found that emails with a personal impact resulted in more clicks and that technical teams — such as IT workers and DevOps teams — clicked just as often and reported suspected phishing attacks less often compared with nontechnical teams
Google on Tuesday announced that it is abandoning its controversial plans for replacing third-party cookies in favor of a new Privacy Sandbox proposal called Topics, which categorizes users' browsing habits into approximately 350 topics.
When vendors build something new—or when you decide to go a different direction in your network—you have to figure out how to integrate these new things. Integration of this type often includes cultural, as well as technical, changes. William Collins joins Tom Ammon and Russ White to discuss his experience in integrating new technologies on Hedge 118.
I'm teaching a three-hour webinar on privacy over at Safari Books on Friday. From the description there—
Privacy is important to every IT professional, including network engineers—but there is very little training oriented towards anyone other than privacy professionals. This training aims to provide a high-level overview of privacy and how privacy impacts network engineers. Information technology professionals are often perceived as “experts” on “all things IT,” and hence are bound to face questions about the importance of privacy, and how individual users can protect their privacy in more public settings.
Please join me for this—it's a very important topic largely ignored in the infrastructure space.
I'm speaking (in person) at NANOG84 on providers and privacy—
Privacy is a hot topic, but there's little information for the networking professional in this area. This presentation will provide a quick overview and thoughts on the area of privacy aimed at transit provider operations personnel, including packet processing and logging. Note this presentation does not constitute legal advice, but rather just presents general concepts and thoughts from the perspective of a network engineer in an area of interest.
Continuing our series on how vendors build networking products, Mike Bushong joins this episode of the Hedge to discuss the overall process, the importance of the product manager, and the importance of managing and selling change. Join Tom Ammon, Eyvonne, and Russ White as we discuss how vendors build products.
On the 10th of February (next week) I'm participating in a panel discussing—
A networking strategy involving disaggregation deployment, overlay network virtualization, automation, and visibility can remedy the complexities with better utilization and performance and ultimately enable network slicing and self-healing abilities. Cloudification of the network is here, but how far do we need to go, and what is the impact on the hardware?
You can find more information about joining here.
I've kicked off a series over at Packet Pushers on the ; the first installment is up now.
DigiTimes reports that processor prices are set to increase “substantially” in 2022 due to a boost in foundry costs. Specifically, processors based on the sub-7nm process nodes are expected to be more expensive moving forward.
For the past four months, Apple’s iOS and iPadOS devices and Safari browser have violated one of the Internet’s most sacrosanct security policies. The violation results from a bug that leaks user identities and browsing activity in real time.
Although the advisory discussed above is specific to Russian threat actors, the lessons learned and approaches to preparedness, detection, and prevention are generically applicable to a wide range of threats for both IT and OT.
Jack Schofield, a prolific journalist covering computers and computing, developed three "laws" across his thirty years of reporting that have come to be known as Schofield's Laws of Computing. What are these laws, and how do they apply to the modern computing landscape—especially for the network engineer? Join Tom Ammon and Russ White as they discuss Schofield's Laws of Computing.
When youâre out and about, and especially when youâre traveling, you might find yourself feeling quite a bit of anxiety when logging into public Wi-Fi.
There are a lot of resources out there on Twitter, Reddit, and YouTube about this epic vulnerability. I wanted to create this post to summarize the main things I learned, ways to test it as pentester, and the mitigation controls that help prevent the exploitation of this vulnerability.
A Romanian vulnerability researcher has discovered more than 70 flaws in combinations of cloud applications and content delivery networks (CDNs) that could be used to poison the CDN caches and result in denial-of-service (DoS) attacks on the applications.
As we look ahead into 2022, the datacenter compute landscape is considerably richer than it was a decade ago.
In a perfectly regulated industry, both the industry and the public should be miffed at regulators for not fully supporting their issues.
One could argue that the last few years have highlighted some of the most pressing semiconductor industry issues but there are challenges on the horizon well beyond current supply chain and silicon manufacturing bottlenecks.
In light of recent incidents that impacted both information technology (IT) and operational technology (OT) environments, organizations are increasingly evaluating the risks associated with growing IT/OT convergence.
In this post, I want to go into more detail on how we use Suzieq to validate key aspects of the network, as well as Batfish, which we use for evaluating the validation process.
On the surface, ISO 27701 and GDPR are entirely different. The GDPR is a mandatory regulation for companies handling European data, and ISO 27701 is an extension of an optional certification, ISO 27001. Despite their differences, they contemplate many of the same considerations.
The Graviton family of Arm server chips designed by the Annapurna Labs division of Amazon Web Services is arguably the highest volume Arm server chips the datacenter market today, and they have precisely one â and only one â customer. Well, direct customer.
If you look at the past, patch management was not a cybersecurity issue; rather, it was an IT issue. And it wasn’t until the emergence of Code Red in 2001 when Microsoft started issuing patches to plug security vulnerabilities in its software.
Verizon and AT&T said on Monday that they have voluntarily agreed to further delay the rollout of their next-generation 5G wireless technology at the request of U.S. Transportation Secretary Pete Buttigieg.
During our 2021 Financial Institution Cyber Drill, 204 security professionals in 38 teams were given the task to act as âIncident Handlersâ and identify, investigate and provide recommendations to resolve these issues from the artifacts provided by BGD e-GOV CIRT.
Cybersecurity researchers have detailed a high severity flaw in KCodes NetUSB component that’s integrated into millions of end-user router devices from Netgear, TP-Link, Tenda, EDiMAX, D-Link, and Western Digital, among others.
Leichtman Research Group recently conducted a nationwide poll of 2,000 households asking about broadband usage.
Proving that whenever you buy something new, a better thing immediately comes out, the PCI-Sig Group announced the release of PCIe 6.0 on Tuesday, which will double the raw data rates of the PCIe 5.0 technology that only just debuted in Intelâs 12th-gen âAlder Lakeâ Core processors.
Physicists from Lancaster University say that we might be close to combining them into a single piece of hardware, which they call UltraRAM.
Not every manufacturing node comes out perfectly and not every one comes out on time, but in the past decade and a half, Taiwan Semiconductor Manufacturing Co, the worldâs largest and most technologically advanced etcher of chips in the world, has done far better than any of its few remaining peers to push the chip manufacturing envelope while also maintaining consistent and profitable production of older nodes.
The attacker starts with a legitimate URL for a sensitive profile page but appends an invalid path component disguised as a static file â a style sheet.
The first half of the year saw massive ransomware attacks that affected parts of critical infrastructure all around the world, as well as a vulnerability in IT management software. This vulnerability targeted the public sector, credit unions, schools, and other essential services.
But in more recent years, Wazawaka has focused on peddling access to organizations and to databases stolen from hacked companies.
Satellite broadband made the news again recently when the Chinese government said it had to adjust the orbits of the Chinese space station to avoid collisions with Starlink satellites. China claims it had to make adjustments in July and October of last year.
HTTPS was proposed to address this issue and has greatly improved security, protecting web traffic from eavesdropping and tampering. However, HTTPS doesnât solve the problem of trust.
Despite the many benefits that public Wi-Fi has to offer, there are also some downsides that could be a reason to either avoid it altogether or take precautions to be safe when using it.
Devops is the new normal—but, far too often, operations folks (like network engineers) are expected to become full-on developers, and developers are expected to understand operations in ways they never had to before. Mat Duggan joins Tom Ammon and Russ White to discuss why operations is not development IT
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-115.mp3 download
I’ve recently finished my 16th book (according to Goodreads, at any rate). This one is a little different than my normal fare—it’s essentially an expanded and revised version of the dissertation. Rather than being about technology proper, this latest is an examination of the history and philosophy of the superset of social media, which I’ve dubbed neurodigital media.
Fair warning, some readers might find this book a little … controversial.
From the back of the book—
Social media, shopping experiences, and mapping programs might not seem like they have much in common, but they are all built on neurodigital media. What is neurodigital media? It lives at the intersection of the Californian Ideology, the digital computing revolution, network ecosystems, the nudge, and a naturalistic view of the person. The Californian Ideology holds individuals should be reshaped, naturalism says individuals may be reshaped, and digital computing provides the tools, through network ecosystems theory and the nudge, that can reshape individuals. This book explores the history and impact of neurodigital media in the lives of everyday users.
Hardware hacking isn’t a topic most network engineers are familiar with—but we always used to say that if I can get access to the console of a router, I can eventually get into the box. The same is largely true of all kinds of computing hardware, including laptops, compute nodes connected to a data center fabric, and, again, routers and switches. In this episode of the Hedge, Federico Lucifredi joins Tom Ammon and Russ White to discuss the many options hardware hackers have today.
download
I’m a little late in posting this, but I thought I’d put it out here anyway. Tomorrow I’m teaching through a three-hour webinar, How the Internet Really Works part 2. From the session description—
This training will provide short reviews of many of these systems and a deeper look at the many tools network engineers can use to discover the information they need to navigate through the DNS and routing systems on the global Internet. This training will be arranged as a set of case studies posing a problem, and then working through tools available to gather the information needed to understand the problem.
