[Newsclips] IETF SYN-ACK Newspack 2023-07-31

David Goldstein <david@goldsteinreport.com> Mon, 31 July 2023 06:20 UTC

Return-Path: <david@goldsteinreport.com>
X-Original-To: newsclips@ietfa.amsl.com
Delivered-To: newsclips@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 037F4C14EB19 for <newsclips@ietfa.amsl.com>; Sun, 30 Jul 2023 23:20:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.916
X-Spam-Level:
X-Spam-Status: No, score=0.916 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, GB_RUURL=3, HTML_MESSAGE=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, T_KAM_HTML_FONT_INVALID=0.01, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_TEMPERROR=0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=goldsteinreport.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oCtCL95SwZyk for <newsclips@ietfa.amsl.com>; Sun, 30 Jul 2023 23:20:45 -0700 (PDT)
Received: from mars.atomiclayer.com (mars.atomiclayer.com [66.85.142.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 14A3AC15171F for <newsclips@ietf.org>; Sun, 30 Jul 2023 23:20:44 -0700 (PDT)
Received: from David2019Desktop (unknown [144.136.5.199]) by mars.atomiclayer.com (Postfix) with ESMTPSA id 4734F2B6B8F for <newsclips@ietf.org>; Mon, 31 Jul 2023 02:20:43 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=goldsteinreport.com; s=default; t=1690784444; bh=7cgCd0BL4dhvMy8p5AlF19AsoY93ZlLJ4116tzBTwOw=; h=From:To:Subject; b=Ov/t6KdkxcJVQ23OPsijr7yhcqnZtyo1LR9ztHtydL5i3LhjHfvGlt80J4EOcXUBX 3qudxPoXQAvW28qLKB/MogprtnwP+l5SW/o84oD9IFTZmGXluY/3Lxl20k41OJmKB0 Vpfb/WEBOX61Lvwn2h0PPdprwsRzTPkfib5HdkKs=
Authentication-Results: mars.atomiclayer.com; spf=pass (sender IP is 144.136.5.199) smtp.mailfrom=david@goldsteinreport.com smtp.helo=David2019Desktop
Received-SPF: pass (mars.atomiclayer.com: connection is authenticated)
From: David Goldstein <david@goldsteinreport.com>
To: newsclips@ietf.org
Date: Mon, 31 Jul 2023 16:20:41 +1000
Message-ID: <016d01d9c377$230624b0$69126e10$@goldsteinreport.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_016E_01D9C3CA.F4B4CCC0"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AdnDdyFbPJAXBdOuQriGrS20ES8sYg==
Content-Language: en-au
X-PPP-Message-ID: <169078444415.3559407.15526558319653101959@mars.atomiclayer.com>
X-PPP-Vhost: goldsteinreport.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/newsclips/1jFoI18OXGGTIwNEQMBojRpFNLs>
Subject: [Newsclips] IETF SYN-ACK Newspack 2023-07-31
X-BeenThere: newsclips@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF News Clips <newsclips.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/newsclips>, <mailto:newsclips-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/newsclips/>
List-Post: <mailto:newsclips@ietf.org>
List-Help: <mailto:newsclips-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/newsclips>, <mailto:newsclips-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Jul 2023 06:20:52 -0000

The IETF SYN-ACK Newspack collects IETF-related items from a variety of news outlets and other online publications. They do not represent the views of the IETF and are not checked for factual accuracy.

 

**********************

IETF IN THE NEWS

**********************

fTLD Announces New Security Feature – PSD DMARC – Effective November 15, 2023

fTLD Registry Services’ (fTLD) domains, .BANK and .INSURANCE, will be the first non-governmental TLDs to implement Public Suffix Domain (PSD) DMARC (Domain-based Message Authentication, Reporting and Conformance). While fTLD domains in the .BANK and .INSURANCE zones have always been required to implement DMARC, this new security feature covers all .BANK and .INSURANCE domains when it is added. The availability of PSD DMARC follows a multi-year standards development process by the IETF that resulted in publication of RFC 9091.

