Archive

Category Archives for "Networking"

Worth Reading: The state of DNS security

Did you know that 89% of top-level domains are now signed with DNSSEC? Or that over 88% of .GOV domains and over 50% of .CZ domains are signed? Were you aware that over 103,000 domains use DANE and DNSSEC to provide a higher level of security for email? Or that 80% of clients request DNSSEC signature records in DNS queries? All these facts and much more are available in our new State of DNSSEC Deployment 2016 report. —The Internet Society

The post Worth Reading: The state of DNS security appeared first on 'net work.

DevOps Success Requires Equal Parts Dev & Ops

In the push toward DevOps, much of focus is on software developers and development, but without equal investments on the operations side, progress slows down. In this episode of Talking DevOps, Josh Atwell, Developer Advocate for NetApp SolidFire, emphasizes the concept of balance and the need for adequate attention on the operations side of the equation. 

‘Found a nasty bug in my (Cisco) ASA this morning’

The above headline on a post to Reddit piqued my interest this afternoon because it was in that site’s section devoted to system administration and those people know a bug when they encounter one.The Redditor elaborates: “I found a bug in my ASA today. Eth 0/2 was totally unusable and seemed ‘blocked.’ These Cisco bugs are really getting out of hand. I'm just glad I didn't open this port up to the web.”Scare quotes around blocked? Gratuitous mention of the web. I smelled a ruse before even opening the first of three pictures.No. 1, labeled “checking layer 1:”To read this article in full or to leave a comment, please click here

‘Found a nasty bug in my (Cisco) ASA this morning’

The above headline on a post to Reddit piqued my interest this afternoon because it was in that site’s section devoted to system administration and those people know a bug when they encounter one.The Redditor elaborates: “I found a bug in my ASA today. Eth 0/2 was totally unusable and seemed ‘blocked.’ These Cisco bugs are really getting out of hand. I'm just glad I didn't open this port up to the web.”Scare quotes around blocked? Gratuitous mention of the web. I smelled a ruse before even opening the first of three pictures.No. 1, labeled “checking layer 1:”To read this article in full or to leave a comment, please click here

‘Found a nasty bug in my (Cisco) ASA this morning’

The above headline on a post to Reddit piqued my interest this afternoon because it was in that site’s section devoted to system administration and those people know a bug when they encounter one.The Redditor elaborates: “I found a bug in my ASA today. Eth 0/2 was totally unusable and seemed ‘blocked.’ These Cisco bugs are really getting out of hand. I'm just glad I didn't open this port up to the web.”Scare quotes around blocked? Gratuitous mention of the web. I smelled a ruse before even opening the first of three pictures.No. 1, labeled “checking layer 1:”To read this article in full or to leave a comment, please click here

‘Found a nasty bug in my (Cisco) ASA this morning’

The above headline on a post to Reddit piqued my interest this afternoon because it was in that site’s section devoted to system administration and those people know a bug when they encounter one.The Redditor elaborates: “I found a bug in my ASA today. Eth 0/2 was totally unusable and seemed ‘blocked.’ These Cisco bugs are really getting out of hand. I'm just glad I didn't open this port up to the web.”Scare quotes around blocked? Gratuitous mention of the web. I smelled a ruse before even opening the first of three pictures.No. 1, labeled “checking layer 1:”To read this article in full or to leave a comment, please click here

IDG Contributor Network: What does the future hold for the IT services industry?

It would probably be an understatement to say the IT services industry is spooked by the recent financial results reported by major IT services providers. Both the top and the bottom lines have been under pressure. The medium-term future, and even the shorter term, have become unpredictable. Results are inconsistent, and companies have softened their guidance on future growth rates.At the same time, tech spend around the world is increasing. At the NASSCOM Product Conclave in Bangalore a couple of months ago, I was struck by the buoyancy of the start-up market. India alone is home to more than 5,000 start-ups, and this number is slated to more than double by 2020. There is no doubt the tech love affair will continue to heat up as new innovations continue to spring from both unlikely garages and sophisticated computer labs alike.To read this article in full or to leave a comment, please click here

IDG Contributor Network: What does the future hold for the IT services industry?

It would probably be an understatement to say the IT services industry is spooked by the recent financial results reported by major IT services providers. Both the top and the bottom lines have been under pressure. The medium-term future, and even the shorter term, have become unpredictable. Results are inconsistent, and companies have softened their guidance on future growth rates.At the same time, tech spend around the world is increasing. At the NASSCOM Product Conclave in Bangalore a couple of months ago, I was struck by the buoyancy of the start-up market. India alone is home to more than 5,000 start-ups, and this number is slated to more than double by 2020. There is no doubt the tech love affair will continue to heat up as new innovations continue to spring from both unlikely garages and sophisticated computer labs alike.To read this article in full or to leave a comment, please click here

BGP Flowspec Indirection

While Flowspec has been around for a while (RFC5575 was published in 1999), deployment across AS boundaries has been somewhat slow. The primary concerns in deploying flowspec are the ability to shoot oneself in the foot, particularly as poening Flowspec to customers can also open an entirely new, and not well understood, attack surface, and the simple cost of filtering packets. In theory, ASICs can filter packets based on a variety of parameters cheaply. Theory doesn’t always easily translate to practice, however.

