Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

Sorry, But No, I Won’t Add a Link To A Blog Post for $60!

Oh, the scammers and spammers.... I was amused in today's normal haul of bogus comments across my various blogs to get this one:

If you’re willing to place a link to my client, <URL-deleted> with the anchor text “<client-name-deleted>” in one of your new articles then I will send you a one-time payment of $60 via PayPal.

<client-name-deleted> provides the best deals for <deleted> across the country. If you’re interested, please let me know the email address where you’d like me to send the PayPal payment and I will send it once you add the link.

I'd seen this type of message many times before, of course, but just deleted them as a matter of course.

This time, though, I picked up on "to my client".

One wonders, does the client understand the sleazy way in which this person is going about their work? Does the client even care? Are they just paying for "results"?

I do wonder, too, how many people out there just go ahead and accept the offer... hey, $60 can buy a bit and... "why not? They're just asking for a link!" Probably a number of folks... which then only leads to more messages like this...

P.S. And no, I've never taken money to put links in articles. And I certainly wouldn't for only $60. Now... add maybe 2 or 3 zeroes to that number and maybe I'd start considering it... ;-)


If you found this post interesting or useful, please consider either:


Can Komen Ever Regain Our Trust?

There is perhaps no more powerful statement on the betrayal felt by many women with regard to the Susan G. Komen / Planned Parenthood debacle than this one simple video from "Linda":

The pain of her treatment is that felt by at least 1 in 8 women during their lifetime. Her scars on her chest are like those of my wife and so many other women for whom the "cure" involved radical changes to their bodies.

Her sense of betrayal is that of so many women.

Komen ideologyIt's not that the Susan G. Komen For The Cure organization can't choose who it wants to fund based on ideological/political reasons. It can. That is a perfectly valid way to run an organization and to choose who to fund.

But that's not what people signed up for.

It's not what they donated money for.

It's not what they ran or walked races for.

They donated/ran/walked/volunteered... FOR THE CURE.

There was never an asterisk on the "cure".

It was never "for the cure as long as said cure meets our ideological/political guidelines".

It was for the cure. Period. Full stop.

Perhaps it was naive to believe that no politics were involved, but people believed in the story of the Susan G. Komen For The Cure organization. They completely empathized with Nancy Brinker founding the organization based on a promise to her sister who died of breast cancer. They believed in the story. They supported the organization with their time, money and energy. They made the Komen organization the amazingly powerful force that that is today.

It was for the cure. Period. Full stop.

But then Komen completely mishandled communicating the Planned Parenthood issue and made it far worse with a disastrous interview with Andrea Mitchell that raised many more questions than it answered.

Sure, the Komen Board eventually reversed its position, which was pretty much guaranteed to satisfy almost no one. And certainly many people may be pleased at the departure of Komen VP Karen Handel.

But Komen has a far larger problem.

The proverbial curtain has been pulled back and Komen supporters are learning more about the organization that they have supported.

They are learning of the political activities of the organization's leaders. They are learning about other instances, such as the ending of funding to organizations that supported embryonic stem cell research, even though no Komen funding apparently went directly to such research and the Komen organization had in fact trumpeted the potential of such research back in 2006. A statement about this topic on November 30, 2011, was apparently posted to the Komen website but subsequently removed.

Regardless of how you may personally feel about embryonic stem cell research and whether you think it is should be pursued or whether you think it should be outlawed, this is another example of the politicization of Komen's grant-making.

It was for the cure. Period. Full stop. Never with an asterisk.

And more questions are being raised about Komen's methods, their choices, their staffing... and, well, pretty much everything about the organization.

And while there can be no doubt that the Komen organization has done a tremendous amount of work for breast cancer education and research (just look at the last few pages of their 2010 Form 990 to see all the many grants they've given), the question many of us (including my wife and I, who have been definite Komen supporters during my wife's ongoing fight with breast cancer) are now asking is:

Are they the right organization to whom to donate?

Can we trust Komen's leaders to truly put the "cure" above their personal politics?

Are there better organizations where we should focus our time, dollars and energy? Can our dollars be more effective going to organizations directly involved with research?

How do we find a cure for breast cancer? Or at least better tools than the sledgehammers we have today?

Komen's now lost the trust of the Linda's of the world who believed so strongly in the mission and purpose of the organization. Can they regain that trust? Maybe. Maybe not.

It was for the cure. Period. Full stop. Never with an asterisk.

IP Best Current Operational Practices (IPBCOP) Project Launches New Website

Are you looking for “best practices” within the operations community?  If so, our friends over at the IP Best Current Operational Practices (IPBCOP) effort have just launched a new website to help make their information more accessible and available. The IPBCOP project, led by Aaron Hughes and Richard Donaldson, emerged out of a series of operator meetings such as NANOG where it became clear that a need existed to collect operational best practices within the operator community and capture those in a series of documents and templates that others can use.

