[Newsclips] IETF SYN-ACK Newspack 2022-06-27

David Goldstein <david@goldsteinreport.com> Mon, 27 June 2022 09:39 UTC

Return-Path: <david@goldsteinreport.com>
X-Original-To: newsclips@ietfa.amsl.com
Delivered-To: newsclips@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 06C83C14CF01 for <newsclips@ietfa.amsl.com>; Mon, 27 Jun 2022 02:39:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.602
X-Spam-Level:
X-Spam-Status: No, score=0.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_SPAM=2.5] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sie2Kkw0h7EI for <newsclips@ietfa.amsl.com>; Mon, 27 Jun 2022 02:39:33 -0700 (PDT)
Received: from karkinos.atomiclayer.com (karkinos.atomiclayer.com [96.125.178.142]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 330CDC15A75C for <newsclips@ietf.org>; Mon, 27 Jun 2022 02:39:32 -0700 (PDT)
Received: from David2019Desktop (unknown [124.183.4.6]) by karkinos.atomiclayer.com (Postfix) with ESMTPSA id 99B0D29DEF1 for <newsclips@ietf.org>; Mon, 27 Jun 2022 05:39:29 -0400 (EDT)
Authentication-Results: karkinos.atomiclayer.com; spf=pass (sender IP is 124.183.4.6) smtp.mailfrom=david@goldsteinreport.com smtp.helo=David2019Desktop
Received-SPF: pass (karkinos.atomiclayer.com: connection is authenticated)
From: David Goldstein <david@goldsteinreport.com>
To: newsclips@ietf.org
Date: Mon, 27 Jun 2022 19:39:25 +1000
Message-ID: <000001d88a09$cd9da8b0$68d8fa10$@goldsteinreport.com>
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_NextPart_000_0001_01D88A5D.9F4E2580"
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AdiJ5n56JPW52fTETQWuT/B72wuLLw==
Content-Language: en-au
X-PPP-Message-ID: <20220627093930.26379.5858@karkinos.atomiclayer.com>
X-PPP-Vhost: goldsteinreport.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/newsclips/hqD98rBC_e_dQfnJ9S5HS5L6vz0>
Subject: [Newsclips] IETF SYN-ACK Newspack 2022-06-27
X-BeenThere: newsclips@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF News Clips <newsclips.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/newsclips>, <mailto:newsclips-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/newsclips/>
List-Post: <mailto:newsclips@ietf.org>
List-Help: <mailto:newsclips-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/newsclips>, <mailto:newsclips-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Jun 2022 09:39:38 -0000

The IETF SYN-ACK Newspack collects IETF-related items from a variety of news outlets and other online publications. They do not represent the views of the IETF and are not checked for factual accuracy.

 

**********************

IETF IN THE NEWS

**********************

Internet Society Announces New Members of Board of Trustees

The Internet Society–which celebrates its 30th anniversary this year as a global nonprofit promoting the development and use of an open, globally connected, and secure Internet–today announced that four new members have been seated on its board of trustees.

< <https://www.internetsociety.org/news/press-releases/2022/announcing-new-members-of-board-of-trustees/> https://www.internetsociety.org/news/press-releases/2022/announcing-new-members-of-board-of-trustees/>

 

Who makes the Internet? A longitudinal analysis of the IETF

Operation of the Internet requires interoperability between networks, systems, and applications, as well as cooperation among a growing number of stakeholders. The Internet Engineering Task Force (IETF) is critical in supporting this cooperation and interoperability by bringing together interested parties and standardizing the protocols that enable Internet interconnectivity such as IPv4/6, HTTP/s or BGP.

< <https://networks.imdea.org/whatsnew/events-agenda/who-makes-the-internet-a-longitudinal-analysis-of-the-ietf/> https://networks.imdea.org/whatsnew/events-agenda/who-makes-the-internet-a-longitudinal-analysis-of-the-ietf/>

 

Privacy Access Token

Various browser vendors (Apple, Google, Mozilla) recently announced support for the private access token (PAT), a new standard being drafted by the IETF. The privacy pass is designed to bring more privacy to web users, and reduce data collection or the need to interrupt the user experience with a CAPTCHA challenge commonly used by website owners when data collected show some anomalies to verify the client is legitimate and prevent bots from committing fraud.