You can register here.
Over the last few episodes of the Hedge, we’ve been talking to folks involved in bringing network products to market. In this episode, Tom Ammon and Russ White talk to Jeff Jakab about the role of the Product Line Manager in helping bring new networking products to life. Join us to understand the roles various people play in the vendor side of the world—both so you can understand the range of roles network engineers can play at a vendor, and so you can better understand how products are designed, developed, and deployed.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-113.mp3 download
Software Eats the World?
Iâm told software is going to eat the world very soon now. Everything already is, or will be, software based. To some folks, this sounds completely wonderful, butâleaving aside the privacy issuesâI still see an elephant in the room with this vision of the future.
Quality.
Let me give you some recent examples.
First, ceiling fans. Modern ceiling fans, in case you didnât know, donât rely on the wall switch and pull chains. Instead, they rely on remote controls. This is brilliantâyou can dim the light, change the speed of the fan, etc., from a remote control. No unsightly chains hanging from the ceiling.
Well, itâs brilliant so long as it works. Iâve replaced three of the four ceiling fans in my house. Two of the remote controls have somehow attached themselves to two of the three fans. Itâs impossible to control one of the fans without also controlling the other. They sometimes get into this entertaining mode where turning one fan off turns the other one on.
For the third oneâthe one hanging from a 13-foot ceilingâthe remote control sometimes operates one of the other fans, and sometimes the fan its supposed to operate. Most of the time it doesnât seem to do much of anything.
The fan manufacturerâa large, well-known companyâmentions this situation in their instructions and points to a FAQ that doesnât exist. Searching around online I found instructions for solving this problem that involve unwiring the fans and repeating a set of steps 12 times for each fan to correct the situation. These instructions, needless to say, donât work.
There is no way to reset the remote, nor the connection between the remote and the fan. There is no way to manually select some dip switch so the remote has a specific fan it talks to. Just some mystical software thatâs supposed to work (but doesnât) and no real instructions on how to resolve the problem. The result will be a multi-hour wait on a customer support line, spending hours of my time to sort the problem out, and the joy of climbing (tall) ladders to unwire and wire ceiling fans in four different rooms.
Thinking through possible problems and building software interfaces that take those situations into account ⦠might be a bit more important than we think they are if software is really going to eat the world.
Second, the retailerâs web siteâa large retailer with thousands of physical stores across the United States. Twice Iâve ordered from this site, asking to have the item held in the local store so I can pick it up. The site wonât let you order the item for store pickup unless they have it in stock.
The first time they called me to say they couldnât find the item I ordered, but they found a ânewer modelâ that was a lot less expensive. It was a lot less expensive because it wasnât the same item. They never did find the item I originally ordered.
The second time they called me to say they couldnât find the item I ordered. I asked if they could just ship the item to my house when itâs back in stock. âIâm sorry, our system doesnât allow us to do that â¦â Several hours later, they called back to tell me they found it, but they cannot reinstate my orderâI must place a new order.
Again, software quality strikes ⦠what should be a simple process just isnât. There will always be mismatches between the state in software and the state in the real worldâbut design the system so itâs possible to adapt when this happens, rather than shutting down the process and starting over.
Third, I own a car that has all the âbells and whistles,â including an adaptive cruise control system. There are certain situations, however, where this adaptive control does the wrong thing, producing potentially dangerous results. There is no way to set the car to use the non-adaptive cruise control permanently (I called and waited on the phone for several hours to discover this). You can set the non-adaptive cruise control on a per-use basis by going through set of menus to change the settings ⦠while driving.
Software quality anyone?
Software eats the world might be someoneâs ultimate dreamâbut I suspect that software quality will always be the fly in the ointment. People are not perfect (even in crowds); software is created by people; hence software will always suffer from quality problems.
Maybe a little humility about our ability to make things as complex as we might like because âwe can always have software do that bitâ would be a good thingâeven in the networking world.
Unfortunately, when engineers are entrusted with the task of delivering smooth video streaming to our users, we face numerous challenges from âlast-mileâ wireless connections.
Exploit code has been released for a serious code-execution vulnerability in Log4j, an open source logging utility that’s used in countless apps, including those used by large enterprise organizations, several websites reported last Thursday.
The Tuesday outage at an Amazon Web Services data center affected services from several collaboration software vendors, highlighting how reliant companies have become on cloud providers for a variety of workplace tools.
Amazon.com Inc.âs ubiquitous cloud-computing network, the spine for a lot of digital communications and transactions across the U.S., went dark for several hours on Tuesday.
This is the hoarderâs mentality. âI canât use this right now, but maybe I will some other time.â
More than 35,000 Java packages, amounting to over 8% of the Maven Central repository (the most significant Java package repository), have been impacted by the recently disclosed log4j vulnerabilities
So much for a quiet holiday season: CVE-2021-44228 (aka Log4Shell) may well be the most impactful vulnerability we’ve seen in years.
Cybersecurity researchers have demonstrated a new attack technique that makes it possible to leverage a device’s Bluetooth component to directly extract network passwords and manipulate traffic on a Wi-Fi chip, putting billions of electronic devices at risk of stealthy attacks.
In late 2021, the term Web3 began to increasingly appear in mainstream media outlets. This does not refer, however, to a sudden increase in interest in the Semantic Web as defined by Tim Berners-Lee, but rather to something entirely different.
It also found affected hospitals had tens of thousands of outdated Windows 7 systems, and that the health systemâs IT administrators failed to respond to multiple warning signs that a massive attack was imminent.
At 10:30 p.m. PST on Oct. 6, Twitch released the following statement on its corporate blog: “We have learned that some data was exposed to the internet due to an error in a Twitch server configuration change that was subsequently accessed by a malicious third party.”
The HDMI Licensing Administrator, the group that defines and licenses HDMI standards, has some confusing requirements around the HDMI 2.1 standard.
Intel issued a press release, unveiling various advancements in the fields of packaging, transistor, and quantum physics. The company has stated that these new findings were made in pursuit of Mooreâs Law.
The Technical Marketing role is often misunderstood—or simply forgotten—in the vendor world. What does the TME do, and why? What value does the TME bring to the development and release of new products? Pete Lumbis joins Tom Ammon and Russ White to discuss the importance and value of the TME.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-112.mp3 download
In a highly anticipated decision, a judge of the United States International Trade Commission ruled in August that Google infringed five patents owned by speaker maker Sonos. The case charged Google with copying Sonos’ patented technology in its Google Home smart speakers.
If youâve followed the news over the last few years, youâre probably convinced that weâre living in a golden age of conspiracy theories and disinformation.
Americans, and not just Americans, are well aware of how deep the dysfunction of the ruling factions runs. Many older ones remember the abuses of the Intelligence Community and the warnings against the Military-Industrial Complex; they have lived long enough to see the political resistance to the Community and the Complex shift, under pressure of deliberate policies, from the Left to the Right.
The rumors spread like wildfire: Muslims were secretly lacing a Sri Lankan villageâs food with sterilization drugs. Soon, a video circulated that appeared to show a Muslim shopkeeper admitting to drugging his customers â he had misunderstood the question that was angrily put to him.
Antitrust has not had its moment since the 1911 breakup of Standard Oil. But this past year, policymakers and government leaders around the globe have been taking a hard look at the technology markets.
For well over a decade, I have been arguing that governments should create IT accident investigation boards for the exact same reasons they have done so for ships, railroads, planes, and in many cases, automobiles.
Yet risks remain, and once the genie is out of the bottle, they are often difficult to manage and containâthey range from unintended consequences and side effects to threats to privacy and loss or misdirection of control.
How can we change the field of computing so that ethics is as central a concern as growth, efficiency, and innovation? There is no one intervention to change an entire field: instead, broad change will take a combination of guidelines, governance, and advocacy.
Jerome Pesenti, Facebookâs VP of Artificial Intelligence, explains the changes to the face recognition system that have accompanied the very recent brand name change from Facebook to Metaâ¦
The dominant regime of the electric ageââdemocracyâ mediated and managed by corporate journalists, academics, expertsâis being slowly eaten by a new cybernetic order, mediated by algorithm and increasingly not managed at all.
The metaverse is, as they say, happening. Mark Zuckerberg announced last month that Facebookâs parent company, now called Meta, will take the lead in building out an immersive, interactive, and ubiquitous network of virtual environments that he envisions as the next phase of the Internet.
When Google introduced Manifest V3 in 2019, web extension developers were alarmed at the amount of functionality that would be taken away for features they provide users. Especially features like blocking trackers and providing secure connections.
In preventing people like me from accessing Twitter despite plainly qualifying under their own terms of service â and in failing to provide the kind of communication Dorsey testified under oath occurs in situations like mine â Twitter is arguably engaging in fraud, telling the public one thing while engaging in the opposite.