< <https://www.register.insurance/july-7-2023/> https://www.register.insurance/july-7-2023/>

< <https://www.register.bank/july-7-2023/> https://www.register.bank/july-7-2023/>

 

ACE-OAuth – A new standard for lightweight authorization and access control

... This blog post is about a recent contribution to the area of Authentication and Authorization for Constrained Environments (ACE-OAuth) — or just ACE for short—a new security standard for lightweight authorization. ACE-OAuth is a framework and a set of protocols developed and standardized by the IETF with the goal to ensure that only authorized users and devices can access resources and protect against unauthorized access.

< <https://www.ericsson.com/en/blog/2023/7/ace-oauth-standard-for-lightweight-authorization> https://www.ericsson.com/en/blog/2023/7/ace-oauth-standard-for-lightweight-authorization>

 

Everything You Need to Know About POP

... POP was first created in the 1980s by the IETF to allow users to download email messages from a remote server to their local computer. The original version, POP1, was quickly superseded by POP2, which had more features and better security.

< <https://www.thetechedvocate.org/everything-you-need-to-know-about-pop/> https://www.thetechedvocate.org/everything-you-need-to-know-about-pop/>

 

Great expectations from AI, but a bleak house for cybersecurity

... One wonders which company might offer such a service? But he added: Standards are emerging that embrace an open and interoperable trust model that works for any data, anywhere including the C2PA provenance and authenticity metadata standard and IETF SCITT integrity, transparency and trust architecture.

< <https://diginomica.com/great-expectations-ai-bleak-house-cybersecurity> https://diginomica.com/great-expectations-ai-bleak-house-cybersecurity>

 

Android Foils AirTag Stalkers and Thieves — While Apple Does Nothing

... And what’s Apple doing? Sitting on their hands, waiting for the IETF. In today’s SB Blogwatch, we can’t wait until Tim’s crew get with the program.

< <https://securityboulevard.com/2023/07/android-airtag-warning-richixbw/> https://securityboulevard.com/2023/07/android-airtag-warning-richixbw/>

 

Google Messages Getting Cross-Platform End-to-End Encryption with MLS Protocol

... The development comes as the IETF released the core specification of the Messaging Layer Security (MLS) protocol as a Request for Comments (RFC 9420).

< <https://thehackernews.com/2023/07/google-messages-getting-cross-platform.html> https://thehackernews.com/2023/07/google-messages-getting-cross-platform.html>

 

Google Messages to feature MLS support for improved security

"MLS builds on the best lessons of the current generation of security protocols. Like the widely used Double Ratchet protocol, MLS allows for asynchronous operation and provides advanced security features such as post-compromise security. And, like TLS 1.3, MLS provides robust authentication," said the IETF.

< <https://www.scmagazine.com/brief/google-messages-to-feature-mls-support-for-improved-security> https://www.scmagazine.com/brief/google-messages-to-feature-mls-support-for-improved-security>

 

Google Messages to adopt Messaging Layer Security (MLS) protocol

... Messaging Layer Security (MLS) was a new protocol born in 2017. It provides end-to-end encryption for group messaging. MLS was developed by a group of security experts from various organizations, aka IETF. The protocol uses sophisticated cryptographic techniques to guarantee the confidentiality and security of messages. Additionally, it offers defense against intrusions such as message forging, manipulation, and eavesdropping.

< <https://www.androidheadlines.com/2023/07/google-messages-adopt-messaging-layer-security-mls-protocol.html> https://www.androidheadlines.com/2023/07/google-messages-adopt-messaging-layer-security-mls-protocol.html>

 

Google Messages could be getting cross platform end-to-end encryption

... If you’re not familiar with MLS, it’s a protocol developed by the IETF. The IETF recently approved the publication of MLS specification RFC 9420. Google states with the new specification, MLS now enables “practical interoperability across services and platforms, scaling to groups of thousands of multi-device users.”

< <https://www.inferse.com/637876/google-messages-could-be-getting-cross-platform-end-to-end-encryption/> https://www.inferse.com/637876/google-messages-could-be-getting-cross-platform-end-to-end-encryption/>

 

Google says a joint Bluetooth tracker misuse standard is waiting on Apple

... The specification was submitted as an Internet-Draft through the IETF, a standards development organization. The specification is open until August for review and comment from external parties.

