en.osm.town is one of the many independent Mastodon servers you can use to participate in the fediverse.
An independent, community of OpenStreetMap people on the Fediverse/Mastodon. Funding graciously provided by the OpenStreetMap Foundation.

Server stats:

259
active users

#rpki

1 post1 participant0 posts today

When #FlaxTyphoon reports emerged, we examined whether its activity was detectable within AIDE, GCA’s #cybersecurity intelligence platform that monitors global network traffic, detects potential threats, and delivers actionable insights to improve network security.

Our analysis revealed behavioral signals and infrastructure overlaps consistent with Flax Typhoon’s tactics—including VPN tunneling, web shell traffic, and credential-based reconnaissance—across sensors located in Taiwan, the United States, Europe, and East Asia.

Key action items for every network operator to take to reduce risk and strengthen network integrity:

👁️ Monitor for unauthorized access attempts and abnormal service behavior.

💪 Strengthen routing security by implementing Mutually Agreed Norms for Routing Security (MANRS) best practices and validating route origins with #RPKI.

🤝 Join collaborative intelligence efforts like AIDE, where shared visibility enables shared defense—and actionable data drives real-world mitigation.

Read more in Meghal Donde's insightful and data-packed post: globalcyberalliance.org/flax-t

Did you know chrony, the #NTP implementation, sets up an administrative listener on the loopback interface using UDP/323 by default?

Unfortunately in the #RPKI rpki-rtr has TCP/323 registered with IANA (see IETF RFC 6810). UDP/323 is reserved. Reserving a transport that is unused by the assigned application is common practice these days.

chrony's choice can probably be chalked up to a historical accident since it came first and presumably picked 323 because it "looked" like 123 and was then unassigned.

Chrony should probably change their default imo, but maybe it's too late or not worth it now?

We are pleased to announce the latest release of Routinator, version 0.14.2 ‘Roll Initiative!’ This of our #RPKI validator fixes an issue in the bundled UI that caused it to retrieve data from our own test instance rather than the actual Routinator instance. Users of the bundled UI should upgrade. github.com/NLnetLabs/routinato

GitHubRelease 0.14.2 ’Roll Initiative!’ · NLnetLabs/routinatorThis release fixes an issue in the bundled UI that caused it to retrieve data from our own test instance rather than the actual Routinator instance. Users of the bundled UI should upgrade. Other ch...

We just released Routinator 0.14.1, fixing CVE-2025-0638, where non-ASCII characters in the file names listed in an #RPKI manifest lead to a crash of Routinator:
nlnetlabs.nl/downloads/routina

You should also be aware of CVE-2024-12084, fixing a heap-based buffer overflow flaw was found in the rsync daemon:
nvd.nist.gov/vuln/detail/cve-2

Please make sure you update both Routinator and rsync. Lastly, because gzip is re-enabled, you’ll save up to 50% bandwidth.

nlnetlabs.nl/news/2025/Jan/22/

“… require contracted providers of Internet services to agencies to adopt and deploy Internet routing security technologies, including publishing Route Origin Authorizations and performing Route Origin Validation filtering."

In light of this Executive Order; if you need #RPKI solutions that are continually developed, have a proven track record, are trusted by the world’s largest operators and are supported with a service-level agreement, we're here for you. #OpenSource

whitehouse.gov/briefing-room/p

The White House · Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity | The White HouseBy the authority vested in me as President by the Constitution and the laws of the United States of America, including the International Emergency

Whoof, this "Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity" is a lot of words:

whitehouse.gov/briefing-room/p

Notable:

"Within 120 days, publish #RPKI Route Origin Authorizations..."

"Within 180 days, enable encrypted DNS protocols..."

"Agencies shall implement PQC key establishment or hybrid key establishment including a PQC algorithm as soon as practicable..."

"Within 270 days, establish a program to use advanced AI models for cyber defense."

The White House · Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity | The White HouseBy the authority vested in me as President by the Constitution and the laws of the United States of America, including the International Emergency

Is it #MutualAid if I offer #jobs to #USA friends who want to emigrate right now?! Or am I profiting from other peoples suffering? If you *do* want to get #FediHired , check out these #job openings in #Amsterdam / Holland : currently 7 positions , but try open solicitation too . Mention me as a reference for bonus points ;) #trainer #software #engineer #security #embedded #legal #hybrid #RPKI #BGP #RIPE #Atlas #ipv6 #ipv4 #DNS Please share with your #American friends! ripe.net/jobs

RIPE Network Coordination CenterCareers at the RIPE NCCCareer opportunities at the RIPE NCC and employee benefits.