[Newsclips] IETF SYN-ACK Newspack 2021-12-20

David Goldstein <david@goldsteinreport.com> Mon, 20 December 2021 03:52 UTC

Return-Path: <david@goldsteinreport.com>
X-Original-To: newsclips@ietfa.amsl.com
Delivered-To: newsclips@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98F723A0D96 for <newsclips@ietfa.amsl.com>; Sun, 19 Dec 2021 19:52:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.868
X-Spam-Level:
X-Spam-Status: No, score=-0.868 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, GB_AFFORDABLE=1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_FILL_THIS_FORM_FRAUD_PHISH=0.01, T_FILL_THIS_FORM_SHORT=0.01, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AAc5oi7U6g3S for <newsclips@ietfa.amsl.com>; Sun, 19 Dec 2021 19:52:16 -0800 (PST)
Received: from karkinos.atomiclayer.com (karkinos.atomiclayer.com [96.125.178.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 78A853A0D8B for <newsclips@ietf.org>; Sun, 19 Dec 2021 19:52:16 -0800 (PST)
Received: from David2019Desktop (unknown [144.136.3.82]) by karkinos.atomiclayer.com (Postfix) with ESMTPSA id 67C29280F30 for <newsclips@ietf.org>; Sun, 19 Dec 2021 22:52:13 -0500 (EST)
Authentication-Results: karkinos.atomiclayer.com; spf=pass (sender IP is 144.136.3.82) smtp.mailfrom=david@goldsteinreport.com smtp.helo=David2019Desktop
Received-SPF: pass (karkinos.atomiclayer.com: connection is authenticated)
From: David Goldstein <david@goldsteinreport.com>
To: newsclips@ietf.org
Date: Mon, 20 Dec 2021 14:52:09 +1100
Message-ID: <00be01d7f554$f9b02e90$ed108bb0$@goldsteinreport.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_00BF_01D7F5B1.2D222D30"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: Adf1VDXmsn3eFJwSQFiO1sHZvmT2jg==
Content-Language: en-au
X-PPP-Message-ID: <20211220035214.2122514.9276@karkinos.atomiclayer.com>
X-PPP-Vhost: goldsteinreport.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/newsclips/VGQpSrQZ5vN_idqrcFzUD_OAU8Y>
Subject: [Newsclips] IETF SYN-ACK Newspack 2021-12-20
X-BeenThere: newsclips@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: IETF News Clips <newsclips.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/newsclips>, <mailto:newsclips-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/newsclips/>
List-Post: <mailto:newsclips@ietf.org>
List-Help: <mailto:newsclips-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/newsclips>, <mailto:newsclips-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 20 Dec 2021 03:52:24 -0000

Hi IETF Participants,

 

This is the final IETF SYN-ACK Newspack for 2021. I hope you’ve enjoyed it! I’ll return in 2022 in the week commencing 10 January. Thanks for those of you who have sent in comments, mostly good! But I do appreciate the good and bad feedback. And anyone with news to share, especially if it’s by IETF participants, please send through and I will include it. Over the next couple of weeks I’ll continue to monitor the news.

 

Till the Newspack returns, for those of you celebrating Christmas and new year, merry Christmas and happy new year. For everyone, take care and stay safe in what for many are challenging times.

The IETF SYN-ACK Newspack collects IETF-related items from a variety of news outlets and other online publications. They do not represent the views of the IETF and are not checked for factual accuracy.

 

Kind regards,

David

 

**********************

IETF IN THE NEWS

**********************

Internet Hall of Fame Celebrates 10th Anniversary

The Internet Hall of Fame announced today the names of 21 pioneers and visionaries from 11 countries who have made outstanding contributions to the Internet’s global growth, reach, security, and scale.

< <https://www.internetsociety.org/news/press-releases/2021/internet-hall-of-fame-celebrates-10th-anniversary/> https://www.internetsociety.org/news/press-releases/2021/internet-hall-of-fame-celebrates-10th-anniversary/>

 

L’Internet Hall of Fame fête son 10e anniversaire

L’Internet Hall of Fame a annoncé aujourd’hui les noms de 21 pionniers et visionnaires de 11 pays ayant contribué de manière exceptionnelle à la croissance, à la portée, à la sécurité et à l’échelle mondiale de l’Internet.

< <https://www.internetsociety.org/fr/news/communiques-de-presse/2021/linternet-hall-of-fame-fete-son-10e-anniversaire/> https://www.internetsociety.org/fr/news/communiques-de-presse/2021/linternet-hall-of-fame-fete-son-10e-anniversaire/>

 

Dan Kaminsky Inducted into Internet Hall of Fame

Famed hacker Dan Kaminsky has been inducted in the Internet Society’s Hall of Fame for his groundbreaking contributions to DNS security.

< <https://www.securityweek.com/dan-kaminsky-inducted-internet-hall-fame> https://www.securityweek.com/dan-kaminsky-inducted-internet-hall-fame>

 

DENIC - the Cooperative behind .de - Turns 25!

Anybody who surfs the Internet in Germany – to visit a website, to write an e-mail or a blog, to browse an online shop, to book a ticket for a train or concert, to do digital banking, to stream a film or music, to keep fit with a virtual sports course during the lockdown, or to confer with colleagues working from home via video call – very frequently, although mostly without knowing, makes use of the services of DENIC eG (Deutsches Network Information Center). This is the case, whenever a .de stands behind the web offer. ... As a cooperative characterised by community spirit and committed to democratic values, DENIC is also actively involved – beyond the realm of its core tasks – in various multistakeholder processes at national and international level where different interest groups meet to deal with critical and complex themes around the Internet. Through its participation in national and international coordination and standardisation bodies like ICANN, RIPE or IETF, DENIC contributes to the preservation and further development of the Internet as an open, free and secure medium.

< <https://www.denic.de/en/whats-new/news/article/denic-the-cooperative-behind-de-turns-25/> https://www.denic.de/en/whats-new/news/article/denic-the-cooperative-behind-de-turns-25/>

< <https://www.denic.de/aktuelles/news/artikel/denic-die-genossenschaft-hinter-de-wird-25/> https://www.denic.de/aktuelles/news/artikel/denic-die-genossenschaft-hinter-de-wird-25/> [Deutsche Fassung]

 

The space between IPv6 allocations: part 2 by George Michaelson

The first post in this series explored how and why APNIC delegates IPv6 address space to its Members using the ‘binary chop’ method, in which each subsequent delegation of IPv6 can be the size of all the previous delegations given to that Member in this part of the address space. Basically, they can double in size each time if need be. ... The various ideas around IPv6 addressing are interesting, and they are worth discussing. If you want to be part of that discussion, you should get involved! These ideas are under active discussion in the Internet Research Task Force (IRTF), which meets regularly at the Internet Engineering Task Force (IETF).

< <https://blog.apnic.net/2021/12/17/the-space-between-ipv6-allocations-part-2/> https://blog.apnic.net/2021/12/17/the-space-between-ipv6-allocations-part-2/>

 

Opinion: IPv4 address markets by Geoff Huston

Something odd happened through 2021 in the market for IPv4 addresses. Across 2021, the reported market price for the transfer of IPv4 addresses has doubled, from approximately USD 27 per IPv4 individual address at the end of 2020, to around USD 55 per address in December 2021. It has taken seven years for the market price to rise from just under USD 10 to get to USD 20 per address. 2020 saw the price rise a further USD 7 per address, and then in the next 12 months the market price doubled. ... IPv4 has a 32-bit address space that’s fixed and finite. If we want to encompass a larger set of directly connected devices we need a larger address field, or at least that was the thinking at the time of the IETF’s collective ruminations on routing and addressing in the early 1990s.

< <https://www.potaroo.net/ispcol/2021-12/ipv4markets.html> https://www.potaroo.net/ispcol/2021-12/ipv4markets.html>

< <https://blog.apnic.net/2021/12/16/opinion-ipv4-address-markets/> https://blog.apnic.net/2021/12/16/opinion-ipv4-address-markets/>

< <https://circleid.com/posts/20211216-the-formation-of-ipv4-address-markets> https://circleid.com/posts/20211216-the-formation-of-ipv4-address-markets>

 

IETF 112: Glenn Dean on Rubbing Shoulders With The Internet’s Elite Standards Setters and Developing Adaptive DNS Discovery

Rubbing shoulders with the elite of internet experts and developing future standards are reasons why Glenn Dean is involved in developing tomorrow’s internet standards. Dean, who currently works for Comcast-NBCUniversal, is involved in the Adaptive DNS Discovery (ADD) working group, which he says everyone involved in the DNS should be interested in as it covers a lot of different user scenarios. And it is ccTLDs that understand a great many scenarios whereby ADD can be of benefit. What does ADD do? And what was Glenn’s path to being involved in the IETF? Read on.

< <https://www.centr.org/news/blog/ietf-112-add.html> https://www.centr.org/news/blog/ietf-112-add.html>

 

Global internet outages explained

... The Internet Engineering Task Force (IETF) has been working to improve the security of BGP, but the complexity and growth of the internet has made this very difficult, particularly as changes often require every single operator to reconfigure their routers or upgrade their hardware.

< <https://www.bcs.org/articles-opinion-and-research/global-internet-outages-explained/> https://www.bcs.org/articles-opinion-and-research/global-internet-outages-explained/>

 

Open networking agility and control for a new era of connectivity

... Pere Monclus, VP/CTO, Networking with software vendor VMware remembers the input of standard bodies like the IETF, helping to look for a way to open up the definition of protocols and packet formats so networks could interoperate: “Now, fast forward 20 years, the meaning of openness has changed,” he says. “From an open source point of view we now have operating systems, abstraction, interfaces of size, contributing to a much more open ecosystem from open standards to open ecosystems.”