< <https://appleinsider.com/articles/23/07/27/google-says-a-joint-bluetooth-tracker-misuse-standard-is-waiting-on-apple> https://appleinsider.com/articles/23/07/27/google-says-a-joint-bluetooth-tracker-misuse-standard-is-waiting-on-apple>

 

Your Android Phone Will Soon Be Able to Alert You to an Unknown AirTag

... At this time, unknown tracker alerts only work with AirTags. However, Google promises to work with other tag manufacturers to expand the protection to other tracking tags as these other companies get on board. In May, Google and Apple jointly submitted a proposed specification to the IETF, inviting companies such as Samsung, Tile, Chipolo, and others to also participate with their trackers.

< <https://www.idropnews.com/news/your-android-phone-will-soon-be-able-to-alert-you-to-an-unknown-airtag/197838/> https://www.idropnews.com/news/your-android-phone-will-soon-be-able-to-alert-you-to-an-unknown-airtag/197838/>

 

10 Jahre nach Snowden: Schlechteres Netz trotz mehr Vertraulichkeit?​ [10 years after Snowden: worse network despite more confidentiality?​]

Eine Dekade nach den Edward Snowdens Enthüllungen über die universelle Überwachung digitaler Kommunikation vor allem durch den US-Geheimdienst zieht die IETF eine Zwischenbilanz.

< <https://www.heise.de/news/10-Jahre-nach-Snowden-Schlechteres-Netz-trotz-mehr-Vertraulichkeit-9228856.html> https://www.heise.de/news/10-Jahre-nach-Snowden-Schlechteres-Netz-trotz-mehr-Vertraulichkeit-9228856.html>

 

Protocole MLS : Google Messages prépare les messages universels [MLS protocol: Google Messages prepares universal messages]

... Mais ce temps pourrait être bientôt révolu avec l'intégration d'une nouvelle norme. Google vient en effet d'annoncer sur son blog que son appli Messages utiliserait désormais le Messaging Layer Security (MLS), développé par l'Organisation IETF.

< <https://www.commentcamarche.net/applis-sites/messageries/28683-protocole-mls-google-messages-prepare-les-messages-universels/> https://www.commentcamarche.net/applis-sites/messageries/28683-protocole-mls-google-messages-prepare-les-messages-universels/>

 

Ouf, votre smartphone Android pourra enfin vous alerter si un AirTag vous espionne [Wow, your Android smartphone will finally be able to alert you if an AirTag is spying on you.]

... C’est pour cela que Google et Apple se sont alliés en mai dernier lors de la Google I/O pour lutter contre le pistage indésirable. Les deux firmes ont proposé conjointement une solution universelle, permettant de détecter et d’alerter de la présence d’appareils de pistage Bluetooth, sur iOS et sur Android. La proposition a été envoyée à l’IETF, qui a jusqu’au 2 août prochain pour donner son avis sur le sujet.

< <https://www.konbini.com/internet/ouf-votre-smartphone-android-pourra-enfin-vous-alerter-si-un-airtag-vous-espionne/> https://www.konbini.com/internet/ouf-votre-smartphone-android-pourra-enfin-vous-alerter-si-un-airtag-vous-espionne/>

 

Google Messages guadagna la crittografia end-to-end: interoperabilità con il protocollo MLS [Google Messages Earn End-to-End Encryption: Interoperability with MLS Protocol]

... IETF ha rilasciato le specifiche core del protocollo di Messaging Layer Security (MLS) come Request for Comments (RFC 9420).

< <https://www.cybersecurity360.it/news/google-messages-guadagna-la-crittografia-end-to-end-multi-piattaforma-con-il-protocollo-mls/> https://www.cybersecurity360.it/news/google-messages-guadagna-la-crittografia-end-to-end-multi-piattaforma-con-il-protocollo-mls/>

 

Patto tra Apple e Google, il telefono Android ti avvertirà se un Airtag ti sta seguendo [Pact between Apple and Google, the Android phone will warn you if an Airtag is following you]

... La specifica è stata presentata come Internet Draft attraverso l’IETF, un’organizzazione che si occupa dello sviluppo di standard.