The project has been working via a mailing list for the past while and currently has three drafts under active consideration:

More drafts are in development and a BCOP template is available for those interested in submitting their own best practices document for consideration.  The IPBCOP project is very much a community effort and all communication really happens through their mailing list, which is open for anyone interested to join.  You can also connect with IPBCOP on Twitter, Facebook and Google+.

We think this is a great effort that will only help the operations community move forward with technologies like IPv6 and we encourage you all to check it out and if possible get involved!

Free Light Reading Webinar Feb 8th: Making the IPv6 Transition For Cable

If you have 90 minutes to spare tomorrow, Wednesday, February 8, 2012, the folks over at Light Reading are offering a free (see below) webinar at 1:00 pm US Eastern on the topic of “Making the IPv6 Transition For Cable“.  It is sponsored by Arris, Cisco, Juniper Networks and Motorola, and more importantly has an expert panel of people from the cable industry:

  • John Brzozowski, Distinguished Engineer & Chief Architect for IPv6, Comcast
  • Jeff Finkelstein, Senior Director, Network Architecture, Cox Communications
  • Lee Howard, Director of Network Technology, Time Warner Cable

Given that we know these folks ourselves, we expect their contributions to the webinar to provide solid information and case studies for other cable operators and service providers.  The webinar will also apparently include presenters from the various sponsors who will probably provide their perspective on how their various products and services can help with the IPv6 transition.

Due note that this webinar is “free” in the sense that there is no direct financial cost. As is typical of these type of sponsored webinars, you do, of course, need to provide information about yourself that will then be provided to the sponsors for their marketing efforts.

Regardless of that fact, I expect that there will be some quite useful IPv6 information available during the session and I’ll be personally joining in for at least the first hour of the session. I expect, although don’t know for certain, that there will be a recording available for later viewing (subject, again, to providing all your contact information).

It’s great to see these kind of sessions out there as we get closer and closer to World IPv6 Launch on June 6th!

The folks at Light Reading also produced a brief video providing a preview of some of the topics and people involved with tomorrow’s webinar:

P.S. Hat tip to Stephen Liu over on Cisco’s blog where we saw mention of this webinar.

Government Computer News – Thanks for the Deploy360 Mention!

GovernmentcomputernewsVery nice to see the mention of Deploy360 in the Government Computer News “CyberEye” column: Internet Society launches info hub for DNSSEC, IPv6. Many thanks for the mention! The US Government has been pushing hard on both IPv6 and DNSSEC and we’ve got some statistics on our site about US government DNSSEC and IPv6 adoption. We’ve also got some more sites that we’ll be adding to our list of resources that are specifically government-related. We’re very much looking forward to doing all we can to help government IT professionals from the US and from governments all around the world.

If you are a government IT professional, please do look around our site and see if the resources we have here can help you. And if you still need answers to questions, please let us know and we’ll be glad to help!

US DoD DREN Provides Excellent IPv6 Knowledge Base

DOD High Performance Computing Modernization ProgramIf you are looking to learn more about IPv6 or looking for lists of products and training resources related to IPv6, the folks over at the United States Department of Defense (DOD) High Performance Computing Modernization Program maintain a comprehensive site devoted to sharing information about IPv6 based on the work of the Defense Research and Engineering Network (DREN).

Long names and acronyms aside, some of the many excellent resources to be found within the site include:

The site includes a great amount of information of value not only to US government agencies and employees, but also to anyone working with IPv6.  Kudos to the team at DREN for maintaining the site and we’re pleased to add it to the list of resources we’re promoting here on Deploy360.

Attending O’Reilly’s TOCCON Next Week? Deploy360 Will Be There…

Logo for O'Reilly's Tools of Change for Publishing ConferenceWill you be attending O’Reilly’s “Tools of Change for Publishing 2012” conference (a.k.a. “TOCCON”) in New York from February 13-15, 2012? If so, I (Dan York) will be there and would be delighted to connect with readers of this site. (Just drop me an email or ping me on Twitter.) Given the incredible changes happening within the world of publishing – both online and traditional – I’ll be down at TOCCON  looking at how we can best seize the opportunities presented by these changes to make our Deploy360 content available in even more formats and channels.  Additionally, a number of sessions are about the underlying technology we’re using (WordPress) or have relevance to the kind of platform we’re building – so I’ll be looking forward to picking up any tips and tricks that will help our site work even smoother and better.

If you aren’t familiar with TOCCON, it’s an annual event sponsored by O’Reilly, the well-known technical publisher, that brings together many of the people at the bleeding edge of the disruption happening within the world of content creation.  Here’s the quick intro from their site:

The acceleration of change and innovation in the publishing industry today is dizzying, and the pace can be overwhelming. But this change/forward/fast environment is also ripe with opportunity for those who embrace it and learn to adapt and innovate quickly.

O’Reilly’s TOC Conference is where the publishing and tech industries converge, as practitioners and executives from both camps share what they’ve learned from their successes and failures, explore ideas, and join together to navigate publishing’s ongoing transformation. TOC 2012 delivers a deft mix of the practical and the visionary to give attendees the tools and guidance they need to succeed—and the inspiration to lead change.