< <https://www.arkoselabs.com/blog/privacy-access-token/> https://www.arkoselabs.com/blog/privacy-access-token/>

< <https://securityboulevard.com/2022/06/privacy-access-token/> https://securityboulevard.com/2022/06/privacy-access-token/>

 

Call for Feedback on ICANN Root Zone Evolution Review Appointment

On behalf of the IETF, the IAB has been asked to name a technical expert to the ICANN Root Zone Evolution Review Committee (RZERC). The RZERC is expected to:

< <https://www.iab.org/2022/06/23/call-for-feedback-on-icann-root-zone-evolution-review-appointment-2/> https://www.iab.org/2022/06/23/call-for-feedback-on-icann-root-zone-evolution-review-appointment-2/>

 

Call for Volunteers for Liaison Manager to ISO/IEC JTC1 SC6

The IAB is currently seeking a new liaison manager to ISO/IEC JTC1 SC6, “Telecommunications and information exchange between systems.” Allison Mankin has served in this role for many years and is looking to step back; the IAB thanks her for her service. The IAB is seeking a volunteer to serve as IETF liaison manager to ISO/IEC JTC1 SC6 to represent IETF views, as required.

< <https://www.iab.org/2022/06/23/call-for-volunteers-for-liaison-manager-to-iso-iec-jtc1-sc6/> https://www.iab.org/2022/06/23/call-for-volunteers-for-liaison-manager-to-iso-iec-jtc1-sc6/>

 

Apple says it’s time your business ran BIMI

... BIMI requires that companies authenticate their email using DMARC. Described by the IETF in more detail in a March 2015 document, DMARC helps mail administrators prevent hackers and other attackers from spoofing their organization and domain. 

< <https://www.computerworld.com/article/3665088/apple-says-its-time-your-business-ran-bimi.html> https://www.computerworld.com/article/3665088/apple-says-its-time-your-business-ran-bimi.html>

 

Apple's iOS 16 will give you an alternative to irritating CAPTCHA tests

... Fortunately, Private Access Tokens (PATs) are not exclusive to Apple hardware. Apple and Google are shaping the authentication standard through the IETF Privacy Pass working group, which suggests it will come to Android at some point. But, PATs also require cooperation from hardware makers and Google hasn't announced its plans for PAT in Android. The working group also includes members from Cloudflare and Fastly.

< <https://www.zdnet.com/article/apples-ios-16-will-give-you-an-alternative-to-irritating-captcha-tests/> https://www.zdnet.com/article/apples-ios-16-will-give-you-an-alternative-to-irritating-captcha-tests/>

 

Apple Offers Alternative to CAPTCHAS in iOS 16 and macOS Ventura

... Private Access Tokens use technology being standardized in the IETF Privacy Pass working group. Apple also worked with Fastly and Cloudflare to support Private Access Tokens, which will be a cross-platform solution.

< <https://www.thurrott.com/apple/268995/apple-captchas-alternative-private-access-tokens-ios-16> https://www.thurrott.com/apple/268995/apple-captchas-alternative-private-access-tokens-ios-16>

 

This New iOS 16 Feature Will Make Annoying CAPTCHAs a Thing of the Past

... Apple’s Automatic Verification is part of a broader Internet Engineering Task Force (IETF) initiative called Privacy Pass. As with other web technologies, Apple isn’t building anything proprietary here. Instead, it’s using its high profile and involvement in the IETF to drive web technologies that are more user-friendly and less privacy-invasive.