< <https://www.macitynet.it/airtag-che-segue-un-telefono-android/> https://www.macitynet.it/airtag-che-segue-un-telefono-android/>

 

Google Mensajes adoptará la especificación MLS para avanzar hacia la mensajería interoperable y segura [Google Messages to adopt MLS specification to move towards interoperable and secure messaging]

... En este contexto, ha anunciado que planea incorporar a su aplicación Mensajes la especificación RFC 9420 MLS, del Grupo de Trabajo de Ingeniería de Internet (IETF). Como explica, esta tecnología "permite la interoperabilidad práctica entre servicios y plataformas, escalando a grupos de miles de usuarios de dispositivos múltiples".

< <https://www.lanacion.com.ar/agencias/google-mensajes-adoptara-la-especificacion-mls-para-avanzar-hacia-la-mensajeria-interoperable-y-nid24072023/> https://www.lanacion.com.ar/agencias/google-mensajes-adoptara-la-especificacion-mls-para-avanzar-hacia-la-mensajeria-interoperable-y-nid24072023/>

 

Sen o prepojených četových appkách sa môže stať realitou. Google podporí nový štandard [The dream of connected chat apps can become a reality. Google will support a new standard]

Organizácia IETF predstavila nový navrhovaný štandard pre vysoko zabezpečené četové aplikácie, ktorý ich v budúcnosti umožní navzájom prepojiť. Používatelia jednej appky tak budú môcť bez akýchkoľvek funkčných či bezpečnostných obmedzení komunikovať aj s ľuďmi, ktorí uprednostňujú konkurenčný softvér. Téme sa venoval web The Hacker News.

< <https://zive.aktuality.sk/clanok/cz3BR43/sen-o-prepojenych-cetovych-appkach-sa-moze-stat-realitou-google-podpori-novy-standard/> https://zive.aktuality.sk/clanok/cz3BR43/sen-o-prepojenych-cetovych-appkach-sa-moze-stat-realitou-google-podpori-novy-standard/>

 

Google Messages Bangun Enkripsi Lintas Platform End-to-End dengan Protokol MLS [Google Messages Builds End-to-End Cross-Platform Encryption with MLS Protocol]

... Perkembangan tersebut terjadi ketika IETF merilis spesifikasi inti dari protokol Messaging Layer Security (MLS) sebagai Request for Comments (RFC 9420).

< <https://cyberthreat.id/read/15807/Google-Messages-Bangun-Enkripsi-Lintas-Platform-End-to-End-dengan-Protokol-MLS> https://cyberthreat.id/read/15807/Google-Messages-Bangun-Enkripsi-Lintas-Platform-End-to-End-dengan-Protokol-MLS>

 

Google Rilis Fitur Anti-stalker di Android, Deteksi AirTag Tak Dikenal [Google Releases Anti-stalker Feature on Android, Detects Unknown AirTag]

... Adapun draf standar baru tersebut sudah dikirimkan juga ke IETF, organisasi terkemuka yang mengembangkan standar industri.

< <https://tekno.kompas.com/read/2023/07/31/07000097/google-rilis-fitur-anti-stalker-di-android-deteksi-airtag-tak-dikenal?page=all> https://tekno.kompas.com/read/2023/07/31/07000097/google-rilis-fitur-anti-stalker-di-android-deteksi-airtag-tak-dikenal?page=all>

 

Mensagens do Google podem estar recebendo criptografia de ponta a ponta entre plataformas [Google Messages May Be Getting Cross-Platform End-to-End Encryption]

... Se você não estiver familiarizado com o MLS, é um protocolo desenvolvido pela IETF. O IETF aprovou recentemente a publicação da especificação MLS RFC 9420. O Google afirma que com a nova especificação, o MLS agora permite “interoperabilidade prática entre serviços e plataformas, escalando para grupos de milhares de usuários de vários dispositivos”.

