Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
RFC2324
Jun 7, 2012

http 418

champagne posting posted:

you'd also have to carry around a scarlet E for the rest of your career which ... actually now I'm thinking on it I think a lot of tech bros would be perfectly fine with

I started my current job jan 4, and one of the first things I got to see was people having to talk someone down who thought making an offer to parler was a good idea for a fedramp company

Adbot
ADBOT LOVES YOU

BlankSystemDaemon
Mar 13, 2009



RFC2324 posted:

I started my current job jan 4, and one of the first things I got to see was people having to talk someone down who thought making an offer to parler was a good idea for a fedramp company
that's not a secfuck, that's just a gently caress

RFC2324
Jun 7, 2012

http 418

BlankSystemDaemon posted:

that's not a secfuck, that's just a gently caress

we have a number of idiots in our pro services department. Very... not great.

but, to be fair, he was dogpiled with "this is a bad idea for 100 reason, let us list them for you" by management

Midjack
Dec 24, 2007



BlankSystemDaemon posted:

that's not a secfuck, that's just a gently caress

jobsec gently caress

ZeusCannon
Nov 5, 2009

BLAAAAAARGH PLEASE KILL ME BLAAAAAAAARGH
Grimey Drawer

RFC2324 posted:

I started my current job jan 4, and one of the first things I got to see was people having to talk someone down who thought making an offer to parler was a good idea for a fedramp company

What the gently caress

suffix
Jul 27, 2013

Wheeee!
quiet day since half the company couldn't resolve slack.com due to their dnssecfuck

https://lists.dns-oarc.net/pipermail/dns-operations/2021-September/021340.html

seems to be over now but lol at your day if you're typing this

https://status.slack.com/2021-09/06c1e17de93e7dc2

quote:

In order to resolve this faster, your ISP (Internet Service Provider) will need to flush their DNS record for slack.com. Please reach out to your networking team to provide them with this information.
We expect all customers’ connectivity issues to be resolved within the next 24 hours.

Raere
Dec 13, 2007

the good ol ipconfig /flushdns

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
^^ post/av combo lookin good

i wonder if 8.8.8.8 / 1.1.1.1 took any special action to flush their caches?

it's not like google is using slack internally, so maybe not them

Methanar
Sep 26, 2013

by the sex ghost

Ulf posted:

^^ post/av combo lookin good

i wonder if 8.8.8.8 / 1.1.1.1 took any special action to flush their caches?

it's not like google is using slack internally, so maybe not them

https://developers.google.com/speed/public-dns/cache

Anyone can flush the cache for a record for google. Ironically though `dns.google` doesn't resolve to anything at the moment so it doesn't work.

dns.google’s server IP address could not be found.

;dns.google. IN A

Ulf
Jul 15, 2001

FOUR COLORS
ONE LOVE
Nap Ghost
dns: maybe the real resource records were the queries we made along the way

Computer Serf
May 14, 2005
Buglord

Ulf posted:

dns: maybe the real resource records were the queries we made along the way

:phoneb::phoneline::question::phoneline::phone:

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'


unfortunately i cannot make this the thread title

hobbesmaster
Jan 28, 2008

what about the classic sysadmin haiku

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
excellent

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Methanar posted:

I just wish I didn't write so much yaml

is there a yaml certification

and is the certificate itself in yaml

Potato Salad
Oct 23, 2014

nobody cares


RFC2324 posted:

I started my current job jan 4, and one of the first things I got to see was people having to talk someone down who thought making an offer to parler was a good idea for a fedramp company

that actually sounds like a good way to catch a lot of domestic terrorism or prevent school shootings if the feds had the resources to follow up on even a tenth of it

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

CMYK BLYAT! posted:

is there a yaml certification

and is the certificate itself in yaml
hella noms & yaml beer pong

Raere
Dec 13, 2007

I don’t know what the best way to handle encryption on the internet is, but I feel like the complex web of certificates we have now ain’t it.

Jenny Agutter
Mar 18, 2009

Potato Salad posted:

that actually sounds like a good way to catch a lot of domestic terrorism or prevent school shootings if the feds had the resources to follow up on even a tenth of it

whats your solution here, give the fbi more money?

ate shit on live tv
Feb 15, 2004

by Azathoth

Raere posted:

I don’t know what the best way to handle encryption on the internet is, but I feel like the complex web of certificates we have now ain’t it.

I'm just going to come out and say that the current implementation of SSL with mandatory expiration dates, the default assumption that without authentication, encryption is useless, and the gate keeper CA's being billion dollar duopoly's that will voluntarily work with the government to undermine encryption and privacy is a bad system.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
tls loving sucks. every time somebody moves from our support team to the tls team i smh a little bit.

mystes
May 31, 2006

ate poo poo on live tv posted:

I'm just going to come out and say that the current implementation of SSL with mandatory expiration dates, the default assumption that without authentication, encryption is useless, and the gate keeper CA's being billion dollar duopoly's that will voluntarily work with the government to undermine encryption and privacy is a bad system.
Encryption without authentication is pretty useless, though.