< <https://www.idropnews.com/news/this-new-ios-16-feature-will-make-annoying-captchas-a-thing-of-the-past/190002/> https://www.idropnews.com/news/this-new-ios-16-feature-will-make-annoying-captchas-a-thing-of-the-past/190002/>

 

We Don’t Have to Sacrifice Encryption to Achieve Messaging Interoperability

... Perhaps it isn’t a surprise, therefore, that one of the standards organizations, the Internet Engineering Task Force (IETF), has been working on a draft specification that solves one of the big problems at the intersection of encryption and interoperability. Messaging Layer Security (MLS) is a protocol specification that describes how messaging clients can work together to maintain end-to-end encrypted communications.

< <https://www.newamerica.org/oti/blog/we-dont-have-to-sacrifice-encryption-to-achieve-messaging-interoperability/> https://www.newamerica.org/oti/blog/we-dont-have-to-sacrifice-encryption-to-achieve-messaging-interoperability/>

 

A great day for non-robots: iOS 16 will bypass CAPTCHAs

... To achieve this CAPTCHA-free utopia, available in both iOS 16 and macOS, Apple relies on Private Access Tokens, which use technology in the process of being standardized by industry organization Internet Engineering Task Force (IETF).

< <https://www.theregister.com/2022/06/21/believe_it_or_not_apple/> https://www.theregister.com/2022/06/21/believe_it_or_not_apple/>

< <https://www.msn.com/en-us/news/technology/a-great-day-for-non-robots-ios-16-will-bypass-captchas/ar-AAYHjUt> https://www.msn.com/en-us/news/technology/a-great-day-for-non-robots-ios-16-will-bypass-captchas/ar-AAYHjUt>

 

How to skip CAPTCHAs with iOS 16?

... The Private Access Tokens system is with technology standardized by the IETF Privacy Pass working group, meaning other platforms should also be able to implement a system to avoid CAPTCHAs. At the same time, Apple is also working with companies to make this system seamless. Cloudflare and Fastly were two CDNs mentioned during the presentation.

< <https://pocketnow.com/how-skip-captchas-ios-16> https://pocketnow.com/how-skip-captchas-ios-16>

 

Apple iOS 16: "I'm not a robot" on your iPhone is a thing of the past

... It is simply Apple telling the site "Ok, trust me, I scanned his face or I know his Apple ID, he is a good guy". This exchange of requests and token transmission is performed according to a protocol recognized by the IETF (Internet Engineering Task Force, an Internet standardization body).

< <https://www.nextpit.com/apple-ios-16-bypass-captcha-security> https://www.nextpit.com/apple-ios-16-bypass-captcha-security>

 

HESP: Sub-second Latency, Fast Channel Change and Improved ABR over Standard CDNs

... HESP is available as an IETF specification. The HESP standard includes details about, for example, the HESP manifest, the continuation stream and the initialization stream. The advantage is that the HESP continuation stream is CMAF compatible. This means that it’s very easy to handle captions/subtitles, timed metadata and Digital Rights Management (DRM), items which are also included in the HESP IETF specification.

< <https://www.streamingmedia.com/Articles/Editorial/Spotlights/HESP-Sub-second-Latency-Fast-Channel-Change-and-Improved-ABR-over-Standard-CDNs-153579.aspx> https://www.streamingmedia.com/Articles/Editorial/Spotlights/HESP-Sub-second-Latency-Fast-Channel-Change-and-Improved-ABR-over-Standard-CDNs-153579.aspx>

 

Apple iOS 16: Bientôt plus besoin de cocher la case "Je ne suis pas un robot" sur votre iPhone [Apple iOS 16: Soon no need to check the box "I'm not a robot" on your iPhone]

... C'est simplement Apple qui dit au site "Ok, fais-moi confiance, j'ai scanné son visage ou je connais son identifiant Apple, c'est un bon gars". Cet échange de requêtes et de transmission de token se fait selon un protocole reconnu par l'IETF (Internet Engineering Task Force, un organisme de standardisation d'Internet).