< <https://www.vanillaplus.com/2021/12/14/66072-open-networking-agility-and-control-for-a-new-era-of-connectivity/> https://www.vanillaplus.com/2021/12/14/66072-open-networking-agility-and-control-for-a-new-era-of-connectivity/>

 

Studie: Chinas wachsendes Interesse an Normen und Standards ist bedenklich [Study: China's growing interest in norms and standards is worrying]

... Auf internationaler Ebene werden digitale Normen in einer Vielzahl von Institutionen entwickelt. Formelle Organisationen sind etwa die Internationale Elektrotechnische Kommission (IEC), die Internationale Organisation für Normung (ISO) und die Internationale Fernmeldeunion (ITU). Dazu kommen quasi-formelle Einrichtungen wie das Institute of Electrical and Electronics Engineers (IEEE), das 3rd Generation Partnership Project (3GPP) und die Internet Engineering Task Force (IETF). Allein die große Zahl der Organisationen und ihrer Mitgliederstrukturen, Arbeitsmethoden und Regeln machen das Ökosystem der Normung komplex.

< <https://www.heise.de/news/Studie-Chinas-wachsendes-Interesse-an-Normen-und-Standards-ist-bedenklich-6293885.html> https://www.heise.de/news/Studie-Chinas-wachsendes-Interesse-an-Normen-und-Standards-ist-bedenklich-6293885.html>

 

Digital Markets Act: EU-Parlament stimmt für verknüpfbare Messenger [Digital Markets Act: EU Parliament votes for linkable messengers]

... Das Bundesamt für Sicherheit in der Informationstechnik (BSI) hatte für den Austausch jüngst das von der Internet Engineering Task Force (IETF) vorangetriebene MLS-Protokoll (Messaging Layer Security) ins Spiel gebracht. Dieses könnte nach Abschluss des Standardisierungsverfahrens die gewünschte sichere Kommunikation zwischen unterschiedlichen Chat-Diensten ermöglichen.

< <https://www.heise.de/news/Digital-Markets-Act-EU-Parlament-stimmt-fuer-verknuepfbare-Messenger-6296475.html> https://www.heise.de/news/Digital-Markets-Act-EU-Parlament-stimmt-fuer-verknuepfbare-Messenger-6296475.html>

 

Digital Markets Act : le Parlement européen vote en faveur des messageries connectées [Digital Markets Act: the European Parliament votes in favour of connected messaging]

... L’Office fédéral allemand de la sécurité des technologies de l’information (BSI) avait récemment évoqué pour l’échange le protocole MLS (Messaging Layer Security) promu par l’Internet Engineering Task Force (IETF). Une fois le processus de normalisation terminé, celui-ci pourrait permettre la communication sécurisée souhaitée entre les différents services de chat. L’Agence fédérale des réseaux travaille également à des solutions techniques. Elle a en vue des « ponts » comme sorte de fonction de traduction, des interfaces ouvertes et une standardisation complète.

< <https://www.lemedia05.com/digital-markets-act-le-parlement-europeen-vote-en-faveur-des-messageries-connectees/> https://www.lemedia05.com/digital-markets-act-le-parlement-europeen-vote-en-faveur-des-messageries-connectees/>

 

ETRI '실시간 스트리밍 기술' 국제표준 등록 [ETRI 'Live Streaming Technology' International Standard Registration]

한국전자통신연구원(ETRI)은 실시간 비디오 스트리밍을 위한 정보중심 네트워킹(ICN) 기술이 국제인터넷표준화기구(IETF) 국제표준으로 등록됐다고 10일 밝혔다. 

< <http://www.daejonilbo.com/news/newsitem.asp?pk_no=1498135> http://www.daejonilbo.com/news/newsitem.asp?pk_no=1498135>

 

优速安全智能域名解析系统通过 [U-Speed Secure Intelligent Domain Name Resolution System passes]

近日,南京优速网络科技有限公司旗下优速安全智能域名解析系统S²DNS在下一代互联网国家工程中心-全球IPv6测试中心正式通过IPv6 Ready核心协议Phase-2测试,并荣获由国际组织IPv6 Forum颁发的IPv6 Ready Logo Phase-2认证证书(Logo ID:02-C-002309)。这标志着上述产品的IPv6核心协议实现已全面符合IETF RFC相关标准,其一致性和互通性得到了权威验证。

< <https://www.sohu.com/a/508013839_104421> https://www.sohu.com/a/508013839_104421>

 

骄傲!清华大学李星教授入选互联网名人堂 [Proud! Professor Li Xing of Tsinghua University was inducted into the Internet Hall of Fame]