Privacy law is manifested in practice as a litany of âAgreeâ buttons to consent to data collection and a series of long, convoluted statements of data collection practices that are supposed to give users enough notice about what companies do with our data to enable us to make informed decisions.
Itâs been 24 hours since Jackâs resignation, and while Iâm not really interested in the evolving loser drama surrounding the new CEOâs decade-old tweets, it is worth noting that Twitter has already updated its content policy in a manner that effectively makes citizen journalism impossible.
In one of the more unusual cybersecurity policing stories of the past year, the FBI announced in June that it had created its own company, called ANOM, to sell devices with a pre-installed encrypted messaging app to criminals.
In its response to Stosselâs defamation claim, Facebook responds on Page 2, Line 8 in the court document (download it below) that Facebook cannot be sued for defamation (which is making a false and harmful assertion) because its âfact checksâ are mere statements of opinion rather than factual assertions.
While GDPR has provided essential data protections for Europeans, it has also imposed substantial compliance costs on American companies seeking to do business in the bloc and forced many companies to cease their European operations.
It is refreshing to find instances in the IT sector where competing groups with their own agendas work together for the common good and the improvement of systems everywhere. So it is with the absorption of the Gen-Z Consortium by the CXL Consortium.
What is open core? Is a project open core, or is a business open core? That’s debatable. Like open source, some view it as a development model, others view it as a business model.
From the recent writeup of the DNS work at the IETF its clear that there is a large amount of attention being focused on the DNS. Itâs not just an IETF conversation, or a DNS OARC conversation, but a conversation that involves a considerable amount of research activity as well.
It seems like Antarcticaâs McMurdo Station could be getting high-speed internetâa modern day luxury feature that could connect its remote laboratories (and seasonal tourist hub) to the rest of the world. The station is located on an island just off the northwestern part of the continent and is the largest US research hub on Antarctica.
âYour phoneâs front camera is always securely looking for your face, even if you donât touch it or raise to wake it.â
Organizations must improve their cybersecurity protocols to detect fraudulent identities and make sure they’re safeguarding their consumersâ personal information.
Rarely do cybercriminal gangs that deploy ransomware gain the initial access to the target themselves. More commonly, that access is purchased from a cybercriminal broker who specializes in acquiring remote access credentials â such as usernames and passwords needed to remotely connect to the targetâs network.
Kubernetes Security is constantly evolving – keeping pace with enhanced functionality, usability and flexibility while also balancing the security needs of a wide and diverse set of use-cases.
Letâs say youâre tasked with selecting a strong authentication solution for your organisation. Where do you begin? This article is the first of a series that will explore authentication and authorisation technologies in the context of recent exploits and developing trends.
At the University of California, Riverside, we found the current design and implementation of modern OSes can lead to side-channel-based DNS cache poisoning attacks, namely SAD DNS (Side-channel AttackeD DNS).
If youâre looking for a rugged case for your phone or tablet, youâve probably seen the terms MIL-SPEC or MIL-STD. But what do they mean? Itâs a simple standard, but its appearance on product packaging is a complex topic.
Web 1.0 was from 1991 to 2004 when web users were consumers of content, and the web was a series of static websites. Web 2.0 emerged in 2004 as user-created content overtook static content. The big winners in this era have been the huge social media platforms that became some of the biggest companies on the planet.
Do-it-yourself is a great way to learn coding, but it’s a risky way to tackle complex application problems that have scant room for error, such as authentication and encryption.
Manifest V3, Google Chromeâs soon-to-be definitive basket of changes to the world of web browser extensions, has been framed by its authors as âa step in the direction of privacy, security, and performance.â
At least 300,000 IP addresses associated with MikroTik devices have been found vulnerable to multiple remotely exploitable security vulnerabilities that have since been patched by the popular supplier of routers and wireless ISP devices.
Machine Learning (ML) and Artificial Intelligence (AI) are all the rage in the network engineering world. Where might these technologies be useful, as opposed to mere hype? The two most obvious areas where AI and ML would be useful are failure reaction and security. Micah Mussler joins Tom Ammon and Russ White to discuss the possibilities of using AI and/or ML in the broader security market—and focusing in on the network.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-111.mp3 download
SpaceX had filed a new application with the Federal Communications Commission for a smaller dish, which just received approval yesterday.
Threat actors are increasingly banking on the technique of HTML smuggling in phishing campaigns as a means to gain initial access and deploy an array of threats, including banking malware, remote administration trojans (RATs), and ransomware payloads.
IBM unveiled a 127-qubit quantum computing chip called Eagle this week, showing off a new asset in the race to build the most powerful quantum computer.
Insurers have halved the amount of cyber cover they provide to customers after the pandemic and home-working drove a surge in ransomware attacks that left them smarting from hefty payouts.
U.S. banking regulators on Thursday finalized a rule that directs banks to report any major cybersecurity incidents to the government within 36 hours of discovery.
After squandering its lead because of a half decade of problems modernizing its manufacturing, that’s where Intel has been headed.
General Motors (GM.N) aims to tackle the global semiconductor shortage with new designs built in North America, President Mark Reuss said on Thursday.
As telehealth and digital platforms cement their role in the post-pandemic future, it’s imperative for the digital health ecosystem to find ways of enhancing support networks, marking the transition from telehealth to tele-wellbeing.
There is currently no specific time frame during which banks must report to federal regulators that a security incident had occurred. A new notification rules changes that to 36 hours.
One of the more common ways cybercriminals cash out access to bank accounts involves draining the victimâs funds via Zelle, a âpeer-to-peerâ (P2P) payment service used by many financial institutions that allows customers to quickly send cash to friends and family.
DDR5 has barely hit the shelves, but Samsung has confirmed itâs already working on the next generation of RAM.
Speculative execution attacks present an enormous security threat, capable of reading arbitrary program data under malicious speculation, and later exfiltrating that data over microarchitectural covert channels. This paper proposes speculative taint tracking (STT), a high security and high performance hardware mechanism to block these attacks.
Alternatively, the unencrypted variants of these protocols can be upgraded to encrypted connections via a mechanism called STARTTLS.
Researchers have demonstrated yet another variant of the SAD DNS cache poisoning attack that leaves about 38% of the domain name resolvers vulnerable, enabling attackers to redirect traffic originally destined to legitimate websites to a server under their control.
In the field of artificial intelligence (AI) research, this article posits that it is tooling which has played a disproportionately large role in deciding which ideas succeed and which fail.
Networking equipment company Netgear has released yet another round of patches to remediate a high-severity remote code execution vulnerability affecting multiple routers that could be exploited by remote attackers to take control of an affected system.
A new analysis of website fingerprinting (WF) attacks aimed at the Tor web browser has revealed that it’s possible for an adversary to glean a website frequented by a victim, but only in scenarios where the threat actor is interested in a specific subset of the websites visited by users.
No fewer than 1,220 Man-in-the-Middle (MitM) phishing websites have been discovered as targeting popular online services like Instagram, Google, PayPal, Apple, Twitter, and LinkedIn with the goal of hijacking users’ credentials and carrying out further follow-on attacks.
To answer this, we at Waseda University have conducted a large-scale survey into the adoption of various DNS security mechanisms â DNSSEC, DNS Cookies, CAA, SPF, DMARC, MTA-STS, DANE, and TLSRPT â and in doing so identified what effects adoption rates.
SRv6, a form of source routing, is the new and interesting method being created by the IETF to allow traffic engineering and traffic steering. This is not the first time the networking world has tried source routing, however—and in the spirit of rule 11, we should ask some questions. How and why did source routing fail last time? Have we learned those lessons and changed the way we’re doing things to overcome those limitations? Security seems to be one area where problems arise in the source routing paradigm.
Andrew Alston joins Tom Ammon and Russ White to discuss security in SRv6.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-110.mp3 download
Kaspersky today publishes its Distributed Denial of Service (DDoS) Q3 2021 report, which found when compared to Q3 2020, the total number of DDoS attacks increased by nearly 24%, while the total number of smart attacks (advanced DDoS attacks that are often targeted) increased by 31% when compared to the same period last year.
IP fragmentation is a process that breaks large packets into smaller packets to allow them to more easily traverse a network. The process is common in the DNS, which is predominantly UDP based.
If youâve been perusing cryptocurrency forums or video-game news recentlyâor spying everything from New York Times job listings to zany Twitter threads claiming that the traditional job interview is about to be replaced by blockchain-based âquests, adventures and courses to prove your worthââyou might have run into the term âWeb3.â
When Facebook announced last month that it was rebranding as Meta, CEO Mark Zuckerberg enthusiastically described the metaverse his company would soon build, promising it would be a world âas detailed and convincing as this oneâ where âyouâre going to be able to do almost anything you can imagine.â
In a previous blog, we shared how Paragon Pathfinder plays an important role in closed-loop automation by tuning the paths of RSVP or Segment-Routed Traffic Engineered LSPs according to changing conditions that it observes in the live network.