< <https://www.nextpit.fr/apple-ios-16-contourner-captcha-iphone> https://www.nextpit.fr/apple-ios-16-contourner-captcha-iphone>

 

Open source : esclave, liste noire… Quand la terminologie pose question [Open source: slave, blacklist... When terminology raises questions]

... L’IETF a sa liste… et ses doutes: Les comptes rendus (2021, 2022) des sessions de l’INI sont publics. Ils laissent entrevoir les débats qui s’y tiennent. Par exemple pour le doublet parent/child. « Attention : parfois, ce sont les parents qui dépendent des enfants », peut-on lire en commentaire. Le tout accompagné d’une alternative : tree/branch ou branch/leaf. On peut aussi constater que le débat terminologique va au-delà des concepts purement logiciels : le cas des connecteurs mâles et femelles est par exemple évoqué.

< <https://www.silicon.fr/esclave-liste-noire-open-source-langage-inclusif-441644.html> https://www.silicon.fr/esclave-liste-noire-open-source-langage-inclusif-441644.html>

 

iOS 16 : la fin des CAPTCHA ? [iOS 16: the end of CAPTCHAs?]

... Bonne nouvelle pour les possesseurs d'appareils Android, les jetons d'accès privés ne seront pas exclusifs au matériel siglé Apple, mais devraient aussi arriver un jour ou l'autre sur les appareils fonctionnant via le système d'exploitation mobile de Google. Le géant américain fait en effet partie du groupe de travail Privacy Pass de l'IETF, à l'origine des normes d'authentification.

< <https://www.zdnet.fr/actualites/ios-16-la-fin-des-captcha-39943750.htm> https://www.zdnet.fr/actualites/ios-16-la-fin-des-captcha-39943750.htm>

 

iOS 16 soll CAPTCHAs lösen: Nie wieder nach Hydranten suchen! [iOS 16 should solve CAPTCHAs: Never look for hydrants again!]

... Es ist lediglich Apple, das der Website sagt: "Okay, vertrau mir, ich habe sein Gesicht gescannt oder ich kenne seine Apple-ID, er ist ein guter Kerl". Dieser Austausch von Anfragen und die Übertragung von Token erfolgt nach einem Protokoll, das von der IETF (Internet Engineering Task Force, einer Standardisierungsorganisation des Internets) anerkannt wird.

< <https://www.nextpit.de/ios-16-captchas-loesen-nie-wieder-zebrastreifen-suchen> https://www.nextpit.de/ios-16-captchas-loesen-nie-wieder-zebrastreifen-suchen>

 

Apple führt mit iOS 16 Alternative zu CAPTCHA-Tests ein [Apple Introduces Alternative to CAPTCHA Testing with iOS 16]

... PATs sind keine exklusiv für Apple-Geräte entwickelte Funktion. An der Entwicklung des Authentifizierungsstandards ist auch Google beteiligt. Darüber hinaus wird aber auch die Unterstützung von Hardware-Anbietern benötigt. Verantwortlich für den Standard ist die IETF Privacy Pass Working Group, der neben Apple und Google auch Cloudflare und Fastly angehören.

< <https://www.silicon.de/41698279/apple-fuehrt-mit-ios-16-alternative-zu-captcha-tests-ein> https://www.silicon.de/41698279/apple-fuehrt-mit-ios-16-alternative-zu-captcha-tests-ein>

 

Wie iOS 16 mit Captchas auf Webseiten und in Apps umgeht [How iOS 16 handles captchas on websites and apps]

... Private Access Tokens basieren auf einem öffentlichen Protokoll von IETF (Internet Engineering Task Force), da in der Arbeitsgruppe neben Apple, Cloudflare und Fastly auch Google-Mitarbeiter teilnehmen, kann man vermuten, dass die Captcha-Umgehung ebenfalls in Android implementiert (wird). 

< <https://www.macwelt.de/news/Wie-iOS-16-mit-Captchas-auf-Webseiten-und-in-Apps-umgeht-11250718.html> https://www.macwelt.de/news/Wie-iOS-16-mit-Captchas-auf-Webseiten-und-in-Apps-umgeht-11250718.html>

 

Apple diz que está na altura de o seu negócio correr BIMI [Apple says it's time for its business to run BIMI]

... O BIMI exige que as empresas autentiquem o seu correio eletrónico utilizando DMARC. Descrito pela IETF com mais detalhe num documento de março de 2015, o DMARC ajuda os administradores de correio eletrónico a evitar que hackers e outros atacantes falsifiquem a sua organização e domínio.