... 当前,IVI无状态翻译技术已成为国际上IPv4和IPv6互联互通最重要的互联网标准,获得9个IETF的RFC,对于引领全球过渡到下一代互联网IPv6单栈具有重要意义。

< <https://www.edu.cn/xxh/zhuan_jia_zhuan_lan/lx/202112/t20211214_2189499.shtml> https://www.edu.cn/xxh/zhuan_jia_zhuan_lan/lx/202112/t20211214_2189499.shtml>

 

展望十四五教育IPv6发展新景观 [Looking forward to the new landscape of IPv6 development in education in the 14th Five-Year Plan]

... 尤其是2016年11月,全球互联网最具权威的技术标准化组织一互联网工程任务组(IETF)的体系结构委员会(IAB)发布了一个声明,希望未来的互联网协议标准全部基于IPv6来制定,新设备和新的扩展协议不再兼容IPv4。这个公告发出了非常明确的信号,正式确认未来互联网将建立在IPv6的基础上。

< <https://www.edu.cn/xxh/focus/hyrd/202112/t20211214_2188975.shtml> https://www.edu.cn/xxh/focus/hyrd/202112/t20211214_2188975.shtml>

 

一支崛起的ICT行业标准参与力量:新华三再获业界权威标准组织认可 [A rising ICT industry standard participation force: H3C has been recognized by the industry's authoritative standards organization]

一直以来,标准化是整个网络产业赖以生存和发展的基础。IETF、CCSA、BBF等为代表的标准化组织好比“灯塔”,引领产业前行之路。近日,在一次性通过3篇BBF文稿之后,紫光股份旗下新华三集团再次通过2篇BBF文稿,并成功提交多篇IETF标准草案,成为一支不容小觑的ICT行业标准参与力量。

< <https://finance.sina.com.cn/tech/2021-12-18/doc-ikyamrmy9812802.shtml> https://finance.sina.com.cn/tech/2021-12-18/doc-ikyamrmy9812802.shtml>

 

**********************

SECURITY & PRIVACY

**********************

us: National Critical Functions: Reframing How Risks are Managed

Today, CISA released the second National Critical Functions: Status Update to the Critical Infrastructure Community to inform stakeholders of the progress made on the National Critical Functions (NCFs) main activities. 

< <https://www.cisa.gov/blog/2021/12/15/national-critical-functions-reframing-how-risks-are-managed> https://www.cisa.gov/blog/2021/12/15/national-critical-functions-reframing-how-risks-are-managed>

 

ESF Members, NSA and CISA publish the fourth installment of 5G cybersecurity guidance

The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) published the fourth installment on securing integrity of 5G cloud infrastructures, Ensure Integrity of Cloud Infrastructure. As 5G networks and devices continue to increase in popularity, the importance of platform security to harden your systems against malicious cyber activity and persistence is apparent.

< <https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/2875523/esf-members-nsa-and-cisa-publish-the-fourth-installment-of-5g-cybersecurity-gui/> https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/2875523/esf-members-nsa-and-cisa-publish-the-fourth-installment-of-5g-cybersecurity-gui/>

 

NIST Launches New International Cybersecurity and Privacy Resources Website

Every day, NIST cybersecurity and privacy resources are being used throughout the world to help organizations manage cybersecurity and privacy risks. To assist our international colleagues, NIST has launched a new International Cybersecurity and Privacy Resources Site. The site includes translations of the Cybersecurity Framework, including a newly published Indonesian translation.

< <https://www.nist.gov/blogs/cybersecurity-insights/nist-launches-new-international-cybersecurity-and-privacy-resources> https://www.nist.gov/blogs/cybersecurity-insights/nist-launches-new-international-cybersecurity-and-privacy-resources>

 

uk: Policy paper: National Cyber Strategy 2022

Foreword: The United Kingdom is an open and democratic society, whose record in collaboration and innovation underpins our success as an outward-looking global nation. We see this in our response to international health emergencies and in our promotion of Net Zero targets. But nowhere are the advantages of this approach more evident than in cyber.

< <https://www.gov.uk/government/publications/national-cyber-strategy-2022/national-cyber-security-strategy-2022> https://www.gov.uk/government/publications/national-cyber-strategy-2022/national-cyber-security-strategy-2022>

 

NIST Launches New International Cybersecurity and Privacy Resources Website

Every day, NIST cybersecurity and privacy resources are being used throughout the world to help organizations manage cybersecurity and privacy risks. To assist our international colleagues, NIST has launched a new International Cybersecurity and Privacy Resources Site. The site includes translations of the Cybersecurity Framework, including a newly published Indonesian translation.

< <https://www.nist.gov/blogs/cybersecurity-insights/nist-launches-new-international-cybersecurity-and-privacy-resources> https://www.nist.gov/blogs/cybersecurity-insights/nist-launches-new-international-cybersecurity-and-privacy-resources>

 

Joint Statement on Log4Shell: Assessment and advice on the Log4j vulnerability.