HTML smuggling, a highly evasive malware delivery technique that leverages legitimate HTML5 and JavaScript features, is increasingly used in email campaigns that deploy banking malware, remote access Trojans (RATs), and other payloads related to targeted attacks.
Smishing messages usually include a link to a site that spoofs a popular bank and tries to siphon personal information. But increasingly, phishers are turning to a hybrid form of smishing â blasting out linkless text messages about suspicious bank transfers as a pretext for immediately calling and scamming anyone who responds via text.
A state-sponsored threat actor allegedly affiliated with Iran has been linked to a series of targeted attacks aimed at internet service providers (ISPs) and telecommunication operators in Israel, Morocco, Tunisia, and Saudi Arabia, as well as a ministry of foreign affairs (MFA) in Africa, new findings reveal.
The aviation industry told the White House on Tuesday it will take âsignificant timeâ to ensure it is safe for major U.S. wireless companies to use C-Band spectrum for 5G communications.
If you are responsible for a web server, you already use Transport Layer Security (TLS, the âSâ in âHTTPSâ) to protect your users from man-in-the-middle attackers that could otherwise passively sniff website cookies or actively inject malicious JavaScript.
ECDSA is a digital signature algorithm that is based on Elliptical Curve Cryptography (ECC). This form of cryptography is based on the algebraic structure of elliptic curves over finite fields.
As many as 13 security vulnerabilities have been discovered in the Nucleus TCP/IP stack, a software library now maintained by Siemens and used in three billion operational technology and IoT devices that could allow for remote code execution, denial-of-service (DoS), and information leak.
A few months ago, Proofpoint, a leading vendor of data loss prevention software, filed a lawsuit against a former employee for stealing confidential sales-enablement data prior to leaving for Abnormal Security, a market rival.
On November 15, 1971, Intel publicly debuted the first commercial single-chip microprocessor, the Intel 4004, with an advertisement in Electronic News.
What is the “core” of the DNS system, and how has it changed across the years? Edward Lewis joins Tom Ammon and Russ White to discuss his research into what the “core” of the domain name system is and how it has changed—including the rise of the large cloud players to the core of the default free zone.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-109.mp3 download
This live training will provide an overview of the systems, providers, and standards bodies important to the operation of the global Internet, including the Domain Name System (DNS), the routing and transport systems, standards bodies, and registrars. For DNS, the process of a query will be considered in some detail, who pays for each server used in the resolution process, and tools engineers can use to interact DNS. For routing and transport, the role of each kind of provider will be considered, along with how they make money to cover their costs, and how engineers can interact with the global routing table (the Default Free Zone, of DFZ). Finally, registrars and standards bodies will be considered, including their organizational structure, how they generate revenue, and how to find their standards.
Way in the past, the EIGRP team (including me) had an interesting idea–why not aggregate routes automatically as much as possible, along classless bounds, and then deaggregate routes when we could detect some failure was causing a routing black hole? To understand this concept better, consider the network below.
In this network, B and C are connected to four different routers, each of which is advertising a different subnet. In turn, B and C are aggregating these four routes into 2001:db8:3e8:10::/60, and advertising this aggregate towards A. From a control plane state perspective, this is a major win. The obvious gain is that the amount of state is reduced from four routes to one. The less obvious gain is A doesn’t need to know about any changes in the state for the four destinations aggregated into the /60. Depending on how often these links change state, the reduction in the rate of change is, perhaps, more important than the reduction in the amount of control plane state.
We always know there will be a tradeoff when reducing state; what is the tradeoff here? If C somehow loses its connection to one of the four routers, say the router advertising 11::/64, C’s 10::/60 aggregate will not change. Since A thinks C still has a route to every subnet within 10::/60, it will continue sending traffic destined to addresses in the 11::/64 towards both B and C. C will not have a route towards these destinations, so it will drop the traffic.
We have a routing black hole.
for more information on aggregation in networks, take a look at my livelesson on abstraction in computer networks
This much is pretty simple. The harder part is figuring out to eliminate this routing black hole. Our first choice is to just not aggregate these routes. While you might be cringing right now, this isn’t such a bad option in many networks. We often underestimate the amount of state and the speed of state change modern routing protocols running on modern processors can support. I’ve seen networks running IS-IS in a single flooding domain with tens of thousands of routes and thousands of nodes running “in the wild.” I’ve seen IS-IS networks with thousands of nodes and hundreds of thousands of routes running in lab environments. These networks still converge.
But what if we really think we need to reduce the amount and speed of state, so we really need to aggregate these routes?
One solution that has been proposed a number of times through the years is auto disaggregation.
In this case, suppose D somehow realizes C cannot reach one of the components of a shared aggregate route. D could simply stop advertising the aggregate, advertising each of the components instead. The question here might be: is this a good idea? Looking at this from the perspective of the SOS triad, the aggregation replaced four routes with a single route. In the auto disaggregation case, the single route change is replaced by four route changes. The amount of state is variable, and in some cases the rate of change in state is actually higher than without the aggregation.
So…
I don’t hold that auto disaggregation is either good nor bad—it just presents a different set of challenges to the network designer. Instead of designing for average rates of change and given table sizes, you can count on much smaller tables, but you might find there are times when the rate of change is dramatically higher than you expect. A good question to ask, before deploying this kind of technology, might be: can I forsee a chain of events that will cause a high enough rate of state change that auto disaggregation is actually more destabilizing than just not summarizing at all in this network?
A real danger with auto disaggregation, by the way, is using summarization to dramatically reduce table sizes without understanding how a goldilocks failure (what we used to call in telco a mother’s day event, or perhaps a black swan) can cascade into widespread failures. If you’re counting on particular devices in your network only have a dozen or two dozen table entries, but just the right set of failures can cause them to have several thousand entries because of auto disaggregation, what kinds of failures modes should you anticipate? Can you anticipate or mitigate this kind of problem?
The idea of automatically summarizing and disaggregating routes is an interesting study in complexity, state, and optimization. It’s a good brain exercise in thinking through what-if situations, and carefully thinking about when and where to deploy this kind of thing.
What do you think about this idea? When would you deploy it, where, and why? When and where would you be cautious about deploying this kind of technology?
We’ve had too many face-palm-worthy incidents of organizations hearing “hey, I found your data in a world readable S3 bucket” or finding a supposedly “test” server exposed that had production data in it.
Virtually all compilers â programs that transform human-readable source code into computer-executable machine code â are vulnerable to an insidious attack in which an adversary can introduce targeted vulnerabilities into any software without being detected, new research released today warns.
2021 has already been a banner year for cybercriminals â the record-largest ransomware payment of $40 million was made by an insurance company this year. And the attacks won’t stop.
In the 2021 Domain Security Report, we analyzed the trend of domain security adoption with respect to the type of domain registrar used, and found that 57% of Global 2000 organizations use consumer-grade registrars with limited protection against domain and DNS hijacking, distributed denial of service (DDoS), man-in-the-middle attacks (MitM), or DNS cache poisoning.
When it comes to cybersecurity, risks are omnipresent. Whether it is a bank dealing with financial transactions or medical providers handling the personal data of patients, cybersecurity threats are unavoidable. The only way to efficiently combat these threats is to understand them.
âFunctional, free and secure by defaultâ, OpenBSD remains a crucial yet largely unacknowledged player in the open-source field.
A new multistage phishing campaign spoofs Amazon’s order notification page and includes a phony customer service voice number where the attackers request the victim’s credit card details to correct the errant “order.”
Traditional security gives value to where the user is coming from. It uses a lot of trust because the user’s location or IP address (perimeter model) is used to define the user to the system. In a zero-trust model, we assume zero units of trust before we grant you access to anything and verify a lot of other information before granting access.
Up to the second half of the 19th century âwith the exception of the industrial power Great Britainâthe protection of inventions was inadequate and strongly disputed.
Two senators have introduced bipartisan legislation that would make it harder for online tech giants to make acquisitions that âharm competition and eliminate consumer choice,â according to the office of Sen. Amy Klobuchar (D-Minn.), one of the billâs co-sponsors.
A team of tech companies including Google, Salesforce, Slack, and Okta recently released the Minimum Viable Secure Product (MVSP) checklist, a vendor-neutral security baseline listing minimum acceptable security requirements for B2B software and business process outsourcing suppliers.
Are you looking to get a VPN subscription soon? Before you get a multi-year subscription, make sure the VPN you choose has these six crucial features.
Death, taxes, and spam. Itâs constant, ever-present, and you likely have a few hundred of them sitting in your Spam folder as you read this.
For those who follow the issue of blocking illegal content from the Internet, there is an interesting development in relation to this issue here in Germany, and I will tell you a little about it.
Neal Stephensonâs foundational cyberpunk novel Snow Crash brought to the public the concept of a metaverse, a virtual reality in which people interact using avatars in a manufactured ecosystem, eschewing the limitations of human existence.
