Babak Farrokhi :dns:'s Avatar

Babak Farrokhi :dns:

@farrokhi.unix.family.ap.brid.gy

Internet Plumber - Doing DNS for fun and (non)profit. #BGP, #DNS, #C, #Golang, #SRE, #FreeBSD, #Unix, #Linux #内向 Medicore at all of the above, but gets the job done πŸŒ‰ bridged from ⁂ https://unix.family/@farrokhi, follow @ap.brid.gy to interact

14 Followers  |  1 Following  |  60 Posts  |  Joined: 04.12.2024  |  2.0682

Latest posts by farrokhi.unix.family.ap.brid.gy on Bluesky

Daily Archives ## Sam Cheadle - E.2. Identification and abuse characteristics of batch registered gTLD domains Your browser does not support the <video> tag Download Video __ Presenter Name| Presentation Title| __| Date Added ---|---|---|--- Sam Cheadle| E.2. Identification and abuse characteristics of batch registered gTLD domains| ____| 2025-05-13

@jtk A semi-related research to this subject: https://ripe90.ripe.net/archives/video/1596/

15.10.2025 17:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
A blue aircraft preparing to board passengers

A blue aircraft preparing to board passengers

Returning home (πŸ‡ΈπŸ‡ͺ β†’ πŸ‡³πŸ‡±) after DNS-OARC 45 and the Netnod Tech Meeting with two more conference badges and t-shirts, wonderful memories, and stronger friendships.

Grateful for everyone’s friendship, knowledge sharing, and openness. Until next time!
#oarc45 #lovedns

10.10.2025 12:11 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Original post on unix.family

DNSDiag 2.8.1 is now available with DNS Cookie support, EDNS Client Subnet testing, automatic Extended DNS Error display, and DNS over QUIC/HTTP3 tracing.
This was also the perfect opportunity to fix the known bugs and make some quality of life improvements […]

04.10.2025 19:47 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

@jtk interesting choice of name. I wonder why such confusing names are chosen.

26.09.2025 02:53 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Preview
DNS-OARC (@dnsoarc@mastodns.net) Attached: 1 image Join the conversation at #OARC45! Table Topics will run during the last 30 minutes of lunch (13:45 – 14:15 CEST) on both workshop days. Small-group discussionsβ€”covering DNS operations, security, and community topicsβ€”will be clearly marked with table signs. Find a topic that interests you and pull up a chair! More information can be found on our event site https://bit.ly/4nG1bCW #LoveDNS #TableTopics ^RP

Heading to OARC in a few weeks? Join one of the table topics! I’ll be moderating an ADoT/ADoQ Adoption discussion among several other interesting choices.
https://mastodns.net/@dnsoarc/115264999087793934
#DNS #lovedns

25.09.2025 17:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Running some experiments on public DNS resolvers to see how they handle ECS. Surprise: resolvers aren’t all created equal!
I will share my findings soon.

25.09.2025 10:34 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Release DNSDiag 2.7.0 Β· farrokhi/dnsdiag Changelog for DNSDiag 2.7.0 New Features DNS over HTTP/3 (DoH3) Support: Added support for RFC 9114 DNS over HTTP3 protocol using -3 or --doh3 option in dnsping Improved Error Handling: Enhanced e...

πŸš€ DNSDiag 2.7.0 is out!

βœ… Support for DNS over HTTP/3 (DoH3)
βœ… Improved support for DoQ
βœ… Improved DoQ & DoH3 error handling
βœ… Cleaner display of RTT, flags & EDE info

πŸ”— Release notes:
https://github.com/farrokhi/dnsdiag/releases/tag/v2.7.0

22.09.2025 09:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
OARC 45 OARC 45 will be a hybrid in-person and online workshop. The workshop will be held in Stockholm, Sweden DNS-OARC is a non-profit, membership organization that seeks to improve the security, stability, and understanding of the Internet's DNS infrastructure. Part of these aims are achieved through workshops. DNS-OARC Workshops are open to OARC members and to all other parties interested in DNS operations and research.This year, OARC 45 is part of a broader DNS Weekβ€”a full calendar of events...