The European Commission, the EU Agency for Cybersecurity, CERT-EU and the network of the EU national computer security incident response teams (CSIRTs network) have been closely following the development of the Log4Shell vulnerability since 10 December 2021.

< <https://www.enisa.europa.eu/news/statement-on-log4shell> https://www.enisa.europa.eu/news/statement-on-log4shell>

 

Brand-New Log4Shell Attack Vector Threatens Local Hosts

Defenders will once again be busy beavers this weekend: There’s an alternative attack vector for the ubiquitous Log4j vulnerability, which relies on a basic Javascript WebSocket connection to trigger remote code-execution (RCE) on servers locally, via drive-by compromise.

< <https://threatpost.com/new-log4shell-attack-vector-local-hosts/177128/> https://threatpost.com/new-log4shell-attack-vector-local-hosts/177128/>

 

A deep dive into a real-life Log4j exploitation

The widely used Apache Log4j vulnerability is still making waves worldwide. After witnessing over 1,272,000 attempts to allocate the vulnerability, and attempted exploits on over 44% of corporate networks globally, Check Point Research recently detected numerous attacks exploiting the Log4j vulnerability, involving mining of cryptocurrencies.

< <https://blog.checkpoint.com/2021/12/14/a-deep-dive-into-a-real-life-log4j-exploitation/> https://blog.checkpoint.com/2021/12/14/a-deep-dive-into-a-real-life-log4j-exploitation/>

 

CISA Issues Emergency Directive Requiring Federal Agencies to Mitigate Apache Log4J Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive (ED) 22-02 today requiring federal civilian departments and agencies to assess their internet-facing network assets for the Apache Log4j vulnerabilities and immediately patch these systems or implement other appropriate mitigation measures. This Directive will be updated to further drive additional mitigation actions.

< <https://www.cisa.gov/news/2021/12/17/cisa-issues-emergency-directive-requiring-federal-agencies-mitigate-apache-log4j> https://www.cisa.gov/news/2021/12/17/cisa-issues-emergency-directive-requiring-federal-agencies-mitigate-apache-log4j>

 

CISA Issues Emergency Directive on Log4j

The US Department of Homeland Security's Cybersecurity Infrastructure and Security Agency (CISA) today ordered civilian federal agencies to take immediate steps to identify, patch, and mitigate Log4j vulnerabilities in their networks.

< <https://www.darkreading.com/threat-intelligence/cisa-issues-emergency-directive-on-log4j> https://www.darkreading.com/threat-intelligence/cisa-issues-emergency-directive-on-log4j>

 

What the Log4Shell Bug Means for SMBs: Experts Weigh In

An exclusive roundtable of security researchers discuss the specific implications of CVE-2021-44228 for smaller businesses, including what’s vulnerable, what an attack looks like and to how to remediate.

< <https://threatpost.com/log4shell-bug-smbs-experts/177021/> https://threatpost.com/log4shell-bug-smbs-experts/177021/>

 

Relentless Log4j Attacks Include State Actors, Possible Worm

Call it a “logjam” of threats: Attackers including nation-state actors have already targeted half of all corporate global networks in security companies’ telemetry using at least 70 distinct malware families — and the fallout from the Log4j vulnerability is just beginning.

< <https://threatpost.com/log4j-attacks-state-actors-worm/177088/> https://threatpost.com/log4j-attacks-state-actors-worm/177088/>

 

EXPLAINER: The security flaw that’s freaked out the internet

Security pros say it’s one of the worst computer vulnerabilities they’ve ever seen. They say state-backed Chinese and Iranian hackers and rogue cryptocurrency miners have already seized on it.

< <https://apnews.com/article/technology-business-software-hacking-343949ddd8446e50eb70823601d15ef3> https://apnews.com/article/technology-business-software-hacking-343949ddd8446e50eb70823601d15ef3>

 

us: DHS Announces “Hack DHS” Bug Bounty Program to Identify Potential Cybersecurity Vulnerabilities

Today, the Department of Homeland Security (DHS) announced the launch of “Hack DHS,” a bug bounty program to identify potential cybersecurity vulnerabilities within certain DHS systems and increase the Department’s cybersecurity resilience. Through Hack DHS, vetted cybersecurity researchers who have been invited to access select external DHS systems (“hackers”) will identify vulnerabilities (“bugs”) that could be exploited by bad actors so they can be patched. These hackers will be rewarded with payments (“bounties”) for the bugs they identify.

< <https://www.dhs.gov/news/2021/12/14/dhs-announces-hack-dhs-bug-bounty-program-identify-potential-cybersecurity> https://www.dhs.gov/news/2021/12/14/dhs-announces-hack-dhs-bug-bounty-program-identify-potential-cybersecurity>

 

Germany: ‘Critical’ cybersecurity flaw already exploited

Germany has activated its national IT crisis center in response to an “extremely critical” flaw in a widely used software tool that the government says has already been exploited internationally.

