snikket_im,
@snikket_im@fosstodon.org avatar

We've published a new blog post about the recent jabber.ru security incident (a kind of attack we have not seen before). It did not affect Snikket servers, but we are taking steps to remove the possibility of such attacks in the future. This includes advice that self-hosters can follow.

https://snikket.org/blog/on-the-jabber-ru-mitm/

nogweii,
@nogweii@nogweii.net avatar

@snikket_im very curious as to what you decide to do about CRT monitoring. Please share what tooling you end up using/developing, even if its something off-the-shelf!

jabberati,
@jabberati@social.anoxinon.de avatar

deleted_by_author

  • Loading...
  • snikket_im,
    @snikket_im@fosstodon.org avatar

    @jabberati
    Thanks! The problem is that we have hundreds of domains on our service, and so we really need something that can identify rogue certificates without drowning us in notifications about all the legitimate ones. That's apparently a bit harder...

    kkarhan,
    @kkarhan@mstdn.social avatar

    @snikket_im thanks for this vital info.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • InstantRegret
  • GTA5RPClips
  • magazineikmin
  • mdbf
  • rosin
  • Youngstown
  • khanakhh
  • everett
  • slotface
  • thenastyranch
  • osvaldo12
  • kavyap
  • ngwrru68w68
  • JUstTest
  • ethstaker
  • modclub
  • cubers
  • cisconetworking
  • Durango
  • tacticalgear
  • tester
  • normalnudes
  • Leos
  • megavids
  • provamag3
  • anitta
  • lostlight
  • All magazines