DNS-OARC 45 in Stockholm is just a few weeks away! πŸ‡ΈπŸ‡ͺ

Looking forward to seeing many of you there β€” let’s catch up and hang out!

https://indico.dns-oarc.net/event/55/

#DNS #LoveDNS #oarc45

21.09.2025 19:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

What is the idea behind research papers not having a date stamp? Is it because publication date is irrelevant? Asking because I check for the date very often and it is usually not easy to find it anywhere.

05.09.2025 14:30 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Alibaba Cloud reveals uptime and efficiency secrets : eBPF, shared SmartNICs, and smart scheduling have improved reliability and cut costs

Alibaba Cloud reveals some details on how they use eBPF, shared SmartNICs, and smart scheduling to improved reliability and cut costs
https://www.theregister.com/2025/09/02/alibaba_cloud_reveals_its_uptime/

02.09.2025 05:33 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
GitHub CEO delivers stark message to developers: Embrace AI or get out. Thomas Dohmke wrote that humans are often resistant to change. He said that's okay, but these people should probably find another profession.

GitHub CEO says "Embrace AI or leave the profession", just a week before he left the profession?
https://www.businessinsider.com/github-ceo-developers-embrace-ai-or-get-out-2025-8?international=true&r=US&IR=T

18.08.2025 11:20 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Anil Dash (@anildash@me.dm) There could not be a more opportune time to make a competitor to GitHub, especially one grounded in community and accountability. Git was not meant to be centralized; β€œpull requests” are not actually an open standard and throwing code over the wall at others is not actually social coding.

Internet was built to be decentralized. Instead, we handed CDNs, DNS, Email, Search, Package Management, and Code Repos to a few giants. And turns out most people are fine with it. This isn’t an accident. It’s supply and demand.

https://me.dm/@anildash/115011879301970616

12.08.2025 12:23 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
An screenshot from a conversation with ChatGPT earlier today that shows ChatGPT itself has no idea about GPT-5 being released a day before.

An screenshot from a conversation with ChatGPT earlier today that shows ChatGPT itself has no idea about GPT-5 being released a day before.

Asked ChatGPT about GPT-5 earlier today, and this is what I've got:

08.08.2025 09:54 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Michael Tsai (@mjtsai@mastodon.social) uBlock Origin Lite for Safari https://mjtsai.com/blog/2025/08/06/ublock-origin-lite-for-safari/ #mjtsaiblog

One person almost single handedly is trying to make internet a better place.
https://mastodon.social/@mjtsai/114983397834787020

06.08.2025 20:43 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
An screenshot from broadcom support website that reads: Moving forward, updates will need to be manually downloaded from the Broadcom Support Portal.
Once the appropriate product update is downloaded, it can be manually installed.

An screenshot from broadcom support website that reads: Moving forward, updates will need to be manually downloaded from the Broadcom Support Portal. Once the appropriate product update is downloaded, it can be manually installed.

According to a broadcom support article (https://knowledge.broadcom.com/external/article?articleNumber=395172), this is how the "automatic" update works from now on:

23.07.2025 11:48 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on unix.family

If you were wondering why VMware Workstation/Fusion stopped automatic updates, you have to jump through many hoops to get the update (logging in to the portal, clicking on many links, accepting nonsense TOC, swearing, clicking on more things, etc.) - I have an answer for you, and the answer is […]

23.07.2025 11:45 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

@DNSresolver softwareupdate.broadcom.com

23.07.2025 11:38 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
We've Issued Our First IP Address Certificate Since Let’s Encrypt started issuing certificates in 2015, people have repeatedly requested the ability to get certificates for IP addresses, an option that only a few certificate authorities have offered. Until now, they’ve had to look elsewhere, because we haven’t provided that feature. Today, we’ve issued our first certificate for an IP address, as we announced we would in January. As with other new certificate features on our engineering roadmap, we’ll now start gradually rolling out this option to more and more of our subscribers.