< <https://www.computerworld.com.pt/2022/06/24/apple-diz-que-esta-na-altura-de-o-seu-negocio-correr-bimi/> https://www.computerworld.com.pt/2022/06/24/apple-diz-que-esta-na-altura-de-o-seu-negocio-correr-bimi/>

 

A corrida para salvar a Internet dos hackers quânticos [The race to save the Internet from quantum hackers]

... Mais recentemente, a Internet está se afastando do RSA, que é vulnerável até mesmo aos ataques clássicos – em oposição aos quânticos. Em 2018, a Internet Engineering Task Force (IETF), uma organização virtual baseada em consenso que orienta a adoção de padrões de segurança em escala global, endossou outro sistema de chave pública para substituí-lo. Esse sistema é chamado de criptografia de curva elíptica, porque sua matemática surgiu de um ramo da geometria do século XIX que estuda objetos chamados curvas elípticas.

< <https://cryptoid.com.br/criptografia/a-corrida-para-salvar-a-internet-dos-hackers-quanticos/> https://cryptoid.com.br/criptografia/a-corrida-para-salvar-a-internet-dos-hackers-quanticos/>

 

Institut Sains dan Teknologi Al-Kamal Jakarta Menggelar Pelatihan Etika Berkomunikasi Menggunakan Platform Digital [Al-Kamal Institute of Science and Technology Jakarta Holds Training on Communication Ethics Using Digital Platforms]

... Disisi lain, Cyber Ethics menjadi hal yang penting untuk dikembangkan di berbagai bidang pendidikan, bisnis, layanan pemerintah sehingga memunculkan etika komunikasi yang unik. Salah satu acuan etika dalam berkomunikasi menggunakan Internet berpedoman pada IETF (The Internet Engineering Task Force) yang ditetapkan RFC (Netiquette Guidelies dalam Request for Comments). Akan tetapi acuan ini seringkali bersifat teknis dan hanya dipahami oleh pengguna komputer profesional atau sebagai etika komputer.

< <https://kicaunews.com/2022/06/20/institut-sains-dan-teknologi-al-kamal-jakarta-menggelar-pelatihan-etika-berkomunikasi-menggunakan-platform-digital/> https://kicaunews.com/2022/06/20/institut-sains-dan-teknologi-al-kamal-jakarta-menggelar-pelatihan-etika-berkomunikasi-menggunakan-platform-digital/>

 

日本也在學的唐鳳工作思考術!台灣的人才特質有哪些獨特之處? [Japan is also learning the Tang Feng work thinking technique! What are the unique characteristics of Taiwan's talent?]

... 或許稍微有點偏離一般的工作思考術,但在這個過程中,可以從唐鳳身上學到的重點是「粗略的共識」(rough consensus)和「滾動式修正」(running code)概念,這是一個制定網際網路技術標準規範的團體「IETF」(Internet Engineering Task Force,網際網路工程小組)的思維方式。

< <https://buzzorange.com/techorange/2022/06/21/design-thinking-for-group/> https://buzzorange.com/techorange/2022/06/21/design-thinking-for-group/>

 

中国移动段晓东指明算网一体技术创新路径:收敛场景需求 合力形成统一标准 [Duan Xiaodong of China Mobile pointed out the technological innovation path of the integration of computing and networking: converging on the needs of scenarios and forming a unified standard]