Engineers (and marketing folks) love new technology. Watching an engineer learn or unwrap some new technology is like watching a dog chase a squirrel—the point is not to catch the squirrel, it’s just that the chase is really fun. Join Andrew Wertkin (from BlueCat Networks), Tom Ammon, and Russ White as we discuss the importance of simple, boring technologies, and moderating our love of the new.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-108.mp3 download
This Friday (the 12th) I’m presenting a live webinar on How Routers Really Work over at Pearson. From the description:
This training will peer into the internal components of a router, starting with an explanation of how a router switches packets. This walk through of a switching path, in turn, will be used as a foundation for explaining the components of a router, including the various tables used to build forwarding tables and the software components used to build these tables.
Please join me by registering here.
I’ve changed just a few of the slides from the last time I gave this talk and reordered some things.
From Facebook to LinkedIn to Indeed, ads are popping up that promise well-paying jobs â if applicants provide their Social Security numbers and other details up front. Scammers then use the information to apply for unemployment benefits.
The coronavirus pandemic giveth to Amazon retail business and its Amazon Web Services cloud business, and the pandemic taketh away from the Amazon retail business.
Companies should recognize that collaboration platforms aren’t isolated, secure channels where traditional threats don’t exist.
The Federal Aviation Administration said on Tuesday it had issued a special information bulletin alerting manufacturers, operators, and pilots that action may be needed to address potential interference with sensitive aircraft electronics caused by the use of 5G telecommunications technology.
The holiday shopping season always means big business for phishers, who tend to find increased success this time of year with a lure about a wayward package that needs redelivery.
If not handled in time, the attacks can lead to IP reputation loss and blocklisting, causing severe and expensive damage to companies, but a few precautionary steps can help keep the threats at bay.
The following resources and tutorials will enhance your understanding of container network security and help you get started.
With major changes to its physical design, specifications, and features, motherboards with DDR4 slots cannot use DDR3 RAM, and DDR4 RAM canât be put into a DDR3 slot. Neither is compatible with the newer DDR5 memory.
The Internet should not have broken as badly as it did when one of Letâs Encryptâs root certificates expired on Sept. 30.
However, sandboxing never really did deliver on its promise: to turn the unknown into the known. Too often, sandboxing misses threats, and in doing so gives organizations a false sense of security.
âIn order to secure your account, please enter the code we have sent your mobile device now,â the voice said. PayPal sometimes texts users a code in order to protect their account. After entering a string of six digits, the voice said, âThank you, your account has been secured and this request has been blocked.â
According to emails advertising the scheme obtained by Futurism, a Harvard blog post from a fake student like John can be bought for as little as $300 via PayPal.
The server environment is complex and if you’re managing thousands of Linux servers, the last thing you want is for an operating system vendor to do something completely unexpected.
Whenever a DNSSEC-signed zone changes its trust anchor â typically a Key Signing Key (KSK) â the delegation signer (DS) record has to be communicated to the parent zone via some API.
Whether you’re just starting in your technology career, or you’re an old hand who likes to go back to basics and understand how to move forward in your career, this episode of the Hedge is for you. Terry Slattery joins Tom Ammon and Russ White to discuss the things you can do to build a successful career as in the world of network engineering.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-107.mp3 download
If your organization includes Android devices as part of its bring-your-own-device (BYOD) policy or uses embedded systems, then a recent root expiration for Letâs Encrypt digital certificates may potentially place your organization at risk.
In a threat hunting approach, when we find some malicious file, binary, or a program, we need to collect the artifacts from them and search within our whole environment to find any possible traces of malicious activity.
In other words, how to fool advanced threat detection systems, past the all-seeing eye of which, according to marketers, no extra byte can slip through. I am talking about systems that use big data analytics as one of the main tools for detecting suspicious activity like SIEM and XDR.
Intel Corp. and Alphabet Inc.âs Google Cloud on Wednesday said they have worked together to create a new category of chip that Intel hopes will become a major seller in the booming cloud computing market.
Attacks involving SEO poisoning — where adversaries artificially increase the search engine ranking of websites hosting their malware to lure potential victims — are on the rise.
The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have published cybersecurity guidance to securely build and configure cloud infrastructures in support of 5G.
The FBI has warned that over 30 US-based companies had been hit by the Ranzy Locker ransomware by July this year, in a flash alert to other organisations who may be at risk.
Microsoft has discovered a vulnerability that could allow an attacker to bypass System Integrity Protection (SIP) in macOS and perform arbitrary operations on a device.
When we look at the intersection of cryptocurrency and domain data, we see something insidious: The prevalence of crypto-related threats. And itâs not just cryptojacking.
âFunctional, free and secure by defaultâ, OpenBSD remains a crucial yet largely unacknowledged player in the open-source field.
Researchers have observed an attacker using a technique they hadn’t previously seen to attempt to sneak phishing emails past enterprise security filters.
The supply chain is holding back the server business, and not just in the way you are thinking. Yes, there is a limited supply of manufacturing and packaging capacity for server-class processors based on the most advanced semiconductor nodes.
The 2021 CWE Most Important Hardware Weaknesses is the first of its kind and the result of collaboration within the Hardware CWE Special Interest Group (SIG), a community forum for individuals representing organizations within hardware design, manufacturing, research, and security domains, as well as academia and government.
In the aftermath of a major network outage, the natural reaction of most network engineers is to find some way to avoid all future outagesâregardless of the cost. The first line of defense against is future outages is redundancy, whether in the form of additional parallel links, new routers, new firewalls, new ⦠whatever, so long as there is more of it so packets have more paths to make it from source to destination.
Please join me for this live webinar.
One topic of constant discussion among network engineers is the basic problems surrounding network modeling, which leads to configuration, telemetry, and troubleshooting. In this episode of the Hedge, Ryan Beckett, Tom Ammon, and Russ White discuss Zen, a general framework for compositional network modelling.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-106.mp3 download
Mark Zuckerberg, unlike Einstein, did not dream up Facebook out of a sense of moral duty, or a zeal for world peace. This summer, the population of Zuckerbergâs supranational regime reached 2.9 billion monthly active users, more humans than live in the worldâs two most populous nationsâChina and Indiaâcombined.
The greatest risk of monopolies is that theyâll obstruct the ideas that will make our homes truly smart. Our âJetsonsâ future is on the line.
Given these concerns, it seems especially bizarre that Amazon was willing to reference the price of competing smart thermostats sold via its platform during the launch. Its smart thermostat is âless than half the average cost of a smart thermostat sold on Amazon.com,â the companyâs senior vice president of devices and services, Dave Limp, said.
Apple’s co-founder changed how we view tech. A decade after his death, we’ve changed how we view the tech industry, too.
The U.S. government is secretly ordering Google to provide data on anyone typing in certain search terms, an accidentally unsealed court document shows. There are fears such âkeyword warrantsâ threaten to implicate innocent Web users in serious crimes and are more common than previously thought.
There are two main types of tech criticism. Despite some superficial similarities, they are polar opposites. Here is how to distinguish them.
Governments and corporations are tracking how we go about our lives with a unique marker that most of us cannot hide or change: our own faces. Across the country, communities are pushing back with laws that restrain this dangerous technology.
Amazon.com Inc has been repeatedly accused of knocking off products it sells on its website and of exploiting its vast trove of internal data to promote its own merchandise at the expense of other sellers. The company has denied the accusations.
The report is supposed to highlight the countryâs prowess in artificial intelligence, yet it reveals a lesser-known truth: Chinaâs AI isnât so much a tool of world domination as a narrowly deployed means of domestic control.
To access data from unsuspecting users, the Chinese Communist Party (CCP) could be exploiting a universal authentication process that is thought to be secure, but in reality may not be, cybersecurity experts warned.
Have you ever been in an online discussion where a vocal proponent confidently claimed that his opponent was the victim of the dreaded âDunningâKrugerâ effect?
The controversy revolves mainly around a mechanism known as client-side scanning. Briefly, client-side scanning checks whether the content of a message, in the various formats in which it can be, whether text, images, videos or files, is similar to some âquestionableâ content before the message is sent to the intended recipient.
Professional networking site LinkedIn announced it will shut down its website in China because Chinaâs hefty compliance requirements have created a âsignificantly more challenging operating environment.â
“It’s simply not reasonable to expect that Huawei would refuse a direction from the Chinese Communist Party.” â Simeon Gilding, former head of the Australian Signals Directorate’s signals intelligence and offensive cyber missions.
A recent phishing campaign targeting Coinbase users shows thieves are getting smarter about phishing one-time passwords (OTPs) needed to complete the login process.
What does it mean to cloud-connect the network? Simply put, it means connecting network equipment to the cloud and collecting telemetry, but this simple idea has far-reaching benefits that can up level the support experience for customers and vendors.
This post will focus on a key part of DNSSEC infrastructure â Root KSK ceremonies. These ceremonies exist to provide transparency to the Internet community around the creation, use, and storage of the Root KSK.
Despite 60% surge in dangerous third-party domain registrations, domain security is an underutilized security component to curb phishing and related ransomware attacks.
The term âcode debtâ in computer programming refers to the idea that certain decisions in writing computer code will lead to future consequences which have to be dealt with.
Before you give in to your impulses and wipe your screen with whatever you have at hand, let us stop you right there. Your display is way more delicate than you think, and if you want it to last you a long time in optimal conditions, youâll need to treat it with proper love and care.
The nifty app CamFind has come a long way with its artificial intelligence. It uses image recognition to identify an object when you point your smartphone camera at it.
For starters, Windows 11 has allowed Microsoft to cut the cord on the 32-bit platform. Windows 11 will be first Windows OS that is 64-bit only.
Earlier in 2021, ASHRAEâs Technical Committee 9.9 published an update â the fifth edition â of its Thermal Guidelines for Data Processing Environments.
The DNSSEC specification does not define in advance which algorithm you should use to generate the digital signature records for a DNSSEC-signed zone. And that’s a very good thing.
While HTTPS is becoming the default online protocol for providing a fast and secure connection for websites and applications, there is still room for improvement. The HTTPA protocol is intended to enhance online security by running code in trusted execution environments (TEEs).
Will we be pushing our organizations and end-users to MFA only to repeat many of the same mistakes? The US government is worried about it. You should be worried as well.
A group of fraudsters made off with $35 million after using forged email messages and deepfake audio to convince an employee of a United Arab Emirates company that a director requested the money as part of an acquisition of another organization, according to a US federal court request filed last week.
While the ransomware spikes of 2021 appear to have temporarily subsided, the issue remains a pressing concern among the US cybersecurity community. On Sept. 21, the US Department of the Treasury announced a set of proposed sanctions and regulatory tools focused on disrupting the ransomware model by increasing ransom payment reporting to government agencies,
Many organizations rely on penetration testing to find security gaps in their systems, but the process has historically looked different.
Many service providers have the feeling that they “didn’t do anything wrong, but somehow we still lost.” How are providers reacting to the massive changes in the networking field, and how are they trying to regain their footing so they can move into the coming decades better positioned to compete? Join Johan Gustawsson, Tom Ammon, and Russ White as we discuss the impact of merchant silicon and changing applications on the architecture of service providers.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-105.mp3 download
You can read Johan’s post on this topic here.
Russia is the source of the lion’s share of nation-state cyberattacks Microsoft has observed in the past year (58%), followed by North Korea (23%), Iran (11%), China (8%), and South Korea, Vietnam, and Turkey all with less than 1% representation, a new pool of data reveals.
Equinix has been testing the use of liquid cooling in its data centers, and hopes to use the technology in its Equinix Metal service to create a high-density, energy efficient computing platform.
As a rule, the English term “computer” and the equivalent German term “Rechner” describe calculating machines. But until the middle of the 20th century, computers were, in fact, humans who performed calculations.
The job-killing robots are almost at the door, we are told, mere moments away from replacing the last traces of human inefficiency and heralding the dawn of a world without work.
The technological breakthroughs and intelligence superiority of the Israel Defense Forceâs Unit 8200 position it, and Israel, as a world leader, at the same level as the United States, Russia, or China.
New PCIe 6.0 technology is in the works, and according to nonprofit electronics industry consortium PCI-SIG, itâs in the final draft stages.
Recently I was asked by a customer how they can easily set up rollback capabilities on the endpoints in their corporate network.
An industry group calling itself 5G Americas has published a whitepaper that touts the advantages of a smart auto grid powered by 5G and the C-V2X technology.
Itâs coming towards the end of 2021 already, which means itâs nearly time again for one of my favourite Internet quirks: A DNSSEC Key Signing Key (KSK) Ceremony, number 43 to be exact.
Across every industry, competition, reputation and customer satisfaction are all impacted by experience. And for most organizations, the network plays a significant role in determining the level and type of service that they can provide.
Thunderbolt 4 technology is still relatively new, but Intel is already working on its successor: Thunderbolt 5 (or whatever Intel decides to call it).
For years, it restricted its G-Sync variable refresh rate technology to monitors that included a dedicated (and costly) proprietary module, instead of adopting the open-source FreeSync developed by AMD.
The important thing to understand about a certificate graph is that the boxes represent entities (meaning an X.500 Distinguished Name and public key).
Despite a dramatic increase in ransomware attacks, enterprise storage and backup environments have a dangerously weaker security posture than the compute and network layers of the IT infrastructure, new research shows.
On Sept. 30, a root certificate provided by digital certificate authority (CA) Let’s Encrypt expired, meaning that the tens of millions of websites and devices that used the cert had to have updated to a new root before then â or run into problems.
Automation is often put forward as the answer to all our problems—but without a map, how can we be certain we are moving in the right direction? David Gee joins Tom Ammon and Russ White on this episode of the Hedge to talk about automata without a map. Where did we come from, what are we doing with automation right now, and what do we need to do to map out a truly better future?
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-104.mp3 download
On Thursday the 19th of October at 1PM ET, I’ll be joining Keith Bogart for the em>INE Live live stream. You can find the details on their web site.
In this session, Keith Bogart will interview prolific author and Network Architect, Russ White Ph.D. One of only a handful of people who have attained CCAr status, Russ White has authored several books such as “Practical BGP”, “The Art of Network Architecture” and “Computer Networking Problems And Solutions”. During this session we’ll find out about his journey to becoming a Network Architect and how his passion for technology can inspire you!
On the 14th (this Thursday), I’ll once again be a guest on a live stream with Jeff T and Jeff D on Between -x2 Nerds.. I think this is the URL, but you can check on their web page later to make certain.
first, a few interesting stories on the facebook outage
Facebook says that a configuration error broke its connection to a key network backbone, disconnecting all of its data centers from the Internet and leaving its DNS servers unreachable, the company said.
Following the Facebook outage that took place on 4 October, we saw people looking to BGPlay to get a better view of what went on. Here’s a look at what the RIPEstat visualisation has to show us about the event in question.
On October 4th Facebook managed to achieve one of the more impactful of outages of the entire history of the Internet, assuming that the metric of “impact” is how many users one can annoy with a single outage. In Facebook’s case the 6-hour outage affected the services it provides so some 3 billion users, if we can believe Facebook’s marketing hype.
But surely the bigger lesson is that we are all too dependent on too few Really Big providers. EU Competition Commissioner told Reuters âFacebookâs (FB.O) six-hour outage the previous day shows âthe repercussions fn relying on just a few big players and underscores the need for more rivals.â
and other stories, as usual
Email is the most popular vector through which to initiate successful cyberattacks. Statistics indicate that anywhere between 90% and 95% of all such attacks involve email, whether to deliver malware, to hoodwink a user into visiting a website from which ransomware will be downloaded, or simply to imitate a CEO or CFO and demand that a multimillion-dollar payment be expedited forthwith.
It looked like a calculator app. But it was actually spyware recording my every keystroke â the type of data that would give a stalker unfettered access to my private life.
Many organizations lag in patching high-severity vulnerabilities, according to a new study that reveals more than 50% of servers scanned have a weak security posture weeks and months after a security update is released.
In February, KrebsOnSecurity wrote about a novel cybercrime service that helped attackers intercept the one-time passwords (OTPs) that many websites require as a second authentication factor in addition to passwords.
Nvidia revealed a new feature coming to RTX 2000 and RTX 3000 graphics cards called DLAA.
Bad actors have accelerated their purchase of domains that look similar to the brands of the largest 2,000 companies in the world, with 60% of such domains registered to risky third parties, not the companies themselves,.
By declaring that they are in line with the chosen security standard, businesses can demonstrate much higher credibility when faced with stakeholders, insurance providers, potential clients, and potential partners. This is just one of many benefits that come with achieving standards.
On Tuesday, D-Wave released its roadmap for upcoming processors and software for its quantum annealers. But D-Wave is also announcing that it’s going to be developing its own gate-based hardware, which it will offer in parallel with the quantum annealer.
Syniverse, a company that routes hundreds of billions of text messages every year for hundreds of carriers including Verizon, T-Mobile, and AT&T, revealed to government regulators that a hacker gained unauthorized access to its databases for five years.
While domain cyber risk is rising, the level of action being taken by Forbes Global 2000 companies to improve their domain security posture has remained unchanged, leaving these companies exposed to even more risk.
Most people only ever give common vulnerabilities and exposures (CVEs) a passing glance. They might look at the common vulnerability scoring system (CVSS) score, determine whether the list of affected products is a concern for them, and move on.
I’m sitting with Jeff Doyle and Jeff Tantsura to talk about network complexity on the Between 0x2 Nerds podcast today at 1PM ET today. The link is here—
Join us if you can.
Our community has been talking about BGP security for over 20 years. While MANRS and the RPKI have made some headway in securing BGP, the process of deciding on a method to provide at least the information providers need to make more rational decisions about the validity of individual routes is still ongoing. Geoff Huston joins Alvaro, Russ, and Tom to discuss how we got here and whether we will learn from our mistakes.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-103.mp3 download
Bowles is showing off her whatever-it-takes strategy for narrowing the digital divide between people with reasonably speedy internet access and those without.
Articles 33 and 34 outline the requirements for breach notification; however, most businesses are still unaware of their responsibilities. Details such as what an organization should report, when, to whom it should be reported, and what should be included in the breach notification are some of the major aspects that businesses overlook.
The idea behind Security.txt is straightforward: The organization places a file called security.txt in a predictable place â such as example.com/security.txt, or example.com/.well-known/security.txt.
Air is an absolutely terrible medium with which to move or remove heat from a system, but it sure is a lot easier and cheaper (well, at least in terms of the cost of goods sold sense) than adding some sort of liquid cooling to a system.
The EU aims to have a common charging port for mobile phones, tablets, and headphones under a European Commission proposal presented on Thursday in a world first, with the move impacting iPhone maker Apple more than its rivals.
As we head toward the annual Supercomputing Conference season we wanted to take a moment for a level-set on exascale.
One noteworthy element of the National Institute of Standards and Technology’s recent Recommended Minimum Standard for Vendor or Developer Verification of Code is the prominence given to threat modeling.
Could domain and subdomain monitoring help in detecting Internet properties that could hint at illegitimate releases?
Networking equipment maker Cisco Systems has rolled out patches to address three critical security vulnerabilities in its IOS XE network operating system that remote attackers could potentially abuse to execute arbitrary code with administrative privileges and trigger a denial-of-service (DoS) condition on vulnerable devices.
Iâve always been intrigued by the history of technology, and I think a lot of that is due to having almost everything computer-related happen during my lifetime. I missed a tech anniversary earlier this year when email turned 50.
Open source software projects – the underpinnings of the global software ecosystem – are getting better at more quickly updating vulnerable dependencies, but at the same time they face more cyberattacks and a significant volume of critical vulns.
On Sept. 28, as part of requiring every major voice provider in the states — including phone companies AT&T, Verizon and T-Mobile — to start using Stir/Shaken technology, companies need to inform the FCC of their plans to combat spam calls or carriers will have to stop accepting calls from those providers.
Presumably, the screens either have identity embedded in them, whereby they will only work with the original phone.
Not that long ago the talk was all about 10nm and 7nm. The latest ânmâ to enter the game is 5nm, which is already in use in some devices and is heading to PCs in the near future.
There are certain phrases and motifs that get repeated in software efforts. I’ve encountered a few particularly problematic ones with such regularity that I’ve catalogued them, and I’ve additionally collected counter-quotes for use as spot treatments as well as an inoculation against future ill-formed thinking.
In a long-overdue notice issued Sept. 30, the FCC said it plans to move quickly on requiring the mobile companies to adopt more secure methods of authenticating customers before redirecting their phone number to a new device or carrier.
Our community has been talking about BGP security for over 20 years. While MANRS and the RPKI have made some headway in securing BGP, the process of deciding on a method to provide at least the information providers need to make more rational decisions about the validity of individual routes is still ongoing. Geoff Huston joins Alvaro, Russ, and Tom to discuss how we got here and whether we will learn from our mistakes.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-102.mp3 download
I sometimes reference Keithâs Law in my teaching, but I donât think Iâve ever explained it. Keithâs Law runs something like this:
Any large external step in a systemâs capability is the result of many incremental changes within the system.
The reason incremental changes within a system appear as a single large step to outside observers is the smaller changes are normally hidden by abstraction. This is, in fact, the purpose of abstractionâto hide small changes inside a system from external view. Keithâs law is closely related to Clarkeâs third law that âAny sufficiently advanced technology is indistinguishable from magic.â What looks like magic from the outside is really just a bunch of smaller thingsâeach easier to understand on its ownâcombined into one single âthingâ through abstraction.
If youâve read this far, youâre probably thinkingâwhat does this have to do with network engineering?
Well, several things, really.
Firstâthe network is just an abstraction that moves packets to its users. Moving packets seems so ⦠simple ⦠to network users. You put data in here, and data comes out over there. All the little stuff that goes into making a network work are lost in the abstraction of the virtual connection between two hosts.
If you want users to understand why building a network is hard, youâre going to have to work hard at it. And youâre not likely to succeedâitâs often better just to live with the reality that users arenât going to understand. Of course, this isnât necessarily a bad thing, at least until itâs time to buy hardware and software to make all this magic work.
Secondâno-one outside the network is ever going to understand the refactoring, simplification, and new features youâre trying to build into the network on their own. Users will only understand these things when they are related to some bigger picture, something they can see beyond the abstraction the network presents.
If youâre going to justify doing new things, you need to do so in terms of âlarger things,â things that can be seen from outside the abstraction.
Thirdâno-one is going to pat you on the back for all the little things that need to be done to deploy a new major service. From the outside, that new service, or new cost savings, or whateverâitâs all just indistinguishable from magic.
Keithâs law is both good and bad. But it also means you need to learn how to frame your work in a way that users, who donât have access to the inner workings of the network, can understand why youâre doing what youâre doing.
Turning this around, this also means you shouldnât accept the âmagicâ of vendor products. That brilliant new capability your vendor is showing you is really made up of a lot of smaller components. The abstraction is just thatâan abstraction. If you really want to understand the positive and negative consequences of deploying something new, you need to look beyond the abstraction.
Apple then made public what was private. The company, under CEO Tim Cook's leadership, had actually been consulting the FBI on various methods for hacking the phone. In fact, the FBI had botched one of the suggested techniques after a mistake. The agency wasn't willing to risk another gaffe.
Software locks, API restrictions, legal threats, forced downgrades and more – these are why Big Tech stays big.
Megan Borovicka joined Facebook in 2013 and then forgot she even had an account. But Facebook never forgot about her.
On May 27, 2020, in the French National Assembly, Cédric O, the French Secretary of State for Digital Economy, forcibly expressed his government’s frustration with Apple and Google in terms more appropriate to a cold war confrontation between superpowers.
Almost everything we do online today is designed to be addictive. The average American spent more than two hours a day on social media in 2020.
Gary Gensler, Joe Biden's deeply establishmentarian SEC head, has dropped a bomb on the crypto community with his sudden attack on Coinbase, the leading crypto platform.
As the data these devices collect is sold and shared—and hacked—deciding what risks you're comfortable with is a necessary part of making an informed choice. And those risks vary widely, in part because there's no single, comprehensive federal law regulating how most companies collect, store, or share customer data.
There are more federal facial recognition technology (FRT) systems than there are federal agencies using them, according to the U.S. General Accounting Office.
Technologists and law enforcement have been arguing about cryptography policy for about 30 years now. People talk past each other, with each side concluding the other side are unreasonable jerks because of some fundamental incompatible assumptions between two conceptual worlds in collision.
The Phorpiex botnet has been operating for years now. It first focused on distributing old-school worms that spread via infected USB drives or through chats that relied on the Internet Relay Chat (IRC) protocol.
The recent IP address crisis involving Africa's regional internet registry (Afrinic) and Cloud Innovation has shaken up the internet industry, also raising the long-standing question if RIR's IP asset governance policies are sustainable for long-term network growth.
Privacy-preserving DNS protocols like DNS over HTTPS (DoH), DNS over TLS (DoT), and DNS over QUIC (DoQ) have been around since 2014 but they have only recently been brought to the attention of the general public following Firefox's announcement to make DoH a default.
As the United States pulled its troops out of Afghanistan after a 20-year occupation, byproducts of the prolonged deployment took on new meaning and represented a new chapter of danger for the Afghan people.
In what appears to be a "throw spaghetti on the wall approach" to stopping antitrust reform targeting Big Tech, a few Members of Congress and a range of former military and intelligence officials wrote a letter asserting that these companies need to be protected for national security.
Yet his tone resonates with a growing unease within the US and elsewhere over the extraordinary rise of these technology giants, not just in monetary terms but in terms of their social power as well.
Commentators on the recent district court's order for a preliminary injunction in Netchoice, LLC v. Ashley Brooke Moody et al. have focused on social media's victory against the State of Florida, celebrating the court's opinion that Google, YouTube, and Facebook are private companies beyond the reach of Gov. Ron DeSantis and the Florida legislature's newest rules restricting Silicon Valley's ability to censor, deplatform and block users. These writers have neglected the tone of irresolution in this and similar cases decided in favor of Big Tech, however.
Apple has long been seen as a champion of security and privacy in a tech industry consumed with vacuuming up consumer data. Two recent events, however, have raised questions about whether the iPhone maker’s reputation is losing its luster.
Anyone who spends a decent amount of time online knows what happens when you shove a bunch of strangers into the same place. We replicate existing power dynamics, we form groups, we troll, we project our biases, we yell until only the most extreme voices are the ones that get heard.
