Home avatar

Welcome to the Internet homepage of Adam Stasiniewicz.

PGP key: 3270d15169357d8177ec914ef51948c9db5b8297
iMessage CKV: APKTIDrc33iKNWyFiGmUG5Sai-3UCAMR4RpfehUIC5Pl7DdQF-eQ
Opinions/views/etc are my own.

Please Use DNSSEC

The other day I was reading about yet another DNS vulnerability. Vulnerabilities in DNS have been well known since 2008, and since 2010 we’ve had an excellent solution, DNSSEC. DNSSEC addresses many of the most common DNS vulnerabilities on the internet today (including this most recent vulnerability). For most, setup is very simple. Unfortunately, DNSSEC is an opt-in technology. So, it’s a good time to remind all my Internet friends that today’s a good day to double-check if you have DNSSEC enabled, and if you don’t, to make plans to enable it.

Infineon / YubiKey Cloning Vulnerability

Original Ars Technica Story

This is, unfortunately, a big deal. Not just for the users of YubiKeys, but also for anything using Infineon crypto chips. Infineon makes the crypto chips in a ton of devices, including TPMs, smart cards, passports, credit cards, and SIM cards. I suspect there will be more fallout from this, as additional devices are found to be using the same cryptographic library.

There are two important mitigations: