Just a guy in Vermont trying to connect all the dots...
Author's posts
Nov 30
Call for Participation — ICANN DNSSEC Workshop at ICANN 55 in Marrakech, Morocco
The DNSSEC Deployment Initiative and the Internet Society Deploy360 Programme, in cooperation with the ICANN Security and Stability Advisory Committee (SSAC), are planning a DNSSEC Workshop at the ICANN 55 meeting on 09 March 2016 in Marrakech, Morocco. The DNSSEC Workshop has been a part of ICANN meetings for several years and has provided a forum for both experienced and new people to meet, present and discuss current and future DNSSEC deployments. For reference, the most recent session was held at the ICANN meeting in Dublin, Ireland on 21 October 2015. The presentations and transcripts are available at: https://meetings.icann.org/en/dublin54/schedule/wed-dnssec.
At ICANN 55 we are particularly interested in live demonstrations of uses of DNSSEC or DANE. Examples might include:
* Email clients and servers using DNSSEC, OPENPGPKEY, or S/MIME for secure email.
* Tools for automating the generation of DNSSEC/DANE records.
* Services for monitoring or managing DNSSEC signing or validation.
* Tools or services for using DNSSEC/DANE along with other existing protocols and
services such as SSH, XMPP, SMTP, S/MIME or PGP/GPG.
* Innovative uses of APIs to do something new and different using DNSSEC/DANE.
* S/MIME and Microsoft Outlook integration with active directory.
Our interest is to provide current examples of the state of development and to show real-world examples of how DNSSEC and DANE related innovation can be used to increase the overall security of the Internet.
We are open to presentations and demonstrations related to any topic associated with DNSSEC and DANE.
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to dnssec-marrakech@isoc.org by **Monday, 14 December 2015**
Examples of the types of topics we are seeking include:
1. DNSSEC activities in Africa
For this panel we are seeking participation from those who have been involved in DNSSEC deployment in Africa and also from those who have not deployed DNSSEC but who have a keen interest in the challenges and benefits of deployment. In particular, we will consider the following questions: Are you interested in reporting on DNSSEC validation of your ISPs? What can DNSSEC do for you? What doesn’t it do? What are the internal tradeoffs to implementing DNSSEC? What did you learn in your deployment of DNSSEC? We are interested in presentations from both people involved with the signing of domains and people involved with the deployment of DNSSEC-validating DNS resolvers.
2. Potential impacts of Root Key Rollover
Given many concerns about the need to do a Root Key Rollover, we would like to bring together a panel of people who can talk about what the potential impacts may be to ISPs, equipment providers and end users, and also what can be done to potentially mitigate those issues. In particular, we are seeking participation from vendors, ISPs, and the community that will be affected by distribution of new root keys. We would like to be able to offer suggestions out of this panel to the wider technical community. If you have a specific concern about the Root Key Rollover, or believe you have a method or solution to help address impacts, we would like to hear from you.
3. Implementing DNSSEC validation at Internet Service Providers (ISPs)
Internet Service Providers (ISPs) play a critical role by enabling DNSSEC validation for the caching DNS resolvers used by their customers. We have now seen massive rollouts of DNSSEC validation within large North American ISPs and at ISPs around the world. We are interested in presentations on topics such as:
* Can you describe your experiences with negative Trust Anchors and operational realities?
* What does an ISP need to do to prepare its network for implementing DNSSEC validation?
* How does an ISP need to prepare its support staff and technical staff for the rollout of DNSSEC validation?
* What measurements are available about the degree of DNSSEC validation currently deployed?
* What tools are available to help an ISP deploy DNSSEC validation?
* What are the practical server-sizing impacts of enabling DNSSEC validation on ISP DNS Resolvers (ex. cost, memory, CPU, bandwidth, technical support, etc.)?