< <https://apnews.com/article/technology-business-europe-software-germany-8f79901b508621fdb898b231e1173593> https://apnews.com/article/technology-business-europe-software-germany-8f79901b508621fdb898b231e1173593>

 

ESF Members, NSA and CISA publish the fourth installment of 5G cybersecurity guidance

The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) published the fourth installment on securing integrity of 5G cloud infrastructures, Ensure Integrity of Cloud Infrastructure. As 5G networks and devices continue to increase in popularity, the importance of platform security to harden your systems against malicious cyber activity and persistence is apparent.

< <https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/2875523/esf-members-nsa-and-cisa-publish-the-fourth-installment-of-5g-cybersecurity-gui/> https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/2875523/esf-members-nsa-and-cisa-publish-the-fourth-installment-of-5g-cybersecurity-gui/>

 

**********************

INTERNET OF THINGS

**********************

The future is not the Internet of Things… it is the Connected Intelligent Edge

The ‘Internet of Things’ was first coined to help people understand the concept of digital appliances that could communicate with an app or central hub. If you’ve been to CES at any point in the last decade, you could see many examples on the show floor, such as connected weight scales or a connected fridge. But these early examples of ‘connected’ tech felt more gimmicky than useful, and were largely contained to the consumer electronics industry. With the onset of 5G and AI technologies giving us the possibility to intelligently connect everything 100% of the time, the scale, utility and promise of connected things are evolving to be transformational, ushering in what some are calling a ‘true digital revolution.’

< <https://techcrunch.com/sponsor/qualcomm/the-future-is-not-the-internet-of-things-it-is-the-connected-intelligent-edge/> https://techcrunch.com/sponsor/qualcomm/the-future-is-not-the-internet-of-things-it-is-the-connected-intelligent-edge/>

 

The 5 Biggest Internet Of Things (IoT) Trends In 2022

The Internet of Things (IoT) is a term that describes the increasingly sophisticated ecosystems of online, connected devices we share our world with. The slightly odd name refers to the fact that the first iteration of the internet was simply a network of connected computers. As the internet grew, phones, office equipment like printers and scanners, and industrial machinery were added to the internet. Today, just about any device we use in our homes, offices, factories, or simply wear on our bodies can be online and connected, hence the internet of "things."

< <https://www.forbes.com/sites/bernardmarr/2021/12/13/the-5-biggest-internet-of-things-iot-trends-in-2022/> https://www.forbes.com/sites/bernardmarr/2021/12/13/the-5-biggest-internet-of-things-iot-trends-in-2022/>

 

**********************

NEW TRANSPORT PROTOCOLS

**********************

HTTP/3 est rapide, et c'est un atout majeur pour les performances du web [HTTP/3 is fast, and it is a major asset for web performance]

Les équipes de recherche ont travaillé en étroite collaboration pour faire passer HTTP/3 et QUIC de normes naissantes à des technologies largement adoptées pour améliorer le Web. HTTP/3 est la troisième version du protocole HTTP (Hypertext Transfer Protocol), anciennement HTTP over-QUIC. QUIC (Quick UDP Internet Connections) a été initialement développé par Google et est le successeur de HTTP/2. Des entreprises comme Google et Facebook utilisent déjà QUIC pour accélérer le Web.

< <https://web.developpez.com/actu/329595/HTTP-3-est-rapide-et-c-est-un-atout-majeur-pour-les-performances-du-web-Google-com-serait-entierement-servi-en-HTTP-3-pour-les-navigateurs-modernes/> https://web.developpez.com/actu/329595/HTTP-3-est-rapide-et-c-est-un-atout-majeur-pour-les-performances-du-web-Google-com-serait-entierement-servi-en-HTTP-3-pour-les-navigateurs-modernes/>

 

Pozrite sa, ako môžete zrýchliť prehliadač Chrome! Poznáte tieto nastavenia? [See how you can speed up Chrome! Do you know these settings?]

... Ide o protokol, ktorý podporuje rýchlejšie prehliadanie no zatiaľ ho nepoužívajú všetky stránky, preto je vypnutý. No ak ho chcete využívať na stránkach, ktoré ho používajú, tak vyhľadajte Experimental QUIC protocol a taktiež ho prepnite na Enabled.

