John Kristoff's Avatar

John Kristoff

@jtk.infosec.exchange.ap.brid.gy

UIC PhD candidate | https://Dataplane.org | Netscout. Internet infrastructure (#BGP, #DNS) and #infosec. Bit mechanic. Also: #Blues / tfr / #fedi22 ๐ŸŒ‰ bridged from https://infosec.exchange/@jtk on the fediverse by https://fed.brid.gy/

32 Followers  |  11 Following  |  258 Posts  |  Joined: 11.11.2024  |  1.9184

Latest posts by jtk.infosec.exchange.ap.brid.gy on Bluesky

Screen capture from a web site that claims to tell you what your IP address is.  For the IPv4 address it shows an IPv6 address, partially redacted.  For the IPv6 address it says Unable to detect IPv6.

Screen capture from a web site that claims to tell you what your IP address is. For the IPv4 address it shows an IPv6 address, partially redacted. For the IPv6 address it says Unable to detect IPv6.

#IPv6 bizarro world, courtesy of whmyip [dot] com. Just me or IPv6=IPv4 for everyone.

04.08.2025 14:36 โ€” ๐Ÿ‘ 1    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Spoonful by The San Pedro Allstars, Reed Turchi, Austin White, Marlon Patton & Eric Burns Listen now on your favorite streaming service. Powered by Songlink/Odesli, an on-demand, customizable smart link service to help you share songs, albums, podcasts and more.

Monday jam: The San Pedro Allstars | Spoonful | https://song.link/us/i/1770056235 #blues

04.08.2025 13:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

In the extended version of @dataplane's The Internet Last Week, we spotted this this #GitHub incident: https://www.githubstatus.com/incidents/s6d4x8c6cvv5

"We are actively setting up additional rate limiting to address increased requests from scraping [...]"

#AI crawlers are not explicitly [โ€ฆ]

04.08.2025 11:53 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on dial.modem.show

Made a high level, basic "get your #IPv6 address plan started" app and posted to github. It's somewhat complimentary to ipv6utils (also on GitHub and Mac homebrew). It is pretty basic, more of a bootstrap than anything - because the first step is usually the hardest [โ€ฆ]

03.08.2025 22:14 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Video thumbnail

In case this week's news was too upbeat for you, radioactive wasps now. https://orpspublic.doe.gov/orps/reports/displayReport2.asp?crypt=%87%C3%95%9Ba%8Evjtc%90

02.08.2025 10:52 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

Spent a 30 minutes to discover #Python's csv module, which I've used often for years, defaults to CRLF on output regardless of what the source file's line endings are and what your local environment is.

I was converting a TSV to CSV and puzzling over why the resulting file was larger.

I will [โ€ฆ]

02.08.2025 10:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

16550. 4GL. A6. AAL5. ATH0. BITNET. CLNS. dBASE. DTE/DCE. ismap. LATA. PL/C. QEMM. Telenet. VLSM. WAIS. wuarchive. Zmodem...

So much dead, forgotten, and abandoned tech terms taking up limited brain space. Just dusting a few into the fedisphere.

01.08.2025 22:21 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

ReliableSite #hosting provider (#AS23470):

"Effective August 10th, 2025, the loyalty rewards points program will discontinued. Any unused points not utilized by August 10th, 2025 will be forfeited."

A new, as of yet unspecified, program will replace it.

01.08.2025 20:00 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Web sites I'm unable to visit today:

* Center for Democracy & Technology
* CircleID
* Lawfare (partial, e.g., /topics, /podcasts)
* NANOG (!@!? - this one is personal)

Presumably a #Cloudflare update with human verification code that donesn't work on my browser or a reclassification of my IP [โ€ฆ]

01.08.2025 19:42 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Weekend Reads

* URI redirection patterns https://arxiv.org/abs/2507.22019
* AI and college grad jobs https://www.wsj.com/lifestyle/careers/ai-entry-level-jobs-graduates-b224d624?st=vM9BGX
* Internet control in Russia [โ€ฆ]

01.08.2025 19:27 โ€” ๐Ÿ‘ 0    ๐Ÿ” 1    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

The device behind pack is a Pingtel SIP xpressa phone. They were in one sense ahead of their time and behind in another.

Ahead because it was a truly a purpose-built SIP hardware phone when SIP was still new. Alternatives were usually H.323 (or SKNY popularized by Cisco's early phones). Behind [โ€ฆ]

31.07.2025 16:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Botgov (@botgov@mastodon.social) The following .gov domains have been registered in the past 24 hours: athenstownshipmn.gov crypto.gov discovermoorpark.gov eatontownsewer.gov fayetteutah.gov hubbardcounty.gov kearneytownshipmi.gov maitlandfl.gov mattituckparks.gov pacificmo.gov townofchevychasemd.gov townofgilcrest.gov vanburencountyar.gov villageofrhinebeck.gov

crypto.gov has arrived
https://mastodon.social/@botgov/114948514901920888

31.07.2025 15:22 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@tomjennings Tom, are you aware of the new book "Other Networks: A Radical Technology Sourcebook" by @loriemerson? It is quite something I think you'd enjoy if you've not seen it.