4. The operational realities of running DNSSEC
Now that DNSSEC has become an operational norm for many registries, registrars, and ISPs, what have we learned about how we manage DNSSEC? What is the best practice around key rollovers? How often do you review your disaster recovery procedures? Is there operational familiarity within your customer support teams? What operational statistics have we gathered about DNSSEC? Are there experiences being documented in the form of best practices, or something similar, for transfer of signed zones?
5. DANE and DNSSEC application automation
For DNSSEC to reach massive deployment levels it is clear that a higher level of automation is required than is currently available. There also is strong interest for DANE usage within web transactions as well as for securing email and Voice-over-IP (VoIP). We are seeking presentations on topics such as:
* What tools, systems and services are available to help automate DNSSEC key management?
* Can you provide an analysis of current tools/services and identify gaps?
* Where are the best opportunities for automation within DNSSEC signing and validation processes?
* What are the costs and benefits of different approaches to automation?
* What are some of the new and innovative uses of DANE and other DNSSEC applications in new areas or industries?
* What tools and services are now available that can support DANE usage?
* How soon could DANE and other DNSSEC applications become a deployable reality?
* How can the industry use DANE and other DNSSEC applications as a mechanism for creating a more secure Internet?
We would be particularly interested in any live demonstrations of DNSSEC / DANE application automation and services. For example, a demonstration of the actual process of setting up a site with a certificate stored in a TLSA record that correctly validates would be welcome. Demonstrations of new tools that make the setup of DNSSEC or DANE more automated would also be welcome.
6. When unexpected DNSSEC events occur
What have we learned from some of the operational outages that we have seen over the past 18 months? Are there lessons that we can pass on to those just about to implement DNSSEC? How do you manage dissemination of information about the outage? What have you learned about communications planning? Do you have a route to ISPs and registrars? How do you liaise with your CERT community?
7. DNSSEC and DANE in the enterprise
Enterprises can play a critical role in both providing DNSSEC validation to their internal networks and also through signing of the domains owned by the enterprise. We are seeking presentations from enterprises that have implemented DNSSEC on validation and/or signing processes and can address questions such as:
* What are the benefits to enterprises of rolling out DNSSEC validation? And how do they do so?
* What are the challenges to deployment for these organizations and how could DANE and other DNSSEC applications address those challenges?
* How should an enterprise best prepare its IT staff and network to implement DNSSEC?
* What tools and systems are available to assist enterprises in the deployment of DNSSEC?
* How can the DANE protocol be used within an enterprise to bring a higher level of security to transactions using SSL/TLS certificates?
8. Hardware Security Modules (HSMs) use cases and innovation
We are interested in demonstrations of HSMs, presentations of HSM-related innovations and real world use cases of HSMs and key management.
In addition, we welcome suggestions for additional topics.
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to dnssec-marrakech@isoc.org by **Monday, 14 December 2015**
We hope that you can join us.
Thank you,
Julie Hedlund
On behalf of the DNSSEC Workshop Program Committee:
Mark Elkins, DNS/ZACR
Cath Goulding, Nominet UK
Jean Robert Hountomey, AfricaCERT
Jacques Latour, .CA
Xiaodong Lee, CNNIC
Luciano Minuchin, NIC.AR
Russ Mundy, Parsons
Ondřej Surý, CZ.NIC
Yoshiro Yoneya, JPRS
Dan York, Internet Society
Nov 30
TDYR 277 – New WordPress Admin Interface and Mac App
Nov 30
Cyber Monday: Save 50% on “Migrating Apps to IPv6”
Today you have a great opportunity to buy “Migrating Applications to IPv6” and hundreds of other ebooks and videos from O’Reilly and associated publishers at a discount of 50% off or more. Simply go to:
and start shopping! Or you can go directly to the book’s page at O’Reilly at:
As I’ve mentioned in the past, buying direct from O’Reilly offers multiple excellent benefits, including:
- DRM-free – no stupidity with license restrictions.
- Free lifetime access
- Multiple formats (ex. ePUB, PDF, Kindle, etc.)
