Aussehen
Suche Einloggen
[c] [meta] [fefe] [erp]

8390 Ergebnisse

[0] [1] [2] [3] [4] [5] [6] [7] [8] [9] ... [419]
  • [l] Felix Thu, 10 Sep 2026 22:51:07 GMT Nr. 164980
    JPG 600×600 90.8k
    JPG 1079×974 317.6k
    >>164977
    Das Hauptproblem ist, wie Felix nun gerade mit Erschrecken feststellen musste, dass es nicht auf Port 53 laufen darf. Wobei es ohnehin TCP und nicht UDP ist.

    >...unless it has mutual agreement with its server to use a port other than port 853 for DNS over TLS. Such another port MUST NOT be port 53
    >This recommendation against use of port 53 for DNS over TLS is to avoid complication in selecting use or non-use of TLS and to reduce risk of downgrade attacks.
    >The first data exchange on this TCP connection MUST be the client and server initiating a TLS handshake using the procedure described in [RFC5246].
    >There are significant security issues in mixing protected and unprotected data, and for this reason, TCP connections on a port designated by a given server for DNS over TLS are reserved purely for encrypted communications.
    Das mit dem "ihr dürft Port 53 nicht verwenden" ist sehr unsinnig. Anstatt das Sinnvolle zu machen und zu sagen: Wenn ihr DoT auf einem Port anbietet, dürft ihr darauf nichts anderes anbieten (was eigentlich fickend immer so ist).

    Beim "mixing protected and unprotected data" muss man bedenken, dass DNS auf _UDP_ läuft, DoT hingegen auf _TCP_. Da muss schon eine Menge schiefgehen, wenn man annimmt, dass plötzlich die ungeschützten Daten statt auf einen UDP-Port nun an einen TCP-Port gehen. Aber Felix hat es mal weiter gesponnen.

    Felix hat mit der DNS- und DoT-Paketstruktur rumgespielt, und ein _gutartiges_ DNS-Paket könnte ein Client Hello bis Byte 5 replizieren, wird aber dann immer spätestens bei Byte 8 abgelehnt. Ein _bösartiges_ DNS-Paket kann natürlich identisch wie ein DoT-Paket aussehen. Sowieso klar: Der DoT-Servierer muss eben ordentlich, auch gegen bösartige Anfragen, implementiert sein (auch z.B. getestet via Fuzzing).

    Aber Felix versteht dann doppelt nicht, warum "da können aber auch DNS-Pakete reinkommen" da noch irgendwie relevant sein sollte. Es gibt hierbei schlicht keine "security issues in mixing protected and unprotected data", und auch keine "downgrade attacks", die über TLS hinausgehen (wie die dort auch in Abschnitt 8 schreiben), und die man mit einem schlichten "Downgrade auf unter TLS 1.2 verboten" (und erst recht "Downgrade auf DNS verboten" und "Umbiegen von TCP auf UDP verboten") nicht beheben könnte. Man trägt ja gerade einen DoT-Servierer bei sich ein, weil man weiß, dass der DoT kann. Auf dem Port 53 wird dann schlicht _nur_ DoT angeboten und nie etwas runtergradiert.

