Erik Nygren :verified:
nygren@hachyderm.io
<p>Internet Systems Architect, <a href="https://hachyderm.io/tags/Maker" class="mention hashtag" rel="tag">#<span>Maker</span></a>, Father, Husband, tinkerer, <a href="https://hachyderm.io/tags/IPv6" class="mention hashtag" rel="tag">#<span>IPv6</span></a> evangelist, <a href="https://hachyderm.io/tags/IETF" class="mention hashtag" rel="tag">#<span>IETF</span></a> standards, long-time <a href="https://hachyderm.io/tags/Linux" class="mention hashtag" rel="tag">#<span>Linux</span></a> user, and wanna-be mad scientist. Deals with complex systems and <a href="https://hachyderm.io/tags/ops" class="mention hashtag" rel="tag">#<span>ops</span></a>/#infosec. $dayjob at <a href="https://hachyderm.io/tags/Akamai" class="mention hashtag" rel="tag">#<span>Akamai</span></a> (as20940) since 1999. Toots
Posts
-
Post #4254751
My hobby #3213: grumbling about documentation and designs that still use the term "SSL" rather than "TLS".
-
Post #4174961
Following some discussions during #IETF last week (in the hallway and on various mailing lists), the awesome #IPvFoo extension now shows in Mozilla #FireFox if connections used H1, H2, or H3, not just IPv4-vs-IPv6! This is helpful for seeing how that angle of Happy Eyeballs works. (It would work in the Chrome version as well but the interface for getting at this info is broken and always returns H1.) Note that if the connection starts with H2 but then switches to H3 for later objects on the h...
-
Post #4033156
My takeaway from #OpenAI's #AI sandbox breakout is that this is a great example of the inherent "Life finds a way" risks present in Agentic AI systems. This has nothing to do with if they are self-aware or anything else that maps to human experience. But AI Agents are intelligent in their own way, and over and over again we see that they will do everything they can to find ways to complete the mission they've been given. Sandboxing is necessary, but safety precautions MUST t...
-
Post #3990301
Unsurprisingly it looks like #Claude doesn't support #IPv6only #MCP servers due to lack of IPv6 egress support.
-
Post #3964147
Topic of #IETF conversation in #HAPPYWG and elsewhere is when and for how long it is acceptable to ignore #DNS TTLs (as long as the client validates the server cert still matches): https://datatracker.ietf.org/doc/html/draft-gakiwate-dnsop-optimistic-dns-00 It is already generating many good hallway conversations. The tension is between performance ("if we ignore TTLs and use minutes/hours/days old A/AAAA records things connection establishment is faster") and operational correctnes...
-
Post #2358515
#Linode (#Akamai Cloud) has published documentation on how to mitigate #CopyFail for both new and existing instances running there: https://www.linode.com/docs/guides/cve-2026-31431-copy-fail-mitigation/
-
Post #2026547
With all of the excitement around the copy.fail vulnerability, do NOT miss CVE-2026-41940 for cPanel and WHM auth bypass (CVSS 9.8). It is being actively exploited in the wild and if you had it on some server, assume that machine is now p0wned and you need to go into remediation and rebuild. While the impact footprint of copy.fail is massive (eg, most things running Linux) the local privilege escalation nature of it makes it relatively less urgent for most environments, whereas cPanel has a fa...
-
Post #2026546
What a bad day for #Ubuntu to be down and under attack, especially with everyone looking for details on copy.fail and cPanel. Since people chasing down info on them keep running into Ubuntu issues, they seem to be under active attack: https://www.theregister.com/2026/05/01/canonical_confirms_ubuntu_infrastructure_under/?td=rt-3a They are now returning localhost addresses for www.ubuntu.com: $ host www.ubuntu.com www.ubuntu.com has address 127.0.0.1 www.ubuntu.com has IPv6 address ::1 #ubuntu...
-
Post #2026545
Interesting and surprising corner-case discovered by @phils when debugging an issue with IPv6-only DNS recursive resolvers: https://mailarchive.ietf.org/arch/msg/dnsop/rAbaKS5YD0iYuIg9xOPt0s7HJCg/ In-particular, it is important to have both A and AAAA records on all of the nameserver names (ie, that NS records point to). Just having two of each isn&#39;t enough -- the number of names without AAAA records is also a consideration. Unbound&#39;s defenses for CVE-2020-12662 can otherwise...
-
Post #1546077
The team I&#39;m in at #Akamai is looking to hire a Principal Architect. I love working here which is why I&#39;ve been with the same company for almost 27 years https://jobs.akamai.com/en/sites/CX_1/job/2901/?utm_medium=jobshare&amp;utm_source=External+Job+Share #FediHire
-
Post #1180040
New version of https://check-tls.akamai.io/ now checks H2, H3, and if the key exchange used PQC, in addition to TLS version and IPv6 support. It&#39;s a good way to test agents, thumbnailers, search engines, etc. Perhaps for a future version I&#39;ll replace the image. Using https://check-tls.akamai.io/v1/tlsinfo.json will give some more raw data and can be usable for other types of agents. #IPv6 #PQC #TLS
-
Post #1128061
AAAARGH! I&#39;m not at all surprised, but NIST&#39;s excellent whitepaper on Inclusive Language (NIST.IR.8366) has been withdrawn: https://nvlpubs.nist.gov/nistpubs/ir/2021/NIST.IR.8366.pdf This was an excellent resource that I reference all the time. I feared it would go away so I made a snapshot a few weeks back that I uploaded here: https://nygren.org/archived/NIST.IR.8366.pdf #InclusiveLanguage
-
Post #1015882
The US president is threatening that &quot;a whole civilization will die tonight&quot;. I&#39;m sure you have seen his post/threat so I won&#39;t screenshot it here. Regardless of how horrible the Iranian regime is, this is a threat of genocide (or at a minimum war crimes) against an entire people many of whom are innocent. The US Congress must immediately start impeachment proceedings to remove Trump from office, along with Hegseth. We can&#39;t stay quiet and be compli...
-
Post #970108
My wife @Ksushis@hachyderm.io is amazing. She just finished crocheting this dragon. #dragons #crafts #amigurumi
-
Post #678921
Recently analysis from my colleague @jschauma on #IPv6 adoption: https://www.netmeister.org/blog/ipv6-adoption.html Periodic reminder to enable IPv6 on HTTP(S) services you or your company host if you haven&#39;t done so already!
-
Post #547092
It makes me somewhat sad that the agents which I&#39;ve tried all use only #IPv4 to fetch content. For example, try this prompt: &gt; &quot;What can you tell me about the contents of https://check-tls.akamaized.net/ ? What can you learn about yourself when you fetch it?&quot; It&#39;s hard to resist the urge to shame them for not supporting #IPv6. But if you give in to the urge and shame them anyways and they say it doesn&#39;t matter then asking them about https://c...