On a personal note, attending TOCCON will be a bit unusual for me. It’s the first time I can recall in many years when I am attending an event and not speaking, staffing a booth or reporting on the event (or, more typically, doing all three).   I’m just there to learn about the tools and technologies and to meet people involved… it will be a interesting change!  :-)

Only 4 months to World IPv6 Launch – are you getting ready?

World IPv6 Launch (more info here) is only four months away on June 6, 2012 -

are you getting ready?

If you haven’t started yet, now is a good time to get going!  Here are some resources we have to help you get started:

We are also always publishing new blog posts related to IPv6 covering a wide range of topics.

More than that, please let us know how we can help you get started with IPv6!

DNSSEC Train-The-Trainer From NLnet Labs Feb 9-10 and Feb 16-17

NL Net LabsInterested in teaching DNSSEC or developing your own DNSSEC training courses or courseware? We recently learned that Olaf Kolkman of NLNet Labs will be teaching a “DNSSEC train-the-trainer” class two separate times this month. His first class is this week on Thursday and Friday, February 9th and 10th. His second is next week on February 16th and 17th. The material covered will include:

BLOCK 1 Classic DNS
BLOCK 2: Unbound in practice
BLOCK 3: DNS Security DNSSEC Theory fundamentals
BLOCK 4: DNS Keys: risks and management
BLOCK 5: Introducing DNSSEC in a workflow
BLOCK 6: Software and tools availability and development
PRACTICE 1: Setting up a validating recursive nameserver
PRACTICE 2: Setting up an Authorititive Nameserver
PRACTICE 3: Secure Delegation
PRACTICE 4: KEY Rollover

The class is being taught at the Fastlane training center in De Meern, The Netherlands, and the information we have is that there are still a few remaining openings in each class. Contact information and a full course outline can be found on the NGN.nl page about the DNSSEC training (in Dutch).

Information Week on DNSSEC: Having the keys to your own castle is important

So there I was eating my lunch and reading a treeware version of Information Week (you know, those paper things we called “magazines” before everything went to e-something?).  Having always been interested in encryption, I started reading the “2012 Data Encryption Survey: Progress and Pain” (sadly, free registration is required to read the whole article) expecting it to be, well, all about data encryption…

… and it was – particularly starting off talking about the the challenges of using SSL/TLS with all the attempts to break SSL, and the multiple compromises at SSL certificate companies that have resulted in attackers successfully getting bogus, but valid, certificates asserting they were someone else.

Then all of a sudden I stopped eating my sandwich as the article took a sharp turn into the world of DNSSEC (and yes, I added some emphasis at the end):

Enter DNSSEC. The DNS Security Extension spec provides the capability for a domain owner–the IT team–to place additional encryption validation at the DNS layer. First it will verify that the SSL certificate is valid. But it also will verify that the DNS server that is authoritative for the domain being requested actually belongs to the certificate owner.

In our example, if a user went to the breached Hotmail.com site and got a Hotmail.com certificate, it wouldn’t validate with the DNS server hosting Hotmail.com, because the certificate generated by the attacker using the hacked CA wouldn’t match. The browser could display a big red box telling the user he’s going to an invalid site. Currently, Google’s Chrome supports DNSSEC natively, and there are plug-ins for Firefox. Internet Explorer 9 doesn’t support DNSSEC, but version 10 is expected to.

The other benefit of DNSSEC is that DNS queries are validated by all servers–from the domain’s authoritative server to the local DNS server to the browser–which means that even man-in-the-middle attacks on DNS queries will be caught.

DNSSEC isn’t perfect, and it’s not a complete replacement for SSL/TLS. But it is a step in the right direction to put control of certificate verification into the hands of certificate owners, instead of the CAs. Furthermore, using DNSSEC is a great solution for organizations with their own internal CAs that don’t want to deploy certificates to every possible device. Most of our respondents, 55%, have their own internal CAs; an additional 15% plan to within 24 months.

Having the keys to your own castle is an important step in controlling your encryption destiny, and if you plan to leverage cloud services securely, it may just be a requirement.

Here, in just a few paragraphs, was a great explanation of an important role DNSSEC can play as another layer in the security infrastructure.  In this case, DNSSEC can be used to check the validity of the certificates being used for SSL/TLS.

More importantly, me being the control-freak that I am, the article points out the incredible importance of being in control of your own security.  You, as the domain owner, can be the one inserting the appropriate keys directly into the DNS infrastructure.  Or you can have someone do it on your behalf… but the point is that you are in control.

That’s a powerful capability!

What do you think?  Have you started looking at DNSSEC yet?  If not, check out the DNSSEC resources we’ve listed so far – and if you don’t find exactly what you need, please ask us about it and we’ll see if we can find something to help you.

P.S. For those wondering, the rest of the article provided some interesting discussion and statistics around encryption within cloud computing platforms and with the use of mobile devices such as tablets and smartphones. Oh, and I did eventually finish my sandwich. ;-)