<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gpoul&#039;s Out Of Memory Blog &#187; Networks</title>
	<atom:link href="http://gpoul.strain.at/category/networks/feed/" rel="self" type="application/rss+xml" />
	<link>http://gpoul.strain.at</link>
	<description>The postings on this site are my own and don’t necessarily represent IBM’s positions, strategies, or opinions.</description>
	<lastBuildDate>Wed, 01 Feb 2012 18:22:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Firefox 10 ESR Released</title>
		<link>http://gpoul.strain.at/2012/02/01/firefox-10-esr-released/</link>
		<comments>http://gpoul.strain.at/2012/02/01/firefox-10-esr-released/#comments</comments>
		<pubDate>Wed, 01 Feb 2012 18:19:18 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=1275</guid>
		<description><![CDATA[Earlier today the Mozilla project released the first Extended Support Release (ESR) of Firefox. The ESR is based on Firefox 10, which was also released today. If you wanted a Firefox version that&#8217;s not updating all the time, but is stable to use and gets security updates for at least a year, you might want [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier today the Mozilla project released the first Extended Support Release (ESR) of Firefox. The ESR is based on Firefox 10, which was also released today. If you wanted a Firefox version that&#8217;s not updating all the time, but is stable to use and gets security updates for at least a year, you might want to check out the <a href="http://www.mozilla.org/en-US/firefox/organizations/faq/">Firefox ESR FAQ</a>, which also contains the download links, and give it a try.</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2012/02/01/firefox-10-esr-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Firefox Rapid Release Process</title>
		<link>http://gpoul.strain.at/2011/06/25/new-firefox-rapid-release-process/</link>
		<comments>http://gpoul.strain.at/2011/06/25/new-firefox-rapid-release-process/#comments</comments>
		<pubDate>Sat, 25 Jun 2011 08:35:39 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=1190</guid>
		<description><![CDATA[Not sure how many of you have already upgraded to Firefox 5, but you&#8217;ll probably have heard about Firefox moving to a rapid release process. They basically want to increment their version number every 6 weeks. Initially I thought this was a good thing, because who really cares about version numbers? After reading a bit [...]]]></description>
			<content:encoded><![CDATA[<p>Not sure how many of you have already upgraded to Firefox 5, but you&#8217;ll probably have heard about Firefox moving to a rapid release process. They basically want to increment their version number every 6 weeks. Initially I thought this was a good thing, because who really cares about version numbers?</p>
<p>After reading a bit more about this on various blogs I now realize that this change might have a negative <a href="http://mike.kaply.com/2011/06/23/understanding-the-corporate-impact/">impact on corporate deployments</a> due to the fact that Firefox will discontinue security patches for those old versions, which makes compatibility testing and large-scale roll-outs a real hassle.</p>
<p>A member of the IE team, Ari Bixhorn, wrote on his blog that <a href="http://bixhorn.com/?p=153">Microsoft offers a long-term support strategy for their browser</a>. As much as I would hate going back to IE, because it would mean platform dependency, but is Microsoft now becoming the sane option? I hope Firefox will reconsider and change their release process. For a company to maintain their own Firefox fork is just not really a sustainable &#8211; or financially sane &#8211; proposition.</p>
<p><strong>Update 6/30:</strong> <a href="http://blog.mozilla.com/blog/2011/06/28/firefox-in-the-enterprise/">Mozilla starts to think about how to support Enterprises</a>.</p>
<p><strong>Update 1/14/2012:</strong> <a href="http://blog.mozilla.com/blog/2012/01/10/delivering-a-mozilla-firefox-extended-support-release/">Mozilla announces that it plans to make Firefox 10 the base for an Extended Support Release targeted at corporate users</a>.</p>
<p><strong>Update 2/1/2012:</strong> Firefox released its <a href="/2012/02/01/firefox-10-esr-released/" title="Firefox 10 ESR Released">first Extended Support Release</a> (ESR) today.</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2011/06/25/new-firefox-rapid-release-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Future Rests with IPv6</title>
		<link>http://gpoul.strain.at/2011/02/06/the-future-rests-with-ipv6/</link>
		<comments>http://gpoul.strain.at/2011/02/06/the-future-rests-with-ipv6/#comments</comments>
		<pubDate>Sun, 06 Feb 2011 17:04:32 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=1109</guid>
		<description><![CDATA[February 3, 2011: &#8220;A critical point in the history of the Internet was reached today with the allocation of the last remaining IPv4 (Internet Protocol version 4) Internet addresses from a central pool. It means the future expansion of the Internet is now dependant on the successful global deployment of the next generation of Internet [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>February 3, 2011: <em>&#8220;A critical point in the history of the Internet was reached today with the allocation of the last remaining IPv4 (Internet Protocol version 4) Internet addresses from a central pool. It means the future expansion of the Internet is now dependant on the successful global deployment of the next generation of Internet protocol, called IPv6.&#8221;</em> &#8211; <a href="http://www.icann.org/en/news/releases/release-03feb11-en.pdf">Available Pool of Unallocated IPv4 Internet Addresses Now Completely Emptied</a></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2011/02/06/the-future-rests-with-ipv6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fun with the cookie jar</title>
		<link>http://gpoul.strain.at/2010/11/01/fun-with-the-cookie-jar/</link>
		<comments>http://gpoul.strain.at/2010/11/01/fun-with-the-cookie-jar/#comments</comments>
		<pubDate>Mon, 01 Nov 2010 09:36:54 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=1069</guid>
		<description><![CDATA[Anyone who worked with web applications, dealt with web security, or single sign-on will certainly have learned that HTTP cookies, while a simple concept, have many complex intricate behaviors that even differ between browser implementations. What&#8217;s making things worse is that there is no real written specification that documents the design behavior. In his recent [...]]]></description>
			<content:encoded><![CDATA[<p>Anyone who worked with web applications, dealt with web security, or single sign-on will certainly have learned that HTTP cookies, while a simple concept, have many complex intricate behaviors that even differ between browser implementations. What&#8217;s making things worse is that there is no real written specification that documents the design behavior. In his recent post on <a href="http://lcamtuf.blogspot.com/2010/10/http-cookies-or-how-not-to-design.html">HTTP cookies and protocol design</a> Michal Zalewski outlines many of these intricacies and design behaviors and I&#8217;m sure you&#8217;ll learn about a few you haven&#8217;t seen before ;-)</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2010/11/01/fun-with-the-cookie-jar/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Public DNS</title>
		<link>http://gpoul.strain.at/2009/12/06/google-public-dns/</link>
		<comments>http://gpoul.strain.at/2009/12/06/google-public-dns/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 13:02:25 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=842</guid>
		<description><![CDATA[Google announced Google Public DNS a few days ago. I don&#8217;t really understand why I&#8217;d want to use it or why this project is a good idea for Google, but now we have one more DNS server for testing purposes that has an IP address that is easy to remember :-)]]></description>
			<content:encoded><![CDATA[<p>Google announced <a href="http://code.google.com/speed/public-dns/docs/intro.html">Google Public DNS</a> a few days ago.</p>
<p>I don&#8217;t really understand why I&#8217;d want to use it or why this project is a good idea for Google, but now we have one more DNS