    Warum steht das überhaupt was von "downgrade"? Mal in die Evolution vom Standard schauen:
    >7. Design Evolution
    >Earlier draft versions of this document proposed an upgrade-based approach to establish a TLS session. The client would signal its interest in TLS by setting a "TLS OK" bit in the Extensions Mechanisms for DNS (EDNS(0)) flags field. A server would signal its acceptance by responding with the TLS OK bit set.
    >Since we assume the client doesn't want to reveal (leak) any information prior to securing the channel, we proposed the use of a "dummy query" that clients could send for this purpose. The proposed query name was STARTTLS, query type TXT, and query class CH.
    >The TLS OK signaling approach has both advantages and disadvantages. One important advantage is that clients and servers could negotiate TLS. If the server is too busy, or doesn't want to provide TLS service to a particular client, it can respond negatively to the TLS probe. An ancillary benefit is that servers could collect information on adoption of DNS over TLS (via the TLS OK bit in queries) before implementation and deployment. Another anticipated advantage is the expectation that DNS over TLS would work over port 53. That is, no need to "waste" another port and deploy new firewall rules on middleboxes.
    >However, at the same time, there was uncertainty whether or not middleboxes would pass the TLS OK bit, given that the EDNS0 flags field has been unchanged for many years. Another disadvantage is that the TLS OK bit may make downgrade attacks easy and indistinguishable from broken middleboxes. From a performance standpoint, the upgrade-based approach had the disadvantage of requiring 1xRTT additional latency for the dummy query.
    >Following this proposal, DNS over DTLS was proposed separately. DNS over DTLS claimed it could work over port 53, but only because a non-DTLS server interprets a DNS-over-DTLS query as a response. That is, the non-DTLS server observes the QR flag set to 1. While this technically works, it seems unfortunate and perhaps even undesirable. DNS over both TLS and DTLS can benefit from a single well-known port and avoid extra latency and misinterpreted queries as responses.
    Joooooooo es war also eine alte Version vom Standard, in der man upgraden/downgraden konnte. Und das Verbot an anderer Stelle im Standard, DoT nicht auf Port 53 anzubieten, ist dann einfach drin geblieben, obwohl der Grund weggefallen ist.

    Aber hey, die erwähnten DNS over DTLS, das benutzt UDP! Sehr gut, das gefällt Felix direkt noch besser, und auch noch weniger Bloat! Schauen wir doch dort mal rein...
    >Such another port MUST NOT be port 53
    https://datatracker.ietf.org/doc/html/rfc8094#section-3.1

    Verfickt nochmal! Die habens einfach rüberkopiert! Kein Wunder, dass dieser Kack nirgends Anschluss findet, weil die am Leben vorbeirennen.
  • [l] Felix Thu, 10 Sep 2026 22:04:01 GMT Nr. 164978 SÄGE
    OGG 4:13 2.8M
    >und meine Stimme die eines freedesktop/gnome Entwicklers ist
  • [l] Felix Thu, 10 Sep 2026 21:48:22 GMT Nr. 164977
    JPG 1920×1080 224.0k
    >>164976
    <https://datatracker.ietf.org/doc/html/rfc7858#section-3.1
    >In order to use a port other than 853, both clients and servers would need a configuration option in their software.
    Use case?

    <https://datatracker.ietf.org/doc/html/rfc8484#section-8.1
    >Additionally, the use of the HTTPS default port 443 and the ability to mix DoH traffic with other HTTPS traffic on the same connection can deter unprivileged on-path devices from interfering with DNS operations and make DNS traffic analysis more difficult.
    Gut.

    >Felix präferiert DoT
    DoH hat den besseren default port, DoT mag schlanker sein. Im Endeffekt brauchen wir eine neue RFC die beides vereint ohne den Bloat.

    (Stell dir beim Lesen meines Beitrages vor, dass ich ca. 96 kg wiege, Redo of a Healer mein Lieblingsanime ist, und meine Stimme die eines freedesktop/gnome Entwicklers ist. Es hilft mit der Immersion.)
  • [l] Felix Thu, 10 Sep 2026 18:40:22 GMT Nr. 164975
    >>164974
    DNSSEC bietet nur Authentizität. DoH is E2EE, und kann auch DNSSEC bieten. Mir ist beides egal, wenn ich einen recursive resolver daheim Betreibe. DNS-Zensur ist wahrscheinlich das wahre problem, wenn man einen Dienstleister nutzt.

    >https://quad9.net/news/press/quad9-faces-new-dns-censorship-legal-challenge-in-france-from-canal/
    <https://quad9.net/news/blog/italian-blocking-demands-following-a-bad-example/

    Scheiß Lizenzen auf Sport und Co.
  • [l] Felix Thu, 10 Sep 2026 18:00:42 GMT Nr. 164974
    Felixens normale DNS-Anfragen bieten genau die gleiche Privatsphäre wie Post-Quantum-DNSSEC-Anfragen.
  • [l] 1.1.1.1 now supports post-quantum DNSSEC Felix Thu, 10 Sep 2026 14:29:45 GMT Nr. 164973
    PNG 432×289 81.9k
    PNG 523×476 418.0k
    PNG 408×728 436.1k
    https://blog.cloudflare.com/post-quantum-dnssec-1111/