< <https://teg6.com/118839/noticias/mensagens-do-google-podem-estar-recebendo-criptografia-de-ponta-a-ponta-entre-plataformas/> https://teg6.com/118839/noticias/mensagens-do-google-podem-estar-recebendo-criptografia-de-ponta-a-ponta-entre-plataformas/>

 

Протокол MLS: новый уровень сквозного шифрования [MLS protocol: a new level of end-to-end encryption]

Новый стандарт от IETF улучшает защиту сообщений в интернете.

< <https://www.securitylab.ru/news/540358.php> https://www.securitylab.ru/news/540358.php>

 

גוגל מאמצת את MLS: לתקשורת טובה יותר בין אנדרואיד ו-iOS

... גוגל (Google) הכריזה על אימוץ תקן אבטחת ההודעות MLS (ר”ת Messaging Layer Security) עליה הכריז “כוח המשימה ההנדסי של האינטרנט”, ה-IETF (ר”ת), האחראי על פיתוח תקני האינטרנט השונים. התקן נועד לשפר את אבטחת ההודעות עם הצפנה מקצה-לקצה, אך גם לאפשר תקשורת טובה יותר בין פלטפורמות שונות.

< <https://www.gadgety.co.il/313357/google-mls/> https://www.gadgety.co.il/313357/google-mls/>

 

**********************

IETF COMMUNITY NOTES

**********************

Reappointment of Tim April to the ICANN Root Zone Evolution Review Committee (RZERC)

The IAB has reappointed Tim April to serve an additional one-year term on the ICANN Root Zone Evolution Review Committee (RZERC). The IAB thanks Tim for his willingness to serve the community in this capacity.

< <https://www.iab.org/2023/07/25/reappointment-of-tim-april-to-the-icann-root-zone-evolution-review-committee-rzerc-2/> https://www.iab.org/2023/07/25/reappointment-of-tim-april-to-the-icann-root-zone-evolution-review-committee-rzerc-2/>

 

**********************

SECURITY & PRIVACY

**********************

Securing the Web forward: Addressing developer concerns in web security

In the ever-evolving landscape of web development, security remains a key concern for developers. A recent survey gathered responses from 297 developers visiting MDN, asking them to rate the challenge they face with various security aspects in their development workflows. These responses offer a clear indication of the complexities and challenges encountered in daily development tasks.

< <https://www.w3.org/blog/2023/securing-the-web-forward-addressing-developer-concerns-in-web-security/> https://www.w3.org/blog/2023/securing-the-web-forward-addressing-developer-concerns-in-web-security/>

 

New report highlights the rise of IPv6 in cybercriminal activities

A new report reveals some of the top emerging cybersecurity threats and trends worldwide. CrowdSec released its Q2 2023 Majority Report, a community-driven data report driven by its users. Key takeaways from the report include the rise of IPv6 as well as the role of VPN in cybercriminal activities. The report consolidates insights from the company’s open source network, providing data on some of the top emerging cybersecurity threats and trends.

< <https://www.securitymagazine.com/articles/99689-new-report-highlights-the-rise-of-ipv6-in-cybercriminal-activities> https://www.securitymagazine.com/articles/99689-new-report-highlights-the-rise-of-ipv6-in-cybercriminal-activities>

 

Announcing the Q2 2023 CrowdSec Majority Report

We are thrilled to announce the release of the CrowdSec Majority Report for Q2 2023! Conceived about a year ago, the Majority Report is a project very close to the hearts of the CrowdSec team. Inspired by the 2002 film, Minority Report, we created the Majority Report to showcase the power of crowdsourced data in detecting malicious behavior and preventing imminent cyberattacks.

< <https://www.crowdsec.net/blog/announcing-the-q2-2023-crowdsec-majority-report> https://www.crowdsec.net/blog/announcing-the-q2-2023-crowdsec-majority-report>

 

HSTS preload adoption and challenges

HTTP Strict Transport Security (HSTS) is a way to signal to a web client that valid HTTPS certificates must be used when connecting to a domain. There are two main benefits to HSTS.

