Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Ondřej Surý

@ondrej@mastodon.rfc1925.org
mastodon 4.7.3
  • Open on mastodon.rfc1925.org

Speaker for the Dead Code, raging feminist, DNS Artist, tooth-fairy agnostic, male ally, skipper, my opinions are my own, not perfect, he/him/his

1109 Followers
275 Following
17 Posts
Joined November 19, 2022
GitHub:
https://github.com/oerdnj
BIND 9 GitLab:
http://gitlab.isc.org/isc-projects/bind9
Gravatar:
https://gravatar.com/oerdnj
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 10mo ago

Repeat after me: Separating username and password fields on separate (fucking responsive) page WILL NOT INCREASE A FUCKING SECURITY IN ANY WAY! IT WILL JUST MAKE THE PASSWORD MANAGERS TO WORK WORSE AND THUS IT WILL FUCKING DECREASE THE SECURITY!!!

779
47
443
1
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 10mo ago

Hey U.S., I’ll make it easy for you. Fuck U.S.A., fuck ICE, fuck Donald Trump and fuck all the Nazis in the current government (you fucking pricks know who you are).

https://www.nytimes.com/2025/12/09/travel/social-media-tourists-visa-border-patrol.html

U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
nytimes.com

U.S. Plans to Scrutinize Foreign Tourists’ Social Media History

Even visitors from countries like Britain and France, whose citizens don’t need visas, would have to share five years’ worth of social media.

21
1
6
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 8mo ago

RE: @briankrebs@infosec.exchange

So, how’s the IETF in San Francisco looking now?

infosec.exchange

BrianKrebs: "We knew this was coming, but now the clock is run…" - Infosec Exchange

15
2
10
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 12mo ago

Enshittification commences in 1…2…3

https://www.qualcomm.com/news/releases/2025/10/qualcomm-to-acquire-arduino-accelerating-developers--access-to-i

qualcomm.com

Qualcomm to Acquire Arduino—Accelerating Developers’ Access to its Leading Edge Computing and AI | Qualcomm

18
1
13
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 35mo ago

(The application is now closed for new applicants, sorry.)

I’m hiring a software engineer for BIND 9. All you need is to speak English, program in any procedural or object-oriented language, be willing to learn technologies we use (C17), be a nice person and be brave to apply!

https://isc.recruitee.com/o/bind-9-software-engineer-2

isc.recruitee.com
86
10
154
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 17mo ago

Microstory: Imagine living in a world where it would be okayish and safe to go in China for IETF and absolutely not ok and unsafe to go into US. Oh wait… @letoams@defcon.social

defcon.social

Paul Wouters 🇪🇺🇨🇦: "IETF-125 will be in Shenzen, China https://mailar…" - DEF CON Social

24
0
16
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 29mo ago

They are just laughing straight to our faces…

47
8
20
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 10mo ago

Anyone from FreeBSD project to who I can speak about jemalloc project?

6
3
13
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 29mo ago

So, here they are… the new “keys to the Internet”!

36
1
17
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 32mo ago

X41 did a security audit of BIND 9 last year, and this is kind of reassuring to hear from external security experts:

> While vulnerabilities were found during this audit, the code has been hardened and could serve as an example on how to develop C code with security in mind.

https://x41-dsec.de/news/security/research/source-code-audit/2024/02/13/bind9-security-audit/

I can obviously name 20+ things that could be improved immediately, but still this is nice…

X41 Source Code Audit of ISC BIND 9
X41 D-Sec - Penetration Tests and Source Code Audits

X41 Source Code Audit of ISC BIND 9

X41 releases the code audit report of BIND 9

37
2
18
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 32mo ago

Also hug your #DNS recursive resolver #Developers, they needed it for past couple of weeks and they couldn’t tell anyone.

#DNSSEC #KeyTrap @rysiek@mstdn.social

mstdn.social

Michał "rysiek" Woźniak · 🇺🇦: "Hug your #DNS recursive resolver #SysAdmin over t…" - Mastodon 🐘

36
1
19
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 31mo ago

Kids, don’t do drugs! Also never implement your own DateTime arithmetics… this is how 30 minutes of free parking looked like this morning here ;)

32
2
12
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 36mo ago

This is such a shitshow :-(, just my computer:
* Termius - Electron/21.4.4
* Mattermost - Electron/26.1.0
* Podman Desktop - Electron/25.2.0
* balenaEtcher, WhatsApp - Electron/13.6.9
* AdGuard for Safari - Electron/18.3.15
* Microsoft Teams - Electron/19.1.8

Special kudos go to:
* Dropbox - Electron/13.1.0-dropbox.20221010.faa890d59 - VULNERABLE, WHAT THE FUCK? MY EYES BLEED @TomSellers@infosec.exchange

infosec.exchange
39
3
28
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 33mo ago

This is exactly the reason why we don’t plan to have bug bounties for BIND 9. We have enough issues to go through even without LLM generated bullshit…

Also we are thankful for all the solid security researchers finding issues in DNS servers even if that’s often very inconvenient ;). @bagder@mastodon.social

mastodon.social

daniel:// stenberg://: ""Buffer Overflow Vulnerability in WebSocket Handl…" - Mastodon

31
1
16
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 40mo ago

Infamous Dear Anonymous User from @bert_hubert@fosstodon.org is asking for help in https://gitlab.isc.org/isc-projects/bind9/-/issues/4107 with BIND 9.4.1 (released in 2007) in a proprietary telco stuff, but reporting it against BIND 9.18.15 because “the lines are same”.

Now, I’ve seen everything and I can finally retire from DNS.

gitlab.isc.org
24
2
15
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 32mo ago

Hey all, ISC is hiring a support engineer! This is not my team, but you will work closely with my team acting as a much appreciated bridge between the customers and the software engineers.

https://isc.recruitee.com/o/support-engineer-for-isc-bind-and-kea-dhcp-2

My personal note: We are looking for a genuine answers. Honest “I don’t know, but I am willing to learn” is much better than AI generated answers, so don’t be afraid to apply.

isc.recruitee.com
10
1
24
0
Open post
Ondřej Surý @ondrej@mastodon.rfc1925.org
· 5mo ago
Replying to
@malwareminigun @michiel This is fallacy as well. The existing (pre-AI) tools (gcc itsefl, clang itself, AddressSanitizer, ThreadSanitizer, clang-analyzer and others) were already excellent of catching most of the memory bugs. Sure, you can ignore this and produce insecure code, but it has nothing to do with the language. Sure, having ownership (and reference counting) in the language would help, but any well-maintained code will end up in a state where most of the CVEs are logical errors.
0
3
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:16:22 UTC