Probably the system should just be to obtain public keys via dns though.

Potato Salad
Oct 23, 2014

nobody cares


Jenny Agutter posted:

whats your solution here, give the fbi more money?

oh I recognize entirely it's not practical; this country will end before we unfuck law enforcement

reform AG career advancement incentives *waves arms* somehow

de-chudification of domestic terror offices *waves arms* somehow

Potato Salad fucked around with this message at 20:47 on Oct 2, 2021

psiox
Oct 15, 2001

Babylon 5 Street Team

Jonny 290 posted:

tls loving sucks. every time somebody moves from our support team to the tls team i smh a little bit.

oh lmao i think i know who you're taking about and rip because that guy rules

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Jonny 290 posted:

tls loving sucks. every time somebody moves from our support team to the tls team i smh a little bit.

maybe but good for them tho. the unfortunate conclusion i got from 10y of support work is that in practice there's no meaningful career growth because it's hard af to quantify "solved difficult cases well" esp across employers, and market determination of pay bands means you'll have to fight tooth and nail to even get parity with the salaries of junior devs despite having a more advanced skillset

the work is honestly less interesting, but it's hard to argue with something like double the pay for half the stress

apseudonym
Feb 25, 2011

mystes posted:

Encryption without authentication is pretty useless, though.

Probably the system should just be to obtain public keys via dns though.

DANE, and all PKI-via-DNS, only make sense if your biggest issue with modern webpki is that its too easy to hold CAs accountable.

spankmeister
Jun 15, 2008






I mean, you can shift the trust anchor from CA's to DNS operators with DNSSEC and DANE but ultimately there's some lovely company somewhere that has control over your certificates.

apseudonym
Feb 25, 2011

spankmeister posted:

I mean, you can shift the trust anchor from CA's to DNS operators with DNSSEC and DANE but ultimately there's some lovely company somewhere that has control over your certificates.

If a CA misbehaves they are quickly no longer a CA, if a DANE root misbehaves what are you going to do, drop .com domains?

There's a reason that DANE is mostly loved by people who have never done IRL PKI

mediaphage
Mar 22, 2007

Excuse me, pardon me, sheer perfection coming through
a huge trade publisher and auction provider, sandhills global, is down, and has been down for days at this point, due to getting cryptod

this affects all their platforms, all their trade pubs, even their corporate website

at first they apparently tried to tell people they were getting DDOSed which i was skeptical of with cloudflare

they have no timeline for getting things up and running

i bet this is really putting the hurt to a lot of small timers tbh since they also provide some of the big hosted auction platforms

BlankSystemDaemon
Mar 13, 2009



more like big hosed auction platform

mediaphage
Mar 22, 2007

Excuse me, pardon me, sheer perfection coming through

BlankSystemDaemon posted:

more like big hosed auction platform

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
facebook.com appears to be returning nxdomain from both cloudflare and google DNS. this is either very good or very bad

Pile Of Garbage
May 28, 2007



infernal machines posted:

facebook.com appears to be returning nxdomain from both cloudflare and google DNS. this is either very good or very bad

im seeing mixed results. locally got NS for facebook.com after flush DNS cache, nothing on my SG VPS.

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
the horizon is split. im getting servfail and a records roughly 50/50 on repeated digs. lol rip

evil_bunnY
Apr 2, 2003

They've bgp withdrawn a bunch of ranges apparently. I hope they all get PTSD.

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


https://twitter.com/MikaelThalen/status/1445036872846086148

Methanar
Sep 26, 2013

by the sex ghost

evil_bunnY posted:

They've bgp withdrawn a bunch of ranges apparently. I hope they all get PTSD.

lol I can't even open HE's looking glass right now to laugh at it myself.

Shame Boy
Mar 2, 2010


https://twitter.com/msjokav_/status/1445068522070155268

yeah it's a real mystery :thunk:

BaldDwarfOnPCP
Jun 26, 2019

by Pragmatica

Jonny 290 posted:

the horizon is split. im getting servfail and a records roughly 50/50 on repeated digs. lol rip



fb, ig, and whatsapp

none of which i use so i couldn't say if they unfucked themselves yet

Adbot
ADBOT LOVES YOU

Luigi Thirty
Apr 30, 2006

Emergency confection port.


My favorite comment on this so far is “they’re gonna find the KKK membership roll” followed by “it says they have the Texas GOP docs right there”

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply