Just a guy in Vermont trying to connect all the dots...
Author's posts
Nov 07
Two More Rough Guides To IETF 91 On IPv6 And Security / TLS
Two more “Rough Guide to IETF 91″ posts have been published that may be of interest to Deploy360 readers:
- Rough Guide to IETF 91: All About IPv6 by Phil Roberts
and
- Rough Guide to IETF 91: Strengthening the Internet (STRINT) Activities Continue by Karen O’Donoghue
Phil’s post naturally talks about all the great work related to IPv6 happening within the various working groups at IETF 91 next week. The reality is that IPv6 is now the main IP protocol discussed in so many different working groups – and all new work is assumed that it will (or must) work on IPv6 … and so IPv6 discussions are taking place in many different places. You can expect that you’ll find members of the Deploy360 team in the dedicated IPv6 sessions Phil mentions!
Karen’s post highlights a number of the security and privacy efforts under way within the IETF and IAB. She also mentions the TLS working group and the Using TLA in Applications (UTA) working groups, both of which are important to the TLS in Applications topic area we have here on Deploy360.
Combined with all the activities related to DNSSEC / DANE and all the activities related to routing security/resiliency … it’s going to be a very busy week next week! We’re looking forward to it and to meeting up with many of you.
In the meantime, if you’d like to get started with IPv6 or TLS, please visit our Start Here page to begin!
Nov 07
CloudFlare Writes About DNSSEC Complexities And Considerations
The folks over at CloudFlare published another great article earlier this week, “DNSSEC: Complexities and Considerations” that dives into more detail about some of the challenges of implementing DNSSEC. Specifically, author Nick Sullivan explores the:
- Exposure of DNS zone content through zone-walking
- DNSSEC key management
- DNS reflection/amplification attacks
He dives into the topics in great detail and explains what CloudFlare is planning to do to address each of these issues. I strongly encourage you to check it out!
And then if you want to start implementing DNSSEC or DANE within your own environment, please visit our Start Here page to get started!
Nov 07
IETF 91 Rough Guide On Routing Resilience And Security – De-aggregation, Route Leaks and more
What will be happening next week at IETF 91 with regard to improving the security and resilience of the Internet’s routing infrastructure?
Our colleague Andrei Robachevsky tackles this question in his post this week: “Rough Guide to IETF 91: Routing Resilience & Security“.
Andrei explains that one of the major issues in routing right now is the growth in the size of the global routing tables and the growth of “de-aggregation”… and the challenges that lie therein. He also writes about “route leaks” and what is being done to address this issue and he writes about the ongoing work related to RPKI in the SIDR working group.
He finishes up talking about the MANRS initiative announced yesterday and how that can help with overall routing security and resiliency.
Please do read Andrei’s Rough Guide post … and then do check out our topic areas on Securing BGP and Anti-spoofing to learn more about how you can secure your routing infrastructure. We will look forward to seeing some of you next week at IETF 91!
Nov 07
FIR On Technology Episode 2 – Known and the Indie Web
What is “Known” and how does it relate to the IndieWeb? What is the difference between the Known software and the Withknown hosted platform? How do these compare to the new Ello social network? And what value are any of these to communicators?
Back on October 29, I released episode 2 of "FIR On Technology with Dan York" where I had a discussion with Shel Holtz about the new Known platform and what it can do. If you haven't taken a listen yet, I encourage you to do so!
I would also encourage you to read my article from September 26: "The Importance of The 'Known' Publishing Platform And The Rise Of The Indie Web", as that was the basis of what got me interested in Known.
Please do explore, too, the lengthy list of links in the show notes that connect you to many different aspects of the Known project as well as to the larger IndieWeb movement.
As I noted, I am experimenting a bit with the hosted version of Known at http://danyork.withknown.com/. I'll be quite honest and say that I'm not yet ready to replace one of my primary publishing platforms... but I'm intrigued by what they are doing with Known and have been watching the ongoing updates to the platform on Github.
I have some ideas for some future projects and might consider Known... although I must admit that most of my work these days is heavily invested in WordPress and I'm trying not to have too many more platforms. However, there are some projects that don't need the full power that WordPress provides - and they might be perfect for what Known is trying to do.
Regardless, I think it's great to have another potential publishing platform out there - and I very much like the ideals of the IndieWeb movement!
Anyway... please do enjoy episode #2 of FIR On Technology - and please do let me know that you think of the podcast!
If you found this post interesting or useful, please consider either:
- following me on Twitter;
- adding me to a circle on Google+;
- following me on Ello;
- following me on App.net;
- subscribing to my email newsletter; or
- subscribing to the RSS feed.
Nov 07
Video: BIND and DNSSEC – What Is New?
How does BIND work with DNSSEC? How easy is it to configure? What new features does it have that makes DNSSEC signing simple? How does it work as a DNSSEC-validating resolver? To answer these questions, I interviewed Eddy Winstead about BIND and what it can do with DNSSEC. We discussed BIND’s features as well as new training programs and documentation. It was an enjoyable interview that we recorded while Eddy and I were both at ICANN 51 in Los Angeles. You can read more and download BIND from http://www.isc.org/ and more information about DNSSEC can be found from our Start Here page.
Enjoy!
Nov 07
“Innovation requires serendipity.” – Eli Pariser in “The Filter Bubble”
"Innovation requires serendipity." - Eli Pariser in "The Filter Bubble"
Nov 06
New MANRS Initiative Aims to Improve Security of Internet Routing (Featured Blog)
Nov 06
TDYR 180 – Minding Your Network Routing MANRS
Nov 06
Arabic Translations Of IPv6 And DNSSEC Fact Sheets Now Available For Download
Rounding out the translations of our IPv6 Fact Sheet and our DNSSEC Fact Sheet into the six official U.N. languages, we are pleased to announce that the Arabic versions are now available:
From the IPv6 Fact Sheet and the DNSSEC Fact Sheet pages you can now get these fact sheets in English, Arabic, Chinese, French, Russian and Spanish.
As we noted in our earlier posts about the IPv6 Fact Sheet and about the DNSSEC Fact Sheet, these simple documents are available for you to use in whatever way you wish. Please feel free to download them and share them widely.
Please do let us know any feedback you have on these documents. Our goal is to help you get IPv6 and DNSSEC deployed within your organizations and networks. Please let us know how we can help.
And if you want to get started with IPv6 or DNSSEC, please visit our Start Here page to find resources to help you get started!
Nov 06
Show Your Commitment To Routing Security – Join the MANRS Initiative!
Do you want to make the Internet’s routing infrastructure more secure? Have you implemented anti-spoofing techniques to help protect against attacks such as DDoS attacks? Have you secured your use of BGP on your network?
If so, why not consider publicly showing your support by signing up as a participant in the MANRS initiative?
This new routing security initiative, launched today, aims to promote better collaboration between network operators to make the Internet more secure and resilient. As the home page says:
How can we work together to improve the security and resilience of the global routing system?
Originally called the “Routing Resilience Manifesto”, the initiative published today the “Mutually Agreed Norms for Routing Security” (MANRS) at:
With the announcement came news of an initial set of participants that includes some of the largest global network operators such as Comcast, Level 3 and NTT. More companies will be added and signups are already coming in!
To participate, a network operator needs to agree to at least 2 (and ideally all 4) of these actions:
- Filtering – Prevent propagation of incorrect routing information.
- Anti-spoofing – Prevent traffic with spoofed source IP addresses.
- Coordination – Facilitate global operational communication and coordination between network operators.
- Global Validation – Facilitate validation of routing information on a global scale.
Basically you could think of this as a “code of conduct” for network routing… an agreement that companies publicly say they are going to follow to help the overall Internet’s routing infrastructure be more resilient and secure.
Our colleague Andrei Robachevsky has been heading this project and working with a team of people from network operators around the world (some of whom have already signed on as formal participants, others who hope to do so soon). It’s great to see this out there and we look forward to seeing the list of participants grow.
Please do read the MANRS document and sign up if your network can undertake those actions. If every network operator can mind their MANRS, we’ll all have a much safer, more secure and more resilient Internet!
P.S. If you are looking for information about how to get started with anti-spoofing or securing BGP, please see our Network Operators Start Here page to get started.


