.US Harbors Prolific Malicious Link Shortening Service

2023-11-02 Thread goemon--- via NANOG
https://krebsonsecurity.com/2023/10/us-harbors-prolific-malicious-link-shortening-service/ "The NTIA recently published a proposal that would allow registrars to redact all registrant data from WHOIS registration records for .US domains. A broad array of industry groups have filed comments oppo

Amir Golestan sentenced to 5 years in prison for IP theft scheme

2023-10-17 Thread goemon--- via NANOG
https://krebsonsecurity.com/2023/10/tech-ceo-sentenced-to-5-years-in-ip-address-scheme/ And a statement from ARIN: https://www.arin.net/blog/2023/10/16/micfo-golestan-sentencing/

Re: NTP Sync Issue Across Tata (Europe)

2023-08-14 Thread goemon--- via NANOG
On Mon, 14 Aug 2023, Masataka Ohta wrote: Mike Hammett wrote: " As such, the ultimate (a little expensive) solution is to have your own Rb clocks locally." Yeah, that's a reasonable course of action for most networks. For most data centers with time sensitive transactions, at least.

Re: Sigh, friends don't let politicians write tech laws

2022-07-29 Thread goemon--- via NANOG
So instead of applying a label, just drop the email outright. -Dan On Fri, 29 Jul 2022, Michael Thomas wrote: https://www.congress.gov/bill/117th-congress/senate-bill/4409/text?r=9&s=1 the body of the proposed law: "(a) Conduct prohibited.— (1) IN GENERAL.—It shall be unlawful for an oper

Re: FCC proposes fines against 73 applicants of Rural Digital Opportunity Fund

2022-07-22 Thread goemon--- via NANOG
On Fri, 22 Jul 2022, William Herrin wrote: On Fri, Jul 22, 2022 at 1:12 PM Sean Donelan wrote: The FCC proposes $4,353,773.87 in total fines against 73 applicants in the Rural Digital Opportunity Fund Phase I Auction (Auction 904) that defaulted on their bids for support between July 26, 2021,

Re: Scanning the Internet for Vulnerabilities

2022-06-20 Thread goemon--- via NANOG
On Mon, 20 Jun 2022, Carsten Bormann wrote: On 2022-06-20, at 14:14, J. Hellenthal wrote: Yeah that's another thing, "research" cause you need to learn it let's have them do it too, multiply that by every university \o/ there was some actual research involved. I agree that there should be a v

Re: Scanning the Internet for Vulnerabilities

2022-06-19 Thread goemon--- via NANOG
On Sun, 19 Jun 2022, Ronald F. Guilmette wrote: In earlier times, this was generally viewed as being distinctly anti-social behavior, but perhaps attitudes have changed relative to earlier eras. I would thus like to know how people feel about it now, in 2022. This has not changed. -Dan

Re: FYI - 2FA to be come mandatory for ARIN Online? (was: Fwd: [arin-announce] Consultation on Requiring Two-Factor Authentication (2FA) for ARIN Online Accounts

2022-05-28 Thread goemon--- via NANOG
On Sat, 28 May 2022, Jim Popovitch via NANOG wrote: On Sat, 2022-05-28 at 11:36 -0700, Randy Bush wrote:   I am not in the ARIN region but I have attended few Arin meetings.   As a comment, I live a country were mobile roaming does not exists, therefore, when 2FA only works with SMS I can not us

Re: BANDWIDTH and VONAGE lose FCC rules exemption for STIR/SHAKEN

2022-02-18 Thread goemon--- via NANOG
On Fri, 18 Feb 2022, Michael Thomas wrote: On 2/17/22 11:58 AM, Sean Donelan wrote: https://www.fcc.gov/document/fcc-finds-two-providers-failed-fully-implement-stirshaken-0 The Federal Communications Commission today took action to ensure that voice service providers meet their commitments

Re: Abuse Contact Handling

2021-08-05 Thread goemon--- via NANOG
On Thu, 5 Aug 2021, Matt Corallo wrote: Thus, lots of the large hosting providers have deemed the cost of actually putting a human on an abuse contact is much too high. it seems they have decided that ending up on DBL is their abuse monitoring/reporting mechanism. -Dan

Re: SITR/SHAKEN implementation in effect today (June 30 2021)

2021-07-09 Thread goemon--- via NANOG
On Fri, 9 Jul 2021, K. Scott Helms wrote: Nothing will change immediately.  Having said that, I do expect that we will see much more effective enforcement.  The investigations will come from the ITG (Industry Traceback Group) with enforcement coming from FCC or FTC depending on the actual offen

Re: SITR/SHAKEN implementation in effect today (June 30 2021)

2021-07-09 Thread goemon--- via NANOG
On Fri, 9 Jul 2021, Michael Thomas wrote: Nothing has changed for me either. Color me surprised. The real proof will be to see if the originating domain can be determined, and whether the receiving domain does anything about it. Why would they do anything? The traffic is revenue. What is the