Tech’s market concentration—summed up brilliantly by Tom Eastman, a New Zealand software developer, as the transformation of the Internet into “a group of five websites, each consisting of screenshots of text from the other four”—has aroused concern from regulators around the world.
At the center of debate regarding regulation of social media and the Internet is Section 230 of the U.S. Communications Decency Act of 1996. This law grants immunity to online platforms from civil liabilities based on third-party content.
Google has been so successful in its execution and protection of its brand that we culturally understand that to "Google" something is to conduct an internet search, despite the existence of alternative search engines.
Microsoft on Tuesday addressed a quartet of security flaws as part of its Patch Tuesday updates that could be abused by adversaries to target Azure cloud customers and elevate privileges as well as allow for remote takeover of vulnerable systems.
To meet current demands, as well as those of the next normal and an unpredictable future, retailers are now adopting software-driven strategies to deliver connected retail experiences and operations, ultimately resulting in the software-defined store.
Network measurement techniques have been mostly developed independently from protocols and, therefore, typically build upon externally visible semantics. One example of this is TCP sequence numbers and acknowledgements, which can be used to derive a flowâs round-trip time (RTT).
Ordinarily, when developing something, you start with a set of requirements or goals. But DNSSEC was a research project, so in place of requirements, developers set expectations of what needed to be done and what could be done to solve the DNS security problem.
Open-source M1-style chips may be in our future, according to a reverse-engineering document released online, Tomâs Hardware reports.
But how can they know that the plan they have is efficient enough to alleviate future cyber incidents? By using a cyber crisis tabletop exercise (CCTE), organizations can test or rehearse the emergency preparedness plan before a crisis occurs.
In a previous blog, we discussed how Paragon Pathfinder (formerly known as NorthStar Controller) greatly increases the level of automation in networks.
More than 20 years ago, the historical rate of shrinking transistors to improve speed, density, power consumption, and cost became impossible to maintain. Even with slower physical scaling, however, electronics manufacturers steadily improved their products by exploiting new materials, new device and circuit designs, and faster communication between chips.
South Korean chipmaker Samsung Electronics aims to be first to adopt a new form of transistor that should allow Moore’s Law to continue for another decade when it puts into production its 3nm semiconductor process toward the end of 2022.
The Roman historian Tacitus (55 A.D.â120 A.D.) once said “the desire for safety stands against every great and noble enterprise.”
The European Processor Initiative (EPI) has pinned its hopes on RISC-V as the path to European semiconductor independence.
Networking equipment company Netgear has released patches to remediate a high-severity remote code execution vulnerability affecting multiple routers that could be exploited by remote attackers to take control of an affected system.
After every major hurricane, like the category 4 Ida that recently hit Louisiana, there is talk in the telecom and power industries about ways to better protect our essential power and communication grids.
This comprehensive research into BulletProofLink sheds a light on phishing-as-a-service operations. In this blog, we expose how effortless it can be for attackers to purchase phishing campaigns and deploy them at scale.
The CMMC offers five tiers of conformity against two separate columns of achievements. To clarify, processes and practices are matched to higher compliance levels.
Understanding the flow of a packet is difficult in modern networks, particularly data center fabrics with their wide fanout and high ECMP counts. At the same time, solving this problem is becoming increasingly important as quality of experience becomes the dominant measure of the network. A number of vendor-specific solutions are being developed to solve this problem. In this episode of the Hedge, Frank Brockners and Shwetha Bhandari join Alvaro Retana and Russ White to discuss the in-situ OAM work currently in progress in the IPPM WG of the IETF.
https://media.blubrry.com/hedge/content.blubrry.com/hedge/hedge-101.mp3 download
One of the designs Iâve been encountering a lot of recently is a âcollapsed spineâ data center network, as shown in the illustration below.
In this design, and B are spine routers, while C-F are top of rack switches. The terminology is important here, because C-F are just switchesâthey donât route packets. When G sends a packet to H, the packet is switched by C to A, which then routes the packet towards F, which then switches the packet towards H. C and F do not perform an IP lookup, just a MAC address lookup. A and B are responsible for setting the correct next hop MAC address to forward packets through F to H.
What are the positive aspects of this design? Primarily that all processing is handled on the two spine routersâthe top of rack switches donât need to keep any sort of routing table, nor do any IP lookups. This means you can use very inexpensive devices for your ToR. In brownfield deployments, so long as the existing ToR devices can switch based on MAC addresses, existing hardware can be used.
This design also centralizes almost all aspects of network configuration and management on the spine routers. There is little (if anything) configured on the ToR devices.
What about negative aspects? After all, if you havenât found the tradeoffs, you havenât looked hard enough. What are they here?
First, Iâm struggling to call this a âfabricâ at allâitâs more of a mash-up between a traditional two-layer hierarchical design with a routed core and switched access. Two of the points behind a fabric are the fabric doesnât have any intelligence (all ports are undifferentiated Ethernet) and all the devices in the fabric are the same.
I suppose you could say the topology itself makes it more âfabric-likeâ than ânetwork-like,â but weâre squinting a bit either way.
The second downside of this design is that it impacts the scaling properties of the fabric. This design assumes youâll have larger/more intelligent devices in the spine, and smaller/less intelligent devices in the ToR. One of my consistent goals in designing fabrics has always been to push as close to single-sku as possibleâuse the same device in every position in the fabric. This greatly simplifies instrumentation, troubleshooting, and supply chain management.
One of the primary points of moving from a network in the more traditional sense to a âtrue fabricâ is to radically simplify the networkâthis design doesnât seem like itâs as âsimple,â on the network side of things, as it could be. Again, something of a âmash-upâ of a simpler fabric and a more traditional two-layer hierarchical routed/switched network.
Scale-out is problematic in this design, as well. Youâd need to continue pushing cheap/low-intelligence switches along the edge, and adding larger devices in the spine to make this work over time. At some point, say when you have eight or sixteen spines, youâd be managing just as much configurationâand configuration thatâs necessarily more complex because youâre essentially managing remote ports rather than local onesâas you would by just moving routing down to the ToR devices. Thereâs some scale point here with this design where itâs adding overhead and unnecessary complexity to save a bit of money on ToR switches.
When making the choice between OPEX and CAPEX, we should all know which one to pick.
Where would I use this kind of design? Probably in a smaller network (small enough not to use chassis devices in the spine) which will never need to be scaled out. I might use it as a transition mechanism to a full fabric at some point in the future, but I would want a well-designed planned to transitionâand I would want it written in stone that this would not be scaled in the future beyond a specific point.
Thereâs nothing more permanent in the world than temporary government programs and temporary network designs.
If anyone has other thoughts on this design, please leave them in the comments below.
Relationships also evolved during this uprooting of typical routines. Pandemic âpodsâ helped some Americans maintain connection, but they complicated relationships and family dynamics at the same time.
Attackers are actively exploiting a Microsoft remote code execution vulnerability using malicious Office files, the tech giant has warned.
âWhen you have a high percentage of all AI activity in Bay Area metros, you may be overconcentrating, losing diversity, and getting groupthink in the algorithmic economy. It locks in a winner-take-most dimension to this sector, and thatâs where we hope that federal policy will begin to invest in new and different AI clusters in new and different places to provide a balance or counter.”
Email isnât just a communication tool; itâs also an identifier and a security measure. Companies use it to create profiles of you when you start accounts with them and it often doubles as your username.
However, it looks like most phishing emails could be used to obtain user credentials according to the 2021 Annual State of Phishing Report by Cofense. After analyzing millions of emails, Cofense found that 57% are credential phishing emails.
Computer programmers are a pretty predictable bunch. Every time they approach legacy code, the gut reaction is âletâs rewrite this from scratch.â The reaction is understandable for many reasons.
Perhaps an all-purpose tablet that you must care for like a new pet, remembering to not leave it unattended, or forgetting it on a mass-transit system. Then, there is the login process.
Whereas years ago different threat actors focused on specific sectors, nowadays the same techniques, tactics, and procedures (e.g., how the perimeter is penetrated, which tools are used for lateral movement) are consistently applied regardless of company size, location, or industry.
The Hafnium attacks targeting Microsoft Exchange Server vulnerabilities triggered several cybersecurity investigators and researchers to hunt for other threat actors that use similar attack methods. Among them is the Cybereason News Network.
Despite being built on the same OS, Microsoft has said that Windows 11 will feature various optimizations, and now, we know what those optimizations are.
In this article, you’ll discover of the power of graphs by working with a small movie data set. It is based on the built in dataset and guide available on the Neo4j Sandbox.
Without evidence of wrongdoing, neither public agents nor private companies should be rifling through the photos on your personal devices.
The evolution of the workloads that we use every day to stay productive has fundamentally changed. New requirements around efficiency and using space wisely mean that leaders in the technology space need to look at cooling differently.
Napier’s rods, also called Napier’s bones (see Figure 1), were invented at the beginning of the 17th century. They have been used for multiplications and divisions until the 19th century.