31.07.2025 10:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 2    ๐Ÿ“Œ 0
Purple stuff rat sitting atop an old net chassis device, in the background is a rare ip phone. Specific product details in a follow up.

Purple stuff rat sitting atop an old net chassis device, in the background is a rare ip phone. Specific product details in a follow up.

This was "packet rat". +2 points to id what pack is sitting on, +10 if you know the specific phone device to the rear.

30.07.2025 21:28 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Preview
Clarifying โ€œAI Firstโ€ โ€“ What It Really Means for rsyslog **TL;DR:** The rsyslog project is embracing **AI First (Human-Controlled)** โ€” AI is becoming an integral partner across development, documentation, user education, technical support, deployment guidance, and future observability tools. This does **not** mean โ€œvibe codingโ€ or letting AI run unsupervised. Instead, AI accelerates routine work, drafts ideas, and provides insights, while **Rainer Gerhards โ€” with decades of battle-tested experience in IT, system logging, and software engineering โ€” and the team remain in full control of strategy, design, and quality.** AI is improving rapidly, and we foresee delegating larger tasks (even parts of code design) to AI over time โ€” but **always with humans setting direction and standards**. โ€œAI Firstโ€ reflects our strategy of embedding AI across the project, from code and docs to observability, always under human guidance and quality control. * * * ## **What โ€œAI Firstโ€ Really Means** The term **AI First** is often misunderstood. For rsyslog, it means: * **AI is a collaborative partner** , not an autonomous actor. * We leverage AI where itโ€™s strong (drafting documentation, proposing refactors, generating examples), but every deliverable is **reviewed, validated, and approved by experienced maintainers**. * We aim for **faster innovation and better results** without sacrificing the stability, security, or trustworthiness rsyslog is known for. * Over time, as AI tools improve, we expect to delegate **more complex design and development tasks** , but **humans will always control the overall direction and quality standards.** * * * ## **Our Five Pillars of AI-Driven Collaboration** 1. **Development & Design** AI assists with code exploration, initial drafts of refactorings, and generating alternative approaches. However, all **architecture, algorithms, and commits are decided by humans**. We firmly reject any idea of โ€œvibe codingโ€ or blindly accepting AI-generated solutions. 2. **Documentation & User Education** The rsyslog documentation had long lagged behind its technical sophistication โ€” something that, frankly, turned potential users away. With AI, weโ€™re now **rewriting and restructuring** content into something that is **partly OK today, but far from done**. We have a plan and will keep improving it through dedicated documentation sprints with the goal to make it really great. 3. **Technical Support & Community Interaction** AI is powering the **rsyslog Assistant** (https://rsyslog.ai), helping users find quick, mostly reliable answers drawn from curated documentation. Human maintainers shape and improve the assistantโ€™s knowledge to ensure accuracy. 4. **Deployment & Consulting Guidance** When assisting customers, we can โ€” if they agree โ€” **use AI to quickly identify best-fit configurations and solutions** , while **experienced humans remain in charge of reviewing and validating all outcomes**. 5. **Observability & Log Intelligence** Our future observability platform will include AI-assisted log analysis, anomaly detection, and insights. This is **not** about replacing humans but providing them with faster, more actionable information while keeping control and transparency. * * * ## **In Summary** **AI First (Human-Controlled)** is about **teamwork** between humans and AI. We believe AI will **rapidly improve** , allowing us to delegate **larger tasks (even aspects of design)** , but the **direction, decisions, and final quality control remain firmly in the hands of Rainer and the rsyslog team** โ€” professionals with decades of proven expertise in system logging and IT architecture. We see AI as a way to **unlock the next stage of rsyslogโ€™s evolution** : better docs, faster development, smarter observability, and more reliable support โ€” all while staying true to our core principles of stability, transparency, and trust.

rsyslog lead dev on AI, and also see this: https://www.rsyslog.com/clarifying-ai-first-what-it-really-means-for-rsyslog/
https://mastodon.social/@rainergrf/114932600848806448

28.07.2025 19:57 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

My first, and maybe most notable, contribution to Wikipedia was the creation of IBM] Token Ring page in October 2021. Some remnants of the original text surprisingly survive to this day: [https://en.wikipedia.org/w/index.php?title=IBM_Token_ring&oldid=351771239

For those who only ever heard [โ€ฆ]

28.07.2025 17:33 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Hadn't noticed until today, but earlier this year the original Cuckoo Sandbox's domain name (cuckoosandbox dot org), that is still linked from the GitHub repo, seems to have fallen under the control of a sports betting operation. The new domain name holder seems to have kept some semblance of [โ€ฆ]

28.07.2025 17:03 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Probably few noticed, but it looks like mirrors.cpan.org might have stopped serving web requests earlier this month. It was being phased out awhile ago AFAIK, but I'm sure there are plenty of dead links out there now.