< <https://blog.apnic.net/2023/07/26/hsts-preload-adoption-and-challenges/> https://blog.apnic.net/2023/07/26/hsts-preload-adoption-and-challenges/>

 

us: New Cybersecurity Advisory Warns About Web Application Vulnerabilities

The National Security Agency (NSA) has partnered with U.S. and international cyber agencies to release the Cybersecurity Advisory (CSA), “Preventing Web Application Access Control Abuse,” warning that vulnerabilities in web applications, including application programming interfaces (APIs), can allow malicious actors to manipulate and access sensitive data.

< <https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3473830/new-cybersecurity-advisory-warns-about-web-application-vulnerabilities/> https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/3473830/new-cybersecurity-advisory-warns-about-web-application-vulnerabilities/>

 

CISA and Partners Release Joint Cybersecurity Advisory on Preventing Web Application Access Control Abuse

The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the Cybersecurity and Infrastructure Security Agency (CISA), and the National Security Agency (NSA) are releasing a joint Cybersecurity Advisory (CSA), Preventing Web Application Access Control Abuse, to warn vendors, designers, developers, and end-user organizations of web applications about insecure direct object reference (IDOR) vulnerabilities.

< <https://www.cisa.gov/news-events/alerts/2023/07/27/cisa-and-partners-release-joint-cybersecurity-advisory-preventing-web-application-access-control> https://www.cisa.gov/news-events/alerts/2023/07/27/cisa-and-partners-release-joint-cybersecurity-advisory-preventing-web-application-access-control>

 

**********************

INTERNET OF THINGS

**********************

Episode 60: Guiding Vendors to IoT Security by Design

In episode 60 of Cybersecurity Where You Are, co-host Sean Atkinson is joined by Kathleen Moriarty, CTO at the Center for Internet Security (CIS); Ben Carter, Internet of Things (IoT) specialist at CIS; and Kaitlin Drape, Research and Innovation Process Lead at CIS.

< <https://www.cisecurity.org/insights/podcast/episode-60-guiding-vendors-to-iot-security-by-design> https://www.cisecurity.org/insights/podcast/episode-60-guiding-vendors-to-iot-security-by-design>

 

How the Internet of Things (IoT) is increasing security effectiveness

Deployed across a wide range of devices, the Internet of Things (IoT) collects data to help business owners make decisions on a macro scale as well as at a granular level. The IoT is a network of physical devices embedded with sensors, software, and network connectivity that allows them to collect and share data. We called on this week's Expert Panel Roundtable to comment on the intersection of the IoT and physical security. We asked: How is the Internet of Things (IoT) increasing the effectiveness of security systems?

< <https://www.sourcesecurity.com/insights/iot-increasing-security-effectiveness-co-227-ga-co-1151-ga-co-1645-ga-co-2123-ga-co-4022-ga-co-8173-ga-co-9887-ga-co-11020-ga-co-1555412760-ga-co-1584600779-ga-co-1607083835-ga-co-1633418524-ga-co-1687947465-ga-off.1690265346.html> https://www.sourcesecurity.com/insights/iot-increasing-security-effectiveness-co-227-ga-co-1151-ga-co-1645-ga-co-2123-ga-co-4022-ga-co-8173-ga-co-9887-ga-co-11020-ga-co-1555412760-ga-co-1584600779-ga-co-1607083835-ga-co-1633418524-ga-co-1687947465-ga-off.1690265346.html>

 

Join industry peers and experts to learn how you can unleash your smart home offerings

The possibilities available for ISPs to offer customers user services accumulate year on year. From delivering WFH solutions for remote workers, to creating an Extended Reality (XR) service for the launch of devices like Apple Vision Pro, opportunities are bountiful in the connected home.

< <https://www.broadband-forum.org/join-industry-peers-and-experts-to-learn-how-you-can-unleash-your-smart-home-offerings> https://www.broadband-forum.org/join-industry-peers-and-experts-to-learn-how-you-can-unleash-your-smart-home-offerings>

 

**********************

QUANTUM NETWORKING

**********************

EPB and Qubitekk Launch Commercial Quantum Network to Accelerate Development and Adoption of Quantum Products [Nov 2022 news release]

Building on a “R&D 100” award-winning effort to run quantum cybersecurity technologies, EPB of Chattanooga and Qubitekk have joined together to launch America’s first industry-led, commercially available quantum network designed for private companies as well as government and university researchers to run quantum equipment and applications in an established fiber optic environment.