... 中国移动一直高度重视算网一体技术的研究,从2018年开始就投入到了算力网络相关技术研究中,积极推进产学研用协同创新,从技术研究、标准制定到产业合作等多个方面持续推进相关工作。尤其是在2021年中国移动全球合作伙伴大会上,中国移动携手全球合作伙伴共同发布了《算力网络白皮书》,系统性的提出了算力网络的全新发展理念,引发了极大关注;也阐述了算力网络三个发展阶段,即泛在协同、融合统一、一体内生,并联合业界发布了相关倡议,掀起了算力网络发展的新高潮;同时在ITU、IETF、3GPP、CCSA等多个国际和国内标准组织中纷纷布局相关的技术和标准,其核心场景和理念已经得到了国际标准化组织的初步认可,其中算力感知、算力路由的核心技术也得到大家的广泛支持。

< <https://finance.sina.com.cn/tech/2022-06-22/doc-imizmscu8196164.shtml?finpagefr=p_114> https://finance.sina.com.cn/tech/2022-06-22/doc-imizmscu8196164.shtml?finpagefr=p_114>

 

iOS 16内置「机器人」能绕过所有验证码?事实没有那么简单 [Can iOS 16's built-in "bots" bypass all verification codes? The truth is not so simple]

... 首先,技术推广需要一定时间。即使 PAT 是由 IETF、苹果、Google 和 Cloudflare 这样的大机构共同起草、推出的验证协议与标准,但目前只有 iOS 16 和 Cloudflare(防止网站被攻击的云服务商)支持这个验证协议(注:开发者和在线服务目前可以在 Cloudflare 和 Fastly 接入测试版 PAT 验证)。

< <https://36kr.com/p/1796982178988547> https://36kr.com/p/1796982178988547>

 

**********************

SECURITY & PRIVACY

**********************

5 Big Myths about DMARC, Debunked

With email attacks contributing to billions of lost dollars each year, a growing number of organizations are adopting Domain-based Message Authentication, Reporting & Conformance (DMARC) in an effort to protect themselves and their customers from fraudsters. Adoption of DMARC has steadily gained traction since the onset of the pandemic, and the original email authentication protocols at the heart of it continue to prove extremely effective at stopping billions of email attacks from ever reaching their targets.

< <https://www.agari.com/email-security-blog/5-dmarc-myths/> https://www.agari.com/email-security-blog/5-dmarc-myths/>

 

Bolt-On vs Baked-In Cybersecurity

A few weeks ago, the annual RSA Conference met in San Francisco. The conference is among the world’s largest cybersecurity events, and it thus provides a useful opportunity to reflect on current issues in cybersecurity.

< <https://www.lawfareblog.com/bolt-vs-baked-cybersecurity> https://www.lawfareblog.com/bolt-vs-baked-cybersecurity>

 

Cloudflare explains how it managed to break the internet

A large chunk of the web (including your own Vulture Central) fell off the internet this morning as content delivery network Cloudflare suffered a self-inflicted outage.…

< <https://www.theregister.com/2022/06/21/cloudflare_oops/?td=rt-3a> https://www.theregister.com/2022/06/21/cloudflare_oops/?td=rt-3a>

< <https://www.msn.com/en-us/news/technology/cloudflare-explains-how-it-managed-to-break-the-internet/ar-AAYHIEY> https://www.msn.com/en-us/news/technology/cloudflare-explains-how-it-managed-to-break-the-internet/ar-AAYHIEY>

 

us: Tech Stakeholders Help FCC Consider Internet Security

The Federal Communications Commission (FCC) heard from key stakeholders about innovations in Internet security, giving the agency a lot to chew on as it evaluates next steps and its role in the complex Internet ecosystem. Tech companies, network operators, content delivery networks, and others invested in network security should look out for future action by the FCC in this and related areas.

< <https://www.wileyconnect.com/tech-stakeholders-help-fcc-consider-internet-security> https://www.wileyconnect.com/tech-stakeholders-help-fcc-consider-internet-security>

 

**********************

NEW TRANSPORT PROTOCOLS

**********************

QUIC und HTTP/3: Immer mehr Zensur auf Protokollebene [QUIC and HTTP/3: More and more censorship at the protocol level]

Eine aktuelle Untersuchung des Open Observatory of Network Interference (OONI) zeigt: Zensur des Internets auf der Protokollebene von QUIC und HTTP/3 nimmt zu. Das auf UDP aufbauende Protokoll QUIC wurde vergangenes Jahr in Version 1 veröffentlicht – und das neue Webtransportprotokoll HTTP/3 kam erst vor wenigen Wochen im RFC 9114 als Proposed Standard hinzu.