- Free updates
- Sync with Dropbox and other similar services
… and more! All you do is enter “CYBER15” as the promotion code when checking out. The deal expires on Tuesday, December 1, 2015 at 05:00 US Pacific Time. Do note that this sale is for ebooks and not for the print versions of the books.
IPv6 deployment is accelerating – make sure that your applications and networks are ready for the IPv6 Internet!
P.S. My “Seven Deadliest Unified Communications Attacks” book is also on sale as an ebook at O’Reilly’s site… if you are interested in voice-over-IP (VoIP) security, please do check that book out, too.
Nov 26
On Thanksgiving, we’re thankful for our next panel
The post On Thanksgiving, we’re thankful for our next panel appeared first on FIR Podcast Network.
Nov 24
Only One Week Left to Submit Nominations for PIR Board of Directors (Closes Nov 30) (Featured Blog)
Nov 24
Giving Up On The iPad2
I finally gave up. After months of trying to continue to use my older iPad 2 with first iOS 8 and then iOS 9, as chronicled in several blog posts, I finally gave in and bought a new iPad Air 2. These two blog posts, and the many comments left both on the posts and on social media, show I am clearly NOT alone in wanting to continue using my iPad 2:
- Will iOS 9 Make My iPad2 Usable Again? (June 2015)
- UPDATE: Will iOS 9 Make My iPad2 Usable Again? (Reports after the upgrade.) (September 2015)
What finally did it for me is that after the iOS 9 upgrade, I was no longer able to use a specific application that I use all the time.
To explain a bit more, I coach a competitive girls Junior Curling team that my daughter is a member of. As part of that, I've been using an app call "iCurlStats" to track the actions and statistics in curling games so that we can be able to go back over them afterward. When I tried to use it in a recent curling tournament (a "bonspiel") it kept crashing all the time... and at terrible moments when I'd entered half of an "end" of a curling game.
It was so frustrating.
And unfortunately I discovered that the makers of that "iCurlStats" app seem to have gone out of business. The app is gone from the AppStore and the developer's website is completely gone. (In the little bit of digging it looks like the company may have been acquired by another company who then shut down different parts of the acquired company.)
So the chances of me getting an updated version of the app from the developer that would still work with an iPad 2 running iOS 9 were basically non-existent.
So I gave up. I gave in to the "planned obsolesence" and forked over more money to Apple for a iPad Air 2. This is the latest iPad in this size and so one would hope that Apple will keep it around for a while. Because I have come to heavily use a number of apps that are only on iOS, I'm right now locked into Apple's shiny, pretty walled garden. And I'm reluctantly okay with that because the apps are useful and help me get things done.
But I will also now be VERY CAUTIOUS applying future iOS updates to this iPad.
Had I not "updated" the iPad 2 to iOS 8 and left it running iOS 7 it probably would still be quite workable. (At least until I was forced to upgrade to newer apps that only ran on iOS 9 or later.) Now the iPad 2 will become something I use for an extra web browser screen or for some of the music apps... at least while all of those continue to work.
So that's the end of the saga.
No more glacial slowness for me - the iPad Air 2 is a remarkable and fast tablet. I can chart my curling games extremely easily and it works great for all the other apps I use, too.
Hopefully I can get a good run of years out of this one.
An audio commentary on this topic is also available:
P.S. There's another part to the story, too. After getting all set up on the iPad Air 2 and having iCurlStats work great - and getting all set up for the curling bonspiel all this past weekend... I decided that I wasn't comfortable with using an app that was no longer supported at all. In my research I had stumbled upon Curl Coach, a newer iPad app for curling coaches, and wound up using it for this past weekend's bonspiel. It is an amazing application! It's not cheap ($40 USD), but it's well worth it for how well it helped me work with our team! I don't know if this would have run on the iPad 2 (removing the need to buy the iPad Air 2), but I'm sure it wouldn't have run as fast as it did... and that is key when you're in the midst of recording a game.