< <https://epb.com/newsroom/press-releases/epb-and-qubitekk-launch-commercial-quantum-network-to-accelerate-development-and-adoption-of-quantum-products/> https://epb.com/newsroom/press-releases/epb-and-qubitekk-launch-commercial-quantum-network-to-accelerate-development-and-adoption-of-quantum-products/>

 

**********************

NEW TRANSPORT PROTOCOLS

**********************

Update QUIC timers once per RTT

In a previous post, I observed that the classic way to compute round-trip time (RTT) statistics and retransmission timers does not work well. When acknowledgements are too frequent, the correlation between successive RTT measurements causes the smoothed RTT estimate to track closely the last values, and the RTT variations to be widely underestimated.

< <https://blog.apnic.net/2023/07/27/update-quic-timers-once-per-rtt/> https://blog.apnic.net/2023/07/27/update-quic-timers-once-per-rtt/>

 

Google propose Web Environment Integrity API

Google has proposed a new API called Web Environment Integrity (WEI) that would allow websites to request a token from the user’s device. This token would provide information about the device’s software stack and hardware configuration.

< <https://www.itworldcanada.com/post/google-propose-web-environment-integrity-api#:~:text=Google%20has%20proposed%20a%20new%20API%20called%20Web,and%20ensure%20the%20authenticity%20of%20devices%20and%20software.%E2%80%9D> https://www.itworldcanada.com/post/google-propose-web-environment-integrity-api#:~:text=Google%20has%20proposed%20a%20new%20API%20called%20Web,and%20ensure%20the%20authenticity%20of%20devices%20and%20software.%E2%80%9D>

 

Google's next big idea for browser security looks like another freedom grab to some

Googlers have proposed a way to determine whether browsers can be trusted, as a defense against criminal fraud and other bad behavior. Some in the internet community fear this is the end of the web as we know it.

< <https://www.theregister.com/2023/07/25/google_web_environment_integrity/> https://www.theregister.com/2023/07/25/google_web_environment_integrity/>

 

Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web

Google's newest proposed web standard is... DRM? Over the weekend the Internet got wind of this proposal for a "Web Environment Integrity API. " The explainer is authored by four Googlers, including at least one person on Chrome's "Privacy Sandbox" team, which is responding to the death of tracking cookies by building a user-tracking ad platform right into the browser.

< <https://arstechnica.com/gadgets/2023/07/googles-web-integrity-api-sounds-like-drm-for-the-web/> https://arstechnica.com/gadgets/2023/07/googles-web-integrity-api-sounds-like-drm-for-the-web/>

 

**********************

OTHERWISE NOTEWORTHY

**********************

Broadband Forum offers standardized path for an application service architecture for ISPs

Internet service providers can now manage individual smart home applications separately and without the need for complicated firmware updates, thanks to Broadband Forum launching significant upgrades to two key standards today.

< <https://www.broadband-forum.org/broadband-forum-offers-standardized-path-for-an-application-service-architecture-for-isps> https://www.broadband-forum.org/broadband-forum-offers-standardized-path-for-an-application-service-architecture-for-isps>

 

How to Design a Decentralized Social Media Protocol

Project Liberty sat down with Dave Clark, an early contributor to the TCP/IP protocols that built and run the internet, and one of the expert advisors on DSNP, the Decentralized Social Networking Protocol.

< <https://www.projectliberty.io/news/dave-clark-how-to-design-a-decentralized-social-media-protocol> https://www.projectliberty.io/news/dave-clark-how-to-design-a-decentralized-social-media-protocol>

 

Draft Note: Vision for W3C

The Advisory Board has published a first Draft Note of Vision for W3C. This document is an articulation of W3C’s mission, values, purpose, and principle.