< <https://www.heise.de/news/QUIC-und-HTTP-3-Immer-mehr-Zensur-auf-Protokollebene-7147249.html> https://www.heise.de/news/QUIC-und-HTTP-3-Immer-mehr-Zensur-auf-Protokollebene-7147249.html>

 

Russland blockiert wohl gezielt HTTP/3 und Quic [Russia is likely to block HTTP/3 and Quic]

Das Open Observatory of Network Interference (OONI) hat eine Zusammenfassung der Forschungsarbeiten von Kathrin Elmenhorst zur weltweiten staatlichen Zensur der Protokolle Quic und HTTP/3 veröffentlicht. Demnach gelang es den Beteiligten, noch im März Untersuchungen in Russland durchzuführen, die zeigen, dass in dem Land wohl der gesamte HTTP/3-Netzwerkverkehr blockiert wird.

< <https://www.golem.de/news/zensur-russland-blockiert-wohl-gezielt-http-3-und-quic-2206-166267.html> https://www.golem.de/news/zensur-russland-blockiert-wohl-gezielt-http-3-und-quic-2206-166267.html>

 

Russland blockiert die Protokolle HTTP/3 und Quic [Russia blocks HTTP/3 and Quic protocols]

Die wachsende Nutzung von Quic und HTTP/3 steigen in Russland auch die Bemühungen, diese Protokolle zu blockieren, zeigt eine aktuelle Untersuchung.

< <https://www.webwork-magazin.net/russland-blockiert-die-protokolle-http-3-und-quic/15597> https://www.webwork-magazin.net/russland-blockiert-die-protokolle-http-3-und-quic/15597>

 

Email Authentication für Empfänger [Email Authentication for Recipients]

Email Authentication kombiniert die Methoden von SPF, DKIM und DMARC zu einem Mechanismus mit dem eingehende Nachrichten auf ihre Authentizität geprüft werden können. Mit diesen Methoden wird sichergestellt, dass das versendende System legitimiert ist, für die Envelope Sender Domain zu agieren (SPF), die Identität einer Domain verifiziert (DKIM) und eine Richtlinie (DMARC) festgelegt, wie mit Nachrichten verfahren werden soll, welche SPF und DKIM nicht gerecht werden, sowie um Reports über den aktuellen Status möglichen Identitätsmissbrauchs zu erhalten.

< <https://www.eco.de/news/email-authentication-fuer-empfaenger/> https://www.eco.de/news/email-authentication-fuer-empfaenger/>

 

Snart i mål med nytt transportsystem for internett [Soon to be the target of a new internet transport system]

... Welzl tok i sin tid initiativ til, og har vært sentral i TAPS (Transport Services), en gruppe i standardiseringsorganisasjonen IETF, som har jobbet med å utvikle API-en.

< <https://titan.uio.no/teknologi-informatikk/2022/snart-i-mal-med-nytt-transportsystem-internett> https://titan.uio.no/teknologi-informatikk/2022/snart-i-mal-med-nytt-transportsystem-internett>

 

**********************

OTHERWISE NOTEWORTHY

**********************

Web inventor Tim Berners-Lee: Screw Web3 — my decentralized internet doesn’t need blockchain

Web inventor Tim Berners-Lee wants to rescue his creation from centralization. But does he align himself with Web3’s promise of salvation?