    >All 2,420 bytes of it
  • [l] Felix Thu, 10 Sep 2026 11:55:37 GMT Nr. 164972
    WEBM 1920×1080 0:04 1.9M
    >>164970
    video relatiert

    >>164971
    https://dynv6.com/docs/apis
    https://dynv6.github.io/api-spec/
  • [l] Felix Thu, 10 Sep 2026 09:53:24 GMT Nr. 164970
    >>164968
    sic transit gloria mundi
  • [l] Felix Thu, 10 Sep 2026 09:52:10 GMT Nr. 164969
    Sofortige Notarschdehnung mit Analairbag!
  • [l] Felix Thu, 10 Sep 2026 06:51:26 GMT Nr. 164967
    JPG 1080×1443 346.0k
    >>164966
    Aber bitte denke dabei nicht, dass ich bigott bin, ich bringe alle Rassen gleichberechtigt um!
  • [l] Felix Thu, 10 Sep 2026 06:38:54 GMT Nr. 164966
    >>164965
    Darf ich trotzdem deine Petition unterschreiben, dass weinerliche Parlamentarier gewalttätige Videospiele spielen müssen?
  • [l] Felix Wed, 09 Sep 2026 20:53:33 GMT Nr. 164965
    JPG 642×580 70.9k
    Ach, Portal.. ich hatte Postal gelesen und mich schon auf ein schönes Postal-Video gefreut... :(
  • [l] Felix Wed, 09 Sep 2026 16:09:23 GMT Nr. 164964
    >>164961
    >Denn Excel 2.0 hatte seine eigens hergestellte Excel Windows Runtime dabei, und brauchte daher nur DOS.
    Das hatte Felix als Besitzer von Windows 2.0 in der Tat verdrängt. Herzlichen Dank für die Aufklärung! <3
    >C Programmierer.PNG
    Felix nimmt dann doch lieber den Apfelkuchen.
  • [l] Felix Wed, 09 Sep 2026 14:29:19 GMT Nr. 164963 SÄGE
    Bonus:
    Der Rust WASM-bindgen Krebs und alle Scripte.
  • [l] Felix Wed, 09 Sep 2026 14:18:22 GMT Nr. 164962
    PNG 595×671 33.5k
    PNG 570×616 47.0k
    >>164727
    >Mit (venünftigerweise) ausgeschaltetem JavaScript gabs ein simples HTML+Bild-Captcha.
    Test:
    https://xcancel.com/antibot/captcha?redirect=%2Felonmusk

    Grenzt etwas an Misshandlung
  • [l] Felix Wed, 09 Sep 2026 10:56:50 GMT Nr. 164961
    PNG 900×706 592.2k
    >>164959
    >Es gab nie Excel für DOS.
    Achtung: Autismus über Systemgrenzen.

    Da Felix das Excel 2.0 im Bildschirmschuss selbst installiert hat: Es gab Excel 2.0 sehr wohl für DOS. Denn Excel 2.0 hatte seine eigens hergestellte Excel Windows Runtime dabei, und brauchte daher nur DOS. Es war Implementierungsdetail von Excel.

    >>164960
    >Und außerdem benötigt diese Windows-Version mindestens DOS 3
    Beachte die geheime Bildnummerierung:
    >Excel 2.0 DOS 1.png
    >Excel 2.0 DOS 2.png
  • [l] Felix Wed, 09 Sep 2026 08:24:20 GMT Nr. 164960 SÄGE
    JPG 320×280 39.7k
    >>164959
    Und außerdem benötigt diese Windows-Version mindestens DOS 3(.0, 3.1 ab Windows 3.0).
    Felix hat sich neulich eine 86Box mit einem emulierten PC/AT-System mit EGA-Grafik aufgesetzt – beim Anblick der gegenüber VGA vertikal gestauchten (aber auf einem 4:3-Röhrenbildschirm entzerrten) System-Schriftart hatte er autistische Erinnerungen an Screenshots in einem Excel-3.0-Buch, das er mangels besserer Lektüre als Kind gelesen hatte.


[0] [1] [2] [3] [4] [5] [6] [7] [8] [9] ... [419]
[c] [meta] [fefe] [erp]