Regardless, recent work in Flowspec is quite interesting; particularly the ability to redirect flows, rather than simply filtering them. Of course, the original RFCs did allow for the redirection of flows into a VRF on the local router, but this leaves a good bit to be desired. To make such a system work, you must actually have a VRF into which to redirect traffic; for one-off situations, such as directing attack traffic to a honey pot, building the VRF and populating it can be more work than capturing the traffic is worth. A newer draft, draft-ietf-idr-flowspec-path-redirect, aims to resolve this.

Before getting to the draft specifics, however, it is useful to review the basic concept of Continue reading

Professionally designed ransomware Spora might be the next big thing

Security researchers have found a new ransomware program dubbed Spora that can perform strong offline file encryption and brings several innovations to the ransom payment model.The malware has targeted Russian-speaking users so far, but its authors have also created an English version of their decryption portal, suggesting they will likely expand their attacks to other countries soon.Spora stands out because it can encrypt files without having to contact a command-and-control (CnC) server and does so in a way still allows for every victim to have a unique decryption key.Traditional ransomware programs generate an AES (Advanced Encryption Standard) key for every encrypted file and then encrypts these keys with an RSA public key generated by a CnC server.To read this article in full or to leave a comment, please click here

Professionally designed ransomware Spora might be the next big thing

Security researchers have found a new ransomware program dubbed Spora that can perform strong offline file encryption and brings several innovations to the ransom payment model.The malware has targeted Russian-speaking users so far, but its authors have also created an English version of their decryption portal, suggesting they will likely expand their attacks to other countries soon.Spora stands out because it can encrypt files without having to contact a command-and-control (CnC) server and does so in a way still allows for every victim to have a unique decryption key.Traditional ransomware programs generate an AES (Advanced Encryption Standard) key for every encrypted file and then encrypts these keys with an RSA public key generated by a CnC server.To read this article in full or to leave a comment, please click here

Your Windows 10 PC may soon lock itself when you walk away

Windows 10 Insider previews are sometimes just full of surprises. An unmentioned feature in Build 15002 was recently uncovered by Windows Central that appears to be a complementary feature to Windows Hello, the biometric login system that automatically unlocks your PC when you sit in front of it.Dubbed Dynamic Lock, this newly discovered feature is designed to automatically lock down your computer when Windows detects that you’re away. It’s not clear if the feature is working yet and Microsoft has yet to discuss it publicly. For that reason it’s unknown what Dynamic Lock actually does. Though Windows Central says Microsoft’s internal name for the feature is “Windows Goodbye,” which indeed suggests a close relationship with Windows Hello.To read this article in full or to leave a comment, please click here

Your Windows 10 PC may soon lock itself when you walk away

Windows 10 Insider previews are sometimes just full of surprises. An unmentioned feature in Build 15002 was recently uncovered by Windows Central that appears to be a complementary feature to Windows Hello, the biometric login system that automatically unlocks your PC when you sit in front of it.Dubbed Dynamic Lock, this newly discovered feature is designed to automatically lock down your computer when Windows detects that you’re away. It’s not clear if the feature is working yet and Microsoft has yet to discuss it publicly. For that reason it’s unknown what Dynamic Lock actually does. Though Windows Central says Microsoft’s internal name for the feature is “Windows Goodbye,” which indeed suggests a close relationship with Windows Hello.To read this article in full or to leave a comment, please click here

You won’t have to hear about the Galaxy Note7 on flights anymore

Since its launch in September, the Galaxy Note7 went from being the phone to beat to the one you couldn’t take on airplanes. Even with a global recall in place and a series of software updates designed to brick any remaining devices, the FAA continued its ban on Samsung’s phablet, and frequent travelers grew accustomed to hearing about the warning before take-off.To read this article in full or to leave a comment, please click here

68% off Etekcity 4 Pack Portable Outdoor LED Camping Lantern with 12 AA Batteries – Deal Alert

Whether used for camping, trick or treating, or power outages, this lantern will provide up to 12 hours of bright omnidirectional LED lighting to see your surroundings. When the battery power of the lantern runs low, the brightness will dim to an energy saving mode to provide longer lasting illumination (up to 4 hours of low power usage). It's lighter, brighter and more portable than most flashlights while still featuring the rugged durability to withstand the outdoors. The military grade exterior is water resistant for more practical use in a high range of environments. Ideal for children, the lantern needs no setup or prepping with fires and oil. The design provides full omnidirectional lighting for clear vision no matter where you may turn. The fold-out collapsible handles make for easier portability and hanging.  This lantern averages 4.8 out of 5 stars on Amazon (read reviews) and the 4 pack's list price of $79.99 has been reduced 68% to $25.99. Check it out on Amazon.To read this article in full or to leave a comment, please click here

Samsung boss to testify in South Korea bribery case

Jay Y. Lee, the current head of the Samsung Group, will be questioned by a special prosecutor Thursday as part of an investigation into a wide-ranging corruption scandal in South Korea that has reached all the way to the country’s president.The case centers on allegations that Samsung, among other businesses, paid millions of dollars to a mysterious associate of President Park Geun-hye in exchange for favorable government decisions. That associate, Choi Soon-sil, is accused of accepting payments for her daughter’s competitive equestrian career as bribes.+ALSO ON NETWORK WORLD: US Intel report: Russia allegedly obtained 'compromising' info on Trump + Amazon Alexa ‘wins’ CES, but how well does the virtual assistant really perform?To read this article in full or to leave a comment, please click here