< <https://thenextweb.com/news/web-inventor-tim-berners-lee-screw-web3-my-decentralized-internet-doesnt-need-blockchain> https://thenextweb.com/news/web-inventor-tim-berners-lee-screw-web3-my-decentralized-internet-doesnt-need-blockchain>

 

Ferret: Automatically finding RFC compliance bugs in DNS nameservers

The DNS is the glue that holds the Internet together by providing the essential mapping from names to IP addresses. However, over time, the DNS has evolved into a complex and intricate protocol, spread across numerous RFCs. This has made it difficult to write efficient, high-throughput, multithreaded implementations that are bug-free and compliant with RFC specifications.

< <https://blog.apnic.net/2022/06/24/ferret-automatically-finding-rfc-compliance-bugs-in-dns-nameservers/> https://blog.apnic.net/2022/06/24/ferret-automatically-finding-rfc-compliance-bugs-in-dns-nameservers/>

 

Why the saga of IPv6 may never end

In this episode of PING, APNIC’s Chief Scientist, Geoff Huston joins us to discuss IPv6 — a topic he has investigated exhaustively over the last 30 years. Specifically, we’re talking about the seemingly never-ending transition to IPv6, the hallmarks it shares with previous IP transitions, how Network Address Translation (NAT) has hindered its deployment for the good and bad of the Internet, and whether 100% IPv6 is even the end goal given how far technology has come since IP addresses were first implemented.

< <https://blog.apnic.net/2022/06/23/podcast-why-the-saga-of-ipv6-may-never-end/> https://blog.apnic.net/2022/06/23/podcast-why-the-saga-of-ipv6-may-never-end/>

 

Surviving the flood — how data centres and the Internet must face climate change

A rather depressing, but sobering, piece of writing came up in my feed this week: Programming in the Apocalypse by Matthew Duggan. The premise of this blog post is climate change, specifically human-made climate change, and it focuses on ’what’s the impact in our sector’.

< <https://blog.apnic.net/2022/06/23/surviving-the-flood-how-data-centres-and-the-internet-must-face-climate-change/> https://blog.apnic.net/2022/06/23/surviving-the-flood-how-data-centres-and-the-internet-must-face-climate-change/>

 

Nanoparticles that control flow of light could mean faster and cheaper internet

Imagine a window with an image etched on its surface, but when you walk around to the other side, the image is entirely different. Though it sounds impossible, that's essentially what researchers from the Australian National University (ANU) have achieved, with tiny translucent slides that can show two distinct images, at the same time, when viewed from opposite sides.

< <https://www.abc.net.au/news/science/2022-06-21/nanoparticles-that-control-flow-of-light-for-faster-internet/101166750> https://www.abc.net.au/news/science/2022-06-21/nanoparticles-that-control-flow-of-light-for-faster-internet/101166750>

 

W3C joins leading standards organizations and companies to coordinate interoperability standards for an open and inclusive metaverse

The Metaverse Standards Forum launched on June 21, 2022, of which the Web Consortium is a founding member, among other key actors whose focus is on leading platforms, hardware, tools, engines, users. The forum, whose membership is free, and open to any organization, brings together leading standards organizations and companies for industry-wide cooperation on interoperability standards needed to build an open and inclusive metaverse.

< <https://www.w3.org/blog/news/archives/9584> https://www.w3.org/blog/news/archives/9584>

 

NVIDIA Joins Forum to Help Lay the Foundation of the Metaverse

The metaverse is the next big step in the evolution of the internet — the 3D web — which presents a major opportunity for every industry from entertainment to automotive to manufacturing, robotics and beyond. That’s why NVIDIA is joining our partners in the Metaverse Standards Forum, an open venue for all interested parties to discuss and debate how best to build the foundations of the metaverse.

< <https://blogs.nvidia.com/blog/2022/06/21/metaverse-standards-forum/> https://blogs.nvidia.com/blog/2022/06/21/metaverse-standards-forum/>

------

David Goldstein

email:  <mailto:david@goldsteinreport.com> david@goldsteinreport.com

web:  <http://goldsteinreport.com/> http://goldsteinreport.com/

Twitter:  <https://twitter.com/goldsteinreport> https://twitter.com/goldsteinreport

phone: +61 418 228 605 - mobile; +61 2 9663 3430 - office/home