< <https://www.w3.org/news/2023/draft-note-vision-for-w3c/> https://www.w3.org/news/2023/draft-note-vision-for-w3c/>

 

Climate Monitoring and 6G Must Learn to Coexist: Experts outline solutions for a more data-hungry wireless society

The electromagnetic spectrum is getting crowded, as more and more technologies tap into frequencies in the gigahertz and tens of gigahertz range. This means that future wireless technologies such as 6G may need to operate even farther up the frequency scale—100 gigahertz and above. And that could lead to some problems. Satellites needed to keep tabs on climate change and other scientific infrastructure already operate in those bands, and they’re not used to having to share. Fortunately, some solutions are in the works.

< <https://spectrum.ieee.org/climate-monitoring-satellites> https://spectrum.ieee.org/climate-monitoring-satellites>

 

Russ Housley and Barry Leiba Reappointed to the Community Coordination Group (CCG)

The IAB has re-appointed Russ Housley and Barry Leiba to the Community Coordination Group for the 2023-2025 term. The IAB thanks both Russ and Barry for their willingness to continue to serve the community in this capacity. The IAB would also like to thank everyone who provided feedback during this process.

< <https://www.iab.org/2023/07/25/russ-housley-and-barry-leiba-reappointed-to-the-community-coordination-group-ccg/> https://www.iab.org/2023/07/25/russ-housley-and-barry-leiba-reappointed-to-the-community-coordination-group-ccg/>

 

Google, Microsoft, OpenAI and Anthropic announce industry group to promote safe AI development

Some of the world’s top artificial intelligence companies are launching a new industry body to work together — and with policymakers and researchers — on ways to regulate the development of bleeding-edge AI.

< <https://edition.cnn.com/2023/07/26/tech/ai-industry-group/index.html> https://edition.cnn.com/2023/07/26/tech/ai-industry-group/index.html>

 

Google, Microsoft, OpenAI and startup form body to regulate AI development

Four of the most influential companies in artificial intelligence have announced the formation of an industry body to oversee safe development of the most advanced models.

< <https://www.theguardian.com/technology/2023/jul/26/google-microsoft-openai-anthropic-ai-frontier-model-forum> https://www.theguardian.com/technology/2023/jul/26/google-microsoft-openai-anthropic-ai-frontier-model-forum>

 

Microsoft, Anthropic, Google, and OpenAI launch Frontier Model Forum

Today, Anthropic, Google, Microsoft, and OpenAI are announcing the formation of the Frontier Model Forum, a new industry body focused on ensuring safe and responsible development of frontier AI models. The Frontier Model Forum will draw on the technical and operational expertise of its member companies to benefit the entire AI ecosystem, such as through advancing technical evaluations and benchmarks, and developing a public library of solutions to support industry best practices and standards.

< <https://blogs.microsoft.com/on-the-issues/2023/07/26/anthropic-google-microsoft-openai-launch-frontier-model-forum/> https://blogs.microsoft.com/on-the-issues/2023/07/26/anthropic-google-microsoft-openai-launch-frontier-model-forum/>

< <https://blog.google/outreach-initiatives/public-policy/google-microsoft-openai-anthropic-frontier-model-forum/> https://blog.google/outreach-initiatives/public-policy/google-microsoft-openai-anthropic-frontier-model-forum/>

 

Our commitment to advancing bold and responsible AI, together

We’re proud to join with other leading AI companies to jointly commit to advancing responsible practices in the development of artificial intelligence. Today is a milestone in bringing the industry together to ensure that AI helps everyone. These commitments will support efforts by the G7, the OECD, and national governments to maximize AI’s benefits and minimize its risks.

< <https://blog.google/outreach-initiatives/public-policy/our-commitment-to-advancing-bold-and-responsible-ai-together/> https://blog.google/outreach-initiatives/public-policy/our-commitment-to-advancing-bold-and-responsible-ai-together/>

------

David Goldstein

email:  <mailto:david@goldsteinreport.com> david@goldsteinreport.com

web:  <http://goldsteinreport.com/> http://goldsteinreport.com/

Twitter:  <https://twitter.com/goldsteinreport> https://twitter.com/goldsteinreport

phone: +61 418 228 605 - mobile; +61 2 9663 3430 - office/home