helvede.net is one of the many independent Mastodon servers you can use to participate in the fediverse.
Velkommen til Helvede, fediversets hotteste instance! Vi er en queerfeministisk server, der shitposter i den 9. cirkel. Welcome to Hell, We’re a DK-based queerfeminist server. Read our server rules!

Server stats:

159
active users

#internetsecurity

0 posts0 participants0 posts today
Continued thread

now also available in English:
None of the biggest internet services are DNSSEC-enabled -- Breakthrough needed to increase actual usage levels
sidn.nl/en/news-and-blogs/none

Over the last two years, there has been considerable criticism of DNSSEC from within the DNS world itself. The main focuses of discontent have been the complexity of the protocol, poor market adoption and aging of the design.

SIDN - The company behind .nlNone of the biggest internet services are DNSSEC-enabled | Cybersecurity | SIDNFrom the DNS world, criticism of DNSSEC is sometimes heard. In this article, we discuss the most important points of criticism and show that DNSSEC can be used without problems in large-scale critical applications.

op SIDN.nl:
Geen van grootste internetdiensten beveiligd met DNSSEC -- Doorbraak nodig om daadwerkelijk gebruik omhoog te brengen
sidn.nl/nieuws-en-blogs/geen-v

DNSSEC is niet alleen belangrijk voor de beveiliging van het bestaande DNS-systeem, maar legt ook een fundament voor nieuwe en toekomstige beveiligingstechnologieën. Maar er is wel een doorbraak nodig om de grootste internetdienstenaanbieders naar DNSSEC over te laten schakelen.

Continued thread

also available in English:
DNS delegation is set for an update -- Proposed DELEG record type will modernise DNS(SEC)
sidn.nl/en/news-and-blogs/dns-

The new DELEG record is intended to replace the NS and glue records in the parent zone. It will also enable reference to an encrypted DNS service and specification of an alternative port number. Finally, it'll be possible to use a DELEG record as the starting point for a series of SVCB/CNAME references,

SIDN - The company behind .nlDNS delegation is set for an update | Cybersecurity | SIDNA new record type – the DELEG record – is therefore being developed to modernise the DNS delegation mechanism, which is now more than 40 years old.

op SIDN.nl:
Een moderniseringsslag voor de DNS-delegatie -- Nieuw DELEG-recordtype geeft DNS(SEC) belangrijke update
sidn.nl/nieuws-en-blogs/een-mo

Het nieuwe DELEG-recordtype moet het huidige delegatiemechanisme van DNS moderniseren. Om te beginnen vervangt het de NS- en glue-records in de parentzone. Daarnaast kan het naar een versleutelde DNS-dienst verwijzen..Ten slotte kan een DELEG-record ook het startpunt zijn van een reeks SVCB/CNAME-verwijzingen.

SIDN - Het bedrijf achter .nlEen moderniseringsslag voor de DNS-delegatie | Cybersecurity | SIDNHet nieuwe DELEG-recordtype – op dit moment nog volop in ontwikkeling – moet het huidige, ruim 40 jaar oude delegatiemechanisme van DNS moderniseren.

theregister.com/2024/11/20/dli

"Owners of certain D-Link VPN routers are being told to replace their devices following the disclosure of a serious remote code execution (RCE) vulnerability."

"Details are not being released given the potential for wide exploitation. The vendor hasn't assigned it a CVE identifier or said much about it other than that it's a buffer overflow that leads to unauthenticated RCE."

The Register · D-Link tells users to trash old VPN routers over bug too dangerous to identifyBy Connor Jones
Continued thread

now also available in English:
Latest version of Firefox adopts HTTPS as the norm -- General trend of migration to encrypted transport continues
sidn.nl/en/news-and-blogs/late

If you type www.example.nl into the navigation bar, Firefox begins by sending a request to 'example.nl/' (on server port 443). It'll try 'example.nl/' (on server port 80) only if the first request draws a blank. That's the reverse of the procedure followed until now.

SIDN - The company behind .nlLatest version of Firefox adopts HTTPS as the norm | Cybersecurity | SIDNVersion 129 of Firefox now tries the HTTPS protocol first to reach a website. With this change, TLS encrypted transport has become the default for Firefox users.

op SIDN.nl:
Algoritmen gebaseerd op verouderde SHA-1 cryptografie worden uit DNSSEC-standaard verwijderd -- Stap als het kan gelijk over naar algoritme nummer 13
sidn.nl/nieuws-en-blogs/algori

Het gebruik van algoritmen nummer 5 (RSA/SHA-1) en nummer 7 (RSASHA1-NSEC3-SHA1) werd al langer afgeraden. Inmiddels wordt gewerkt aan het helemaal uitfaseren van deze twee algoritmen.

We're deeply concerned about the abuse management and prevention policies of @cloudflare, a leading content delivery network. For years, cybercriminals have been exploiting Cloudflare's services to conceal their malicious activities, posing a significant threat to internet security.

As of today, Cloudflare is associated with 1201 unresolved Spamhaus Blocklist listings and accounts for 10.05% of all domains on the Spamhaus Domain Blocklist.

Read the full article to understand what we're seeing, the critical issues, and our recommendation for change 🔽
spamhaus.org/resource-hub/serv

In the meantime, we urge Cloudflare to review its anti-abuse policies and take meaningful action to protect the online community.

Please reach out to the team, we are more than willing to work together to resolve this issue.

Proton

@1jour1kif

Découvert au détour d'un reportage sur la chaîne ARTE consacré à la protection de la vie privée et étant, à l'époque à la recherche d'une alternative à Gmail ou Outlook, j'ai été tout de suite séduit par Proton.

Créé par les scientifiques du CERN à Genève, Proton propose outre la messagerie, un VPN, un stockage en ligne, un gestionnaire de mots de passe avec intégration de la gestion des authentifications à deux facteurs, calendrier et de nouvelles fonctions arrivent encore.

Il existe une version basique gratuite mais, pour ma part, j'ai opté pour une formule payante car j'estime que la sécurité et la protection de la vie privée valent bien quelques euros.

Autre grand avantage de Proton : les données sont stockées en Suisse et bénéficient des lois suisses de protection de la vie privée qui sont, à ce que j'ai lu, encore plus strictes que le RGPD.

Après plus d'un an d'utilisation des services, je reste convaincu que c'était un bon choix.

A few weeks ago I talked about classdojo.com, a site for schools/teachers that sent me a link to "my" account - it was for a child in England, not my child, their security sucks, this site is trash. I wrote to the school AND the website about it.

FYI, they're now sending me updates about "my" child. Photos, names, info, everything. Also? Kid's actual mom seems to also have an account now - I was alerted when she signed up!

DO NOT USE CLASSDOJO.COM

Anyone who can point me to a good guide for how to set up an Synology DS NAS?

Since the internet have upgraded I can't get the vpn connection to work on my ASUS router but my quickconnect.to find It's way to my nas from outside but everything that is available on the net MUST have good security standard. I would like to only connect to my network via OpenVPN or similare level security.

Any good tips are much welcome