Nov 24
TDYR 275 – Finally Giving Up On The iPad 2
Nov 23
For Immediate Release #10: Responding to terror with cats
Welcome to episode #10 of For Immediate Release. This week’s panel includes Philippe Borremans, an independent communications consultant from Brussels and host of the PR-focused podcast, Wag the Dog; Glenn Gaudet, founder and president of GaggleAMP and host of the podcast, AMP Up Your Social Media; and Donna Papacosta, principal of Trafalgar Communications and co-author of the book, The Business of Podcasting: How to Take Your Podcasting Passion from the Personal to the Professional.
In this episode, we covered these topics:
- A follow-up to last week’s discussion of social media and the Paris terrorist attacks, including the Belgian response to a request — and the hashtag #BrusselsLockdown — to avoid sharing pictures of official activity on the streets of Brussels by sharing cat pictures instead; a hashtag that gained traction in Toronto letting worried Muslims that #IllRideWithYou; the use of social media to spread hoaxes, and disinformation. Philippe also discussed his work with the Emergency 2.0 wiki.
- Google+ has redesigned to load faster and emphasize common interests via Communities and Collections. Is it still a worthwhile investment of time for brands?
- If engagement is the new metric, how important is it for employees to serve as brand ambassadors in their social networks?
- Listener comments on the terrorist attacks, Millennial’s desire for training from their employers, and teens struggling to differentiate Google ads from organic results.
- Dan York’s report on Google+, his search for a WordPress plugin, Google’s streaming of apps, and app indexing for search
- Podcast advertising as the next big thing for marketers
- A new trend of companies targeting journalists with paid Facebook ads
- Insights from the Belgian PR Summit
- Instagram captions becoming a new tool for blogging
- A new New York Times feature that lets readers “Follow This Story,” opting in to email updates on a given story
Connect with this week’s panelists at @DonnaPapacosta, @GlennG, and @HoratioNelson.
Links to the source material for this episode are on Delicious.
Special thanks to Jay Moonah for the opening and closing music.
Join us next week for our 11th episode. Joining me are three panelists named Chris: Chris Brogan, CEO of Media Group and bestselling author of Trust Agents, among other books; Chris Christensen, host of the Amateur Traveler podcast and CEO of BloggerBridge; and Christine Perkett, CEO of PerkettPR and SeeDepth.
About this week’s panel
Philippe Borremans is a multi-lingual corporate communications professional with more than 20 years experience in both internal and external communications, crisis communications, online reputation management and media relations. His career started at Porter Novelli in Brussels and continued at IBM for about 10 years. Both functions gave him extensive experience in European Media Relations and Public Relations. A specialist in press relations, issues management and communication campaigns, he is currently an independent communications consultant. Every week beginning in January 2015, Philippe interviews thought leaders and curates PR news on his podcast show, Wag the Dog.
Glenn Gaudet founded and leads GaggleAMP, which helps companies get the most out of their social media efforts with solutions that help amplify and analyze their efforts. He also wrote the book, “Connection, Community & Conversation: Making Social Media Work for Business.” Glenn is passionate about sharing business growth insights with our clients and prospects. One of the ways I do this is through a weekly podcast called AMP Up Your Social Media. He also advise startups on how to bring their products to market, bootstrapping and increasing market influence.
Donna Papacosta is a writer, speaker, podcaster and consultant, operating Trafalgar Communications in Toronto. In addition to leading workshops on social media and communications topics, Donna teaches Digital Communications Strategy and Social Media at the University of Toronto School of Continuing Studies. In 2005 Donna launched Trafcom News, one of the first business podcasts in Canada. Since then she has expanded her expertise in both social media and multimedia, and helps people integrate these tools into their communications. She is the co-author, with Steve Lubetkin, of the recently launched book, The Business of Podcasting, and the author of The Podcast Scripting Book. A dual U.S.-Canadian citizen, Donna holds a Masters degree in Public Administration from New York University and a Certificate in Magazine Journalism from Ryerson University.
The post FIR #10: Responding to terror with cats appeared first on FIR Podcast Network.

)