I also don't find it on the site of "Klaus Schmeh" that it claims to be on a list of "Top 50 unsolved encrypted messages": https://klausschmeh.net/?s=Cyphral
> That points to a glaring hole in the modern-day automated web PKI, not Tesla's dangling DNS record.
It's not. They control a long-term high-value asset (the domain tesla.com). They decided to delegate part of that asset to a large number of "random" people that they do not have a contract or agreement with.
Being able to issue certs for cloud IPs has nothing to do with this since it is not a long term asset, and if it is you probably don't delegate it to random people to control unless you do not value that asset.
If you are going to make recommendations and promote them to a wide community (linux users) that is predominantly using something that you do not consider advisable for that recommendation (systemd) then it might be good to mention that.
Systemd is probably on 80%+ linux systems that people interact with, and 95%+ that people manually configure.
Usually you can't freeze the whole system UI with an infinite counter though. I'm pretty sure normal JS browser processes are not supposed to be able to do that.
It was bought, but after the renaming. Today IBM only build Servers. Mainframes. All other PC, Laptop and Server Production/Branding is sold.
IBM rebranded mainly to IBM iX. A full service agency.
Hardware is now Mainframes. And other deviations are mostly Cloud, OpenShift, Ansible, and RHEL.
> That's why Xbox, PlayStation, Switch all run on a custom silicon and not an ordinary chips!
Not really. Xbox and PlayStation both run on pretty standard AMD Zen 2 chips. Somewhat customized, but standard enough that people by binned playstation 5 motherboards to use as computers with normal OS'es (lookup BC-250). The last gen with more customized chips was the PS3/Xbox360 era, when both went with a variant of PowerPC, same as Gamecube/Wii/WiiU.
Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
I think you should listen to bringup of Linux on Playstation talk from CCC to understand that those platforms are much more than just "somewhat customized".
There are whole sections of peripheral chips missing and they behave quite a bit differently with how they bootstrap and where things are mapped in memory.
The steam decks APU was designed for Magic Leap 2. It is one of the worst examples you could choose for a chip specifically designed for the thing it is in.
>but standard enough that people by binned playstation 5 motherboards to use as computers
That doesn't mean that all the features are enabled right from the factory, or that the compatibility with already existing features is lost.
Modern chip's security features are pretty complicated and include hardware patches, hardware debug authentication, multiple provisioning states (and multi-key hierarchy for that), RMA states to clear all the private information, etc.
>Switch runs on basically the same Nvidia Tegra CPU/GPU as multiple android tablets.
Yes, and the one which got cracked with a bootrom vulnerability ;)
That's a pretty working motivation for a chip company to improve their chip security when the company as beefy as Nintendo tells them that their chip is vulnerable they're losing money because the customers can play for free ;). I'm pretty sure patchable bootroms started to be common only after Switch hack.
I know about the public suffix list - I was wondering about the wildcard specifically. In the very issue you linked to, as of 2025, it seems this was still unresolved...:
> We have no plans to modify the .name entries at this point in time. We are aware of the implications of adding a wildcard, therefore we won't.
Yeah, apparently they both (used to) offer unbounded registrations of 3LDs and unbounded registrations of 2LDs? So if I see j.doe.name, the only way to find out if "doe.name" is a public suffix or not, i.e. if I should (not) be able to set a cookie on it, would be to email the registrar?
So does that mean that in practice, .name domains were always treated by browsers like regular 2LDs, meaning the cookie and origin protection was always broken for those domains?
Doesn't sound like good news for the guy in the OP...
I'm just saying that they have discussed the situation. They seem to have no answer and for cookies and similar things the answer probably is "maybe don't run security critical web stuff in the third level under .name".
IIRC orgs like letsencrypt also use the PSL for rate limits, so there are probably more issues that are not browser-based.
There end up being some weird edge cases where there are some countries which have both the equivalent of .co.uk but also allow registrations directly under the two-letter country code as well. .mx is one such case where most business are, e.g., costco.com.mx, but it’s also possible to register directly under .mx as well so Toyota Mexico is toyota.mx and not toyota.com.mx (the latter is registered, and ostensibly to Toyota, but the whois and nslookup records give very different results and the website doesn’t load when I try to visit it).
This isn't so bad as .com.mx and .mx should be on the public suffix list then.
But letting arbitrary customers take arbitrary 3 level domains, and others take 2 level domains, seems like a mistake as it's not very reasonable for every 3LD customer to put the 2LD on the public suffix list, but mixing 3LD and 2LD registrations means you can't public suffix *.name.
Seems the whole idea of having both was always misguided.
The .us domain should’ve been universally useful for state and municipal governments, but most of those began registering directly under .gov, and not even in an orderly hierarchy under .st.gov
But that was simply the easiest way to market your website as a trusted government entity. And now nobody has ever heard of .us domains in active use.
.us was primarily a hierarchy structure which in practice made confusing and hard to remember domain names, whereas .gov addresses hand out single domains which are generally easy to remember.
Personally, I never saw anything confusing about city.state.us; the hierarchy was organized perfectly logically in the 3-tier jurisdictional structure that every American schoolboy knows by 3rd grade.
But your point about them being rather longer and difficult to remember stands, and the same for a .gov, which could be shorter and catchier.
However amusingly, .us opened up second-level registrations 24 years ago, which means that any qualifying entity could have their name registered directly under .us, which is obviously recognizable, and also one character shorter, than a .gov registration. However, by that time, I believe that .gov had increased in stature so that registering governmental entities under .gov carried more certainty of conveying official status than anything under .us.
Also sadly, QR Codes and URL shorteners today sort of obviate the need to directly register the shortest possible domain name. I don't know: I was always kind of fond of the .us hierarchy, and I'm just personally sad that it's fading away.
City/state/US is logical, the problem is most other hierarchies confuse people. For instance k12 subdomains for schools couldn't use that nomenclature because school districts do not map cleanly to towns. And that's before you talk about fire departments, townships, libraries, park districts, and countless other governmental bodies and districts which have overlapping boundaries of their own.
.gov certainly cares a level of exclusionary access that isn't really true of .us. Only one entity, the US federal government, can decide to hand someone a .gov address. And generally there is few signals harder to fake or impersonate than one.
It’s not something anyone else in the world seems to struggle with, where there are *.gov.uk, *.edu.au etc.
If anything the .gov, .mil and .edu being just American is confusing, as well plainly inappropriate (it feels like an American cultural imperialist thing to people from outside the US). It would have been much better if those had been retired decades ago and moved to under the .us TLD, so e.g. whatever.edu would become whatever.edu.us like every other country. Any existing domains on .gov, .mil, .edu etc. should only be allowed to exist as 301 redirects.
It's imperialist to own and control the thing you created?
If .gov had been an international TLD that was at some point available to everyone, or had been created by everyone, ok. But .gov was created as part of the work the US government did to build out the initial DNS structure. It probably wasn't even a given at the time that arpanet would be international in nature
Also, 301 redirects are not a DNS thing, that is an HTTP thing. Not sure how that would solve your problem since HTTP is intrinsically at the base of it tied to just A or AAAA records. DNS does a lot more than pointing to websites
It used to be that only Japanese corporations could register a .co.jp while anyone else anywhere could register for a .jp. So I had several .jp domains registered through Gandi.net.
The issue is that .jp registered outside of a few Japanese registrars are legally not allowed to offer Whois privacy.
Based on my small sample of schools, all of the ones that were using locality based names under ca.us have migrated elsewhere, including to 2nd level domains under .us.
reply