Last wayback copy of the page is here [โ€ฆ]

27.07.2025 16:43 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Weekend Reads

* FreeBSD Journal https://freebsdfoundation.org/our-work/journal/browser-based-edition/networking-3/
* Anatomy of DDoSia https://www.recordedfuture.com/research/anatomy-of-ddosia
* Dataplane BGP hijack mitigation https://arxiv.org/abs/2507.14842
* Formal specifications for [โ€ฆ]

25.07.2025 12:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@pitrh We see this and a few other one character user names regularly. Current list can be found here: https://dataplane.org/signals/sshidpw.txt

23.07.2025 21:23 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on unix.family

If you were wondering why VMware Workstation/Fusion stopped automatic updates, you have to jump through many hoops to get the update (logging in to the portal, clicking on many links, accepting nonsense TOC, swearing, clicking on more things, etc.) - I have an answer for you, and the answer is [โ€ฆ]

23.07.2025 11:45 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Chevy Chase doing the Saturday Night Weekend Update with caption: This just in Interdomain IP multicast is still dead

Chevy Chase doing the Saturday Night Weekend Update with caption: This just in Interdomain IP multicast is still dead

23.07.2025 11:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

I'm at best a combat C programmer so this latest zmap fix may be perfectly reasonable.

https://github.com/zmap/zmap/pull/944

Is it common, and is it a best practice to not free memory allocated in some use cases? That may be two separation questions.

I have always freed memory allocated by [โ€ฆ]

22.07.2025 20:00 โ€” ๐Ÿ‘ 1    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Register for the You are invited to register for the webinar on

Upcoming #AFRINIC "Behind the Ballot: Navigating the AFRINIC Election Process" Webinar 2025-07-23 https://afrinic.net/election-2025-webinar-1

21.07.2025 21:11 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

I am considering going through my followers and following lists and removing anyone who has a twitter link in their bio.

I don't think this will remove many, and probably mostly just dormant accounts, but if this does impact you, sorry. I hope you will finally consider letting twiiter go.

21.07.2025 02:24 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Getting Started: Ark Integrated Active Measurement Programming Environment CAIDAโ€™s Archipelago (Ark) infrastructure provides a programming environment

CAIDA Ark now has an active measurement programming environment for qualified researchers. https://www.caida.org/projects/ark/programming/

19.07.2025 11:56 โ€” ๐Ÿ‘ 0    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0

@darkuncle Did you know about Microsoft's NCSI test? I think I first learned about it about 15-20 years ago when I was examining a pcap of a Windows bootstrapping.

It still kind of amazes me this hack exists and how little known it is.

19.07.2025 04:47 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0
Original post on infosec.exchange

Weekend Reads

* IPv6 adoption measurement https://arxiv.org/abs/2507.11678
* Starlink capacity analysis https://thexlab.org/wp-content/uploads/2025/07/Starlink_Analysis_Working_Paper_v0.2.pdf
* How subsea cables are made [โ€ฆ]

19.07.2025 04:21 โ€” ๐Ÿ‘ 2    ๐Ÿ” 2    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Preview
Kinetics and Mitsui O.S.K. Lines Sign MOU to Develop World's First Integrated Floating Data Center Platform | Mitsui O.S.K. Lines Introducing 'Kinetics and Mitsui O.S.K. Lines Sign MOU to Develop World's First Integrated Floating Data Center Platform' of Mitsui O.S.K. Lines (MOL)

Floating data center completion anticipated in 2027 with "p]lans to connect to IX (Internet Exchange) on land and submarine cables" [https://www.mol.co.jp/en/pr/2025/25061.html

19.07.2025 03:26 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 0    ๐Ÿ“Œ 0
Original post on infosec.exchange

Maybe I'm doing it wrong or missing the obvious, but am I the only one who thinks the way to read a fediverse timeline is in proper chronological time order (oldest to newest) like I can easily do in my email app?

Some apps have a context feature or implement threading, but by and large reading [โ€ฆ]

18.07.2025 22:58 โ€” ๐Ÿ‘ 0    ๐Ÿ” 0    ๐Ÿ’ฌ 1    ๐Ÿ“Œ 0

@jtk.infosec.exchange.ap.brid.gy is following 11 prominent accounts