Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

Two More Rough Guides To IETF 91 On IPv6 And Security / TLS

IETF LogoTwo more “Rough Guide to IETF 91″ posts have been published that may be of interest to Deploy360 readers:

and

Phil’s post naturally talks about all the great work related to IPv6 happening within the various working groups at IETF 91 next week.  The reality is that IPv6 is now the main IP protocol discussed in so many different working groups – and all new work is assumed that it will (or must) work on IPv6 … and so IPv6 discussions are taking place in many different places.   You can expect that you’ll find members of the Deploy360 team in the dedicated IPv6 sessions Phil mentions!

Karen’s post highlights a number of the security and privacy efforts under way within the IETF and IAB.  She also mentions the TLS working group and the Using TLA in Applications (UTA) working groups, both of which are important to the TLS in Applications topic area we have here on Deploy360.

Combined with all the activities related to DNSSEC / DANE and all the activities related to routing security/resiliency … it’s going to be a very busy week next week!  We’re looking forward to it and to meeting up with many of you.

In the meantime, if you’d like to get started with IPv6 or TLS, please visit our Start Here page to begin!

CloudFlare Writes About DNSSEC Complexities And Considerations

CloudFlare logoThe folks over at CloudFlare published another great article earlier this week, “DNSSEC: Complexities and Considerations” that dives into more detail about some of the challenges of implementing DNSSEC.  Specifically, author Nick Sullivan explores the:

  • Exposure of DNS zone content through zone-walking
  • DNSSEC key management
  • DNS reflection/amplification attacks

He dives into the topics in great detail and explains what CloudFlare is planning to do to address each of these issues.  I strongly encourage you to check it out!

And then if you want to start implementing DNSSEC or DANE within your own environment, please visit our Start Here page to get started!

IETF 91 Rough Guide On Routing Resilience And Security – De-aggregation, Route Leaks and more

IETF LogoWhat will be happening next week at IETF 91 with regard to improving the security and resilience of the Internet’s routing infrastructure?

Our colleague Andrei Robachevsky tackles this question in his post this week: “Rough Guide to IETF 91: Routing Resilience & Security“.

Andrei explains that one of the major issues in routing right now is the growth in the size of the global routing tables and the growth of “de-aggregation”… and the challenges that lie therein.  He also writes about “route leaks” and what is being done to address this issue and he writes about the ongoing work related to RPKI in the SIDR working group.

He finishes up talking about the MANRS initiative announced yesterday  and how that can help with overall routing security and resiliency.

Please do read Andrei’s Rough Guide post … and then do check out our topic areas on Securing BGP and Anti-spoofing to learn more about how you can secure your routing infrastructure.  We will look forward to seeing some of you next week at IETF 91!

FIR On Technology Episode 2 – Known and the Indie Web

Firontechnology 300What is “Known” and how does it relate to the IndieWeb? What is the difference between the Known software and the Withknown hosted platform? How do these compare to the new Ello social network? And what value are any of these to communicators?

Back on October 29, I released episode 2 of "FIR On Technology with Dan York" where I had a discussion with Shel Holtz about the new Known platform and what it can do. If you haven't taken a listen yet, I encourage you to do so!

I would also encourage you to read my article from September 26: "The Importance of The 'Known' Publishing Platform And The Rise Of The Indie Web", as that was the basis of what got me interested in Known.

Please do explore, too, the lengthy list of links in the show notes that connect you to many different aspects of the Known project as well as to the larger IndieWeb movement.

As I noted, I am experimenting a bit with the hosted version of Known at http://danyork.withknown.com/. I'll be quite honest and say that I'm not yet ready to replace one of my primary publishing platforms... but I'm intrigued by what they are doing with Known and have been watching the ongoing updates to the platform on Github.

I have some ideas for some future projects and might consider Known... although I must admit that most of my work these days is heavily invested in WordPress and I'm trying not to have too many more platforms. However, there are some projects that don't need the full power that WordPress provides - and they might be perfect for what Known is trying to do.

Regardless, I think it's great to have another potential publishing platform out there - and I very much like the ideals of the IndieWeb movement!

Anyway... please do enjoy episode #2 of FIR On Technology - and please do let me know that you think of the podcast!


If you found this post interesting or useful, please consider either:


Video: BIND and DNSSEC – What Is New?

How does BIND work with DNSSEC? How easy is it to configure? What new features does it have that makes DNSSEC signing simple? How does it work as a DNSSEC-validating resolver? To answer these questions, I interviewed Eddy Winstead about BIND and what it can do with DNSSEC. We discussed BIND’s features as well as new training programs and documentation. It was an enjoyable interview that we recorded while Eddy and I were both at ICANN 51 in Los Angeles.  You can read more and download BIND from http://www.isc.org/ and more information about DNSSEC can be found from our Start Here page.

Enjoy!

“Innovation requires serendipity.” – Eli Pariser in “The Filter Bubble”

"Innovation requires serendipity." - Eli Pariser in "The Filter Bubble"

New MANRS Initiative Aims to Improve Security of Internet Routing (Featured Blog)

How can we work together to improve the security and resilience of the global routing system? That is the question posed by the "Routing Resilience Manifesto" site with the suggested answer launched today of the "Mutually Agreed Norms for Routing Security (MANRS) document, to which a number of network operators have already signed on as participants, including: Comcast, Level 3, NTT, RUNNet, ClaraNet, SURFnet, SpaceNet, KPN and CERNET. More...

TDYR 180 – Minding Your Network Routing MANRS

How can we work together to improve the security and resilience of the global routing system? A new "MANRS" initiative was launched today to answer that question! See http://www.manrs.org/ to read the MANRS document and sign up!

Arabic Translations Of IPv6 And DNSSEC Fact Sheets Now Available For Download

Rounding out the translations of our IPv6 Fact Sheet and our DNSSEC Fact Sheet into the six official U.N. languages, we are pleased to announce that the Arabic versions are now available:

From the IPv6 Fact Sheet and the DNSSEC Fact Sheet pages you can now get these fact sheets in English, Arabic, Chinese, French, Russian and Spanish.

As we noted in our earlier posts about the IPv6 Fact Sheet and about the DNSSEC Fact Sheet, these simple documents are available for you to use in whatever way you wish.  Please feel free to download them and share them widely.

Please do let us know any feedback you have on these documents.  Our goal is to help you get IPv6 and DNSSEC deployed within your organizations and networks.  Please let us know how we can help.

And if you want to get started with IPv6 or DNSSEC, please visit our Start Here page to find resources to help you get started!

arabic-ipv6

Show Your Commitment To Routing Security – Join the MANRS Initiative!

MANRS logo

Do you want to make the Internet’s routing infrastructure more secure?  Have you implemented anti-spoofing techniques to help protect against attacks such as DDoS attacks?  Have you secured your use of BGP on your network?

If so, why not consider publicly showing your support by signing up as a participant in the MANRS initiative?

This new routing security initiative, launched today, aims to promote better collaboration between network operators to make the Internet more secure and resilient.  As the home page says:

How can we work together to improve the security and resilience of the global routing system?

Originally called the “Routing Resilience Manifesto”, the initiative published today the “Mutually Agreed Norms for Routing Security” (MANRS) at:

https://www.routingmanifesto.org/manrs/

With the announcement came news of an initial set of participants that includes some of the largest global network operators such as Comcast, Level 3 and NTT.  More companies will be added and signups are already coming in!

To participate, a network operator needs to agree to at least 2 (and ideally all 4) of these actions:

Basically you could think of this as a “code of conduct” for network routing… an agreement that companies publicly say they are going to follow to help the overall Internet’s routing infrastructure be more resilient and secure.

Our colleague Andrei Robachevsky has been heading this project and working with a team of people from network operators around the world (some of whom have already signed on as formal participants, others who hope to do so soon).  It’s great to see this out there and we look forward to seeing the list of participants grow.

Please do read the MANRS document and sign up if your network can undertake those actions.  If every network operator can mind their MANRS, we’ll all have a much safer, more secure and more resilient Internet!

P.S. If you are looking for information about how to get started with anti-spoofing or securing BGP, please see our Network Operators Start Here page to get started.