Let’s Encrypt to issue short lived certificates for IP addresses later this year:
https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate/

03.07.2025 06:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Just registered for IETF 123 in Madrid. I will be participating remotely this time.

02.07.2025 08:32 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Why did MailMate switch to β€œFreeΒ Mode” today? FAQ about why MailMate has switched to its β€œFree Mode”.

Also this is why I decided to drop Mailmate: https://freron.com/2025/why-did-mailmate-switch-to-free-mode-today/

01.07.2025 20:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on unix.family

I decided to give `aerc` (https://aerc-mail.org) another try (as my secondary email client). It is not mature, especially in the Threading and custom key-binding department, but it gets the job done. And it feels fresh. I am going to give it a try for the next few weeks or months to see if it's […]

01.07.2025 20:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
Original post on unix.family

I use mu4e/emacs (https://www.djcbsoftware.nl/code/mu/mu4e.html) as my primary email client and Mailmate as my secondary, when I need a GUI client. However, I recently decided to drop Mailmate. It's a fantastic software, and I don't mind paying for the recently introduced subscription model […]

01.07.2025 20:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0
drag paul's run race (@hazel@godforsaken.website) LLMs are responsible for a lot of sins but let us not forget the harm it has caused the em-dash enthusiast community, of whom i consider myself a fellow

I stopped using em-dash a while back when I realized it makes my writings look like LLM generated.
https://godforsaken.website/@hazel/114771774866635191

30.06.2025 22:01 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@jtk @dataplane yes to both! And thank you for doing the good work. Especially looking forward to seeing the Weekend Reads again.

30.06.2025 21:59 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Seems like ChatGPU is down. So people will write high quality code today.

10.06.2025 14:14 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@olaf @bortzmeyer Fantastic. Thanks for sharing!

01.06.2025 19:19 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Original post on unix.family

Pocket was the last reason I needed to drop Firefox. I never liked the forceful nature of its presence in Firefox. Mozilla re-enabled it with every single update, like they did with their Telemetry.
Well, they got rid of it anyway, but it will not help with building trust with their remaining […]

01.06.2025 12:27 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Jason Lefkowitz (@jalefkowit@vmst.io) β€œStop trying to fix the user. It’s not the user’s fault if they click on a link and it infects their system. It’s not their fault if they plug in a strange USB drive or ignore a warning message that they can’t understand. It’s not even their fault if they get fooled by a look-alike bank website and lose their money. The problem is that we’ve designed these systems to be so insecure that regular, nontechnical people can’t use them with confidence. We’re using security awareness campaigns to cover up bad system design.” https://www.schneier.com/blog/archives/2025/05/why-take9-wont-improve-cybersecurity.html

This is why Engineers should not be Designers too. Let’s keep these roles separate.

https://vmst.io/@jalefkowit/114597177875431505

31.05.2025 08:17 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

People are usually very surprised when I tell them how much of the world runs on Linux kernel, cURL and tmux.

31.05.2025 08:15 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
[$] System-wide encrypted DNS The increasing sophistication of attackers has organizations realizing that perimeter-based security models are inadequate. Many are planning to transition their internal networks to a zero-trust architecture. This requires every communication on the network to be encrypted, authenticated, and authorized. This can be achieved in applications and services by using modern communication protocols. However, the world still depends on Domain Name System (DNS) services where encryption, while possible, is far from being the industry standard. To address this we, as part of a working group at Red Hat, worked on fully integrating encrypted DNS for Linux systemsβ€”not only while the system is running but also during the installation and boot process, including support for a custom certificate chain in the initial ramdisk. This integration is now available in CentOS Stream 9, 10, and the upcoming Fedora 43 release.

Encrypted DNS (well, DoT) as part of RHEL and Fedora. They chose #Unbound as the layer between stub and upstream resolver to encrypt DNS traffic, including very early stages of boot as well as initial installation.

https://lwn.net/Articles/1021357/

29.05.2025 21:29 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

@farrokhi.unix.family.ap.brid.gy is following 1 prominent accounts