< <https://vosveteit.sk/pozrite-sa-ako-mozete-zrychlit-prehliadac-chrome-poznate-tieto-nastavenia/> https://vosveteit.sk/pozrite-sa-ako-mozete-zrychlit-prehliadac-chrome-poznate-tieto-nastavenia/>

 

Microsoft、.NET 6におけるネットワーキングの変更と改善について紹介 [Microsoft、. Learn about networking changes and improvements in NET 6]

... .NET 6では、HTTP/3とQUICのセットアップが大幅に簡素化されたほか、固定の再試行回数制限に基づくようにHTTP要求の再試行ロジックが変更され、要求が接続の最初の要求であるかどうかに関係なく機能するようになった。

< <https://codezine.jp/article/detail/15338> https://codezine.jp/article/detail/15338>

 

**********************

OTHERWISE NOTEWORTHY

**********************

Europe launches first large-scale 6G Research and Innovation Programme

This week the newly created Joint Undertaking on Smart Networks and Services towards 6G (SNS JU) adopted its first Work Programme 2021-2022 with an earmarked public funding of about € 240 million.

< <https://digital-strategy.ec.europa.eu/en/news/europe-launches-first-large-scale-6g-research-and-innovation-programme> https://digital-strategy.ec.europa.eu/en/news/europe-launches-first-large-scale-6g-research-and-innovation-programme>

 

W3C Advisory Committee Elects Technical Architecture Group

The W3C Advisory Committee has elected the following people to the W3C Technical Architecture Group (TAG): Rossen Atanassov (Microsoft Corporation), Dapeng (Max) Liu (Alibaba Group) and Sangwhan Moon (Google). They join co-Chair Tim Berners-Lee and continuing participants, Daniel Appelquist (Samsung Electronics; co-Chair), Hadley Beeman (W3C Invited Expert), Amy Guy (Digital Bazaar), Peter Linss (W3C Invited Expert; co-Chair), Theresa O’Connor (Apple, Inc.) and Lea Verou (W3C Invited Expert) . Yves Lafon continues as staff contact. Many thanks for contributions to the TAG to the departing participant, Kenneth Rohde Christiansen (Intel Corporation), whose term ends at the end of January 2022.

< <https://www.w3.org/blog/news/archives/9377> https://www.w3.org/blog/news/archives/9377>

 

Who’s Behind Web3?

If you haven’t been drawn into the growing hype over Web3, where have you been? I kid. It’s mostly just people arguing about what it is exactly; what it will mean; and — since tech has always been an industry populated by narcissists — who’ll be king of it all. That last one is also kind of a joke, so relax. But, if like most of us, you’re still scratching your head about Web3, think of it as the next phase of the internet following Web1 (broadly, websites and browsers) and Web2 (encompassing apps, social media and mobile) that’s meant to be a more decentralized internet run on blockchain, the technology that underpins things like cryptocurrency and NFTs, or nonfungible tokens, that are all the rage. If it functions as imagined, Web3 will bring more power into the hands of creators and away from the mega-corporations like Google, Facebook and Amazon that have dominated the current iteration of the internet.

< <https://www.nytimes.com/2021/12/16/opinion/web3-big-tech.html> https://www.nytimes.com/2021/12/16/opinion/web3-big-tech.html>

 

What is Web3 and how will it change the way we use the internet?

Yet another new buzzword has got the internet excited, but what exactly is Web3? Here’s everything you need to know.

< <https://www.newscientist.com/article/2301706-what-is-web3-and-how-will-it-change-the-way-we-use-the-internet/> https://www.newscientist.com/article/2301706-what-is-web3-and-how-will-it-change-the-way-we-use-the-internet/>

 

The irrational exuberance of web3

This year’s hottest new tech terms are definitely “web3” and “metaverse.” The former refers to a decentralized web, based on the blockchain, while the latter is a combination of the internet and augmented and virtual reality. It is possible that we will see a merging of the concepts at some point. That is, if the concepts ever turn into anything.

< <https://techcrunch.com/2021/12/14/the-irrational-exuberance-of-web3/> https://techcrunch.com/2021/12/14/the-irrational-exuberance-of-web3/>

 

European Commission launches new data and cloud alliance

The new European Commission-powered Alliance for Industrial Data, Edge and Cloud was officially launched on Tuesday (December 14). With 39 members, the initiative gathers some of Europe’s top-notch tech companies to collaborate on next-generation computing technologies.

< <https://www.euractiv.com/section/digital/news/european-commission-launches-new-data-and-cloud-alliance/> https://www.euractiv.com/section/digital/news/european-commission-launches-new-data-and-cloud-alliance/>

 

National Instruments Paves the Way for Terahertz Regime in 6G Networks: Developing tools that can test new technologies for 6G networks is the key step in making it a reality

While 5G networks continue their rollout around the world, researchers and engineers are already looking ahead to a new generation of mobile networks, dubbed 6G. One of the key elements for 6G networks will be to move beyond the millimeter wave (mmWave) spectrum and up into the terahertz (THz) spectrum. The THz spectrum will certainly open up more bandwidth, but there are a number of technical challenges that will need to be addressed if mobile networks can ever exploit this spectrum.

< <https://spectrum.ieee.org/ni-6g-networks> https://spectrum.ieee.org/ni-6g-networks>

 

If 6G Becomes Just 5G+, We’ll Have Made a Big Mistake: Iterating current tech is a bad idea; semantic communication could be the answer

We are still in the early stages of 5G rollouts, with many years still ahead in its technological evolution. But following the traditional 10-year cycle for developing new wireless generations, research into 6G is already going ahead at full steam. Several 6G initiatives around the world, including the first, 6GENESIS, led by the University of Oulu in Finland, are paving the way for the standardization process that is expected to kick off in 2025 or 2026.

< <https://spectrum.ieee.org/6g-semantic-communication> https://spectrum.ieee.org/6g-semantic-communication>

 

New NUS Centre for 5G Digital Building Technology

In a boost to Singapore’s future-built environment landscape, the National University of Singapore (NUS) Department of the Built Environment has established a new research centre to augment the digital capability of Singapore’s construction industry, accelerate 5G training and promote the adoption of 5G technologies in Smart Facilities Management (FM).

< <https://opengovasia.com/new-nus-centre-for-5g-digital-building-technology/> https://opengovasia.com/new-nus-centre-for-5g-digital-building-technology/>

 

Solutions for Providing Internet Access to Rural Areas: IEEE explores employing ICT, regulations, and standards

The COVID-19 pandemic has brought home the need to provide Internet connectivity to underserved communities. Many people with affordable access have been able to work from home, learn remotely, and shop online, but that certainly hasn’t been the case for everyone. Almost half the world’s population has no Internet access, according to the World Economic Forum. And where access is available, it can be too expensive.

< <https://spectrum.ieee.org/providing-internet-to-rural-areas> https://spectrum.ieee.org/providing-internet-to-rural-areas>

 

NIS2 Inconsistency – a DNS Supply Chain Perspective

The European Union’s Network and Information Security directive (NIS2) is missing an opportunity to foster accountability across the entire DNS supply chain. Instead of focusing on the outcome for the consumer, NIS2 is trying regulate specific points in the network.

< <https://www.internetsociety.org/blog/2021/12/nis2-inconsistency-a-dns-supply-chain-perspective/> https://www.internetsociety.org/blog/2021/12/nis2-inconsistency-a-dns-supply-chain-perspective/>

 

Internet Centralization – New Pulse Focus Area Provides New Perspectives

The Internet is built on a decentralized model. Its many network operators make independent decisions about how to interconnect, and the core functions and decisions required to keep the Internet running are distributed among its participants using open standards and protocols. This decentralized architecture, where power and control are distributed, has been key to the Internet’s success by fostering resilience, innovation, and connectivity at a global scale. But to what degree is the current Internet in line with this decentralized ideal? And what are the trends?

< <https://www.internetsociety.org/blog/2021/12/internet-centralization-new-pulse-focus-area-provides-new-perspectives/> https://www.internetsociety.org/blog/2021/12/internet-centralization-new-pulse-focus-area-provides-new-perspectives/>

 

Toward managing network traffic by domain name

Network management is hard. Among many reasons, grappling with low-level, unintuitive identifiers, such as IP addresses, is one of them. Consider this example: ‘Today, huge traffic came from 142.250.65.174’. This statement is not that useful to anybody. Instead, what if the IP addresses were automatically translated to higher-level names like ‘YouTube’? Immediately, this statement becomes much easier to understand. The same principle applies to specifying network policies. For example, it would be much easier and more intuitive to write policies like: ‘Bypass the firewall for traffic from YouTube.’

< <https://blog.apnic.net/2021/12/15/toward-managing-network-traffic-by-domain-name/> https://blog.apnic.net/2021/12/15/toward-managing-network-traffic-by-domain-name/>

 

Webinar for the Nordics: Internet Fragmentation? Technical and Political Perspectives: Speakers: Patrik Fältström & Chris Mondini

This interactive webinar will address the question of Internet Fragmentation, from both technical and geo-political perspectives. Is it a true risk?

< <https://features.icann.org/event/internet-ecosystem/webinar-nordics-internet-fragmentation-technical-and-political-perspectives> https://features.icann.org/event/internet-ecosystem/webinar-nordics-internet-fragmentation-technical-and-political-perspectives>

 

Universal Acceptance studies: good progress in browsers, major challenges in social media

Universal Acceptance is a cornerstone of a digitally inclusive Internet by ensuring all domain names and email addresses (IDNs) - in any language, script, or character - are accepted equally by all Internet-based applications, devices and systems.

< <https://idnworldreport.eu/blog/2021-11-29-oxil-uasg-icann/> https://idnworldreport.eu/blog/2021-11-29-oxil-uasg-icann/>

------

David Goldstein

email:  <mailto:david@goldsteinreport.com> david@goldsteinreport.com

web:  <http://goldsteinreport.com/> http://goldsteinreport.com/

Twitter:  <https://twitter.com/goldsteinreport> https://twitter.com/goldsteinreport

phone: +61 418 228 605 - mobile; +61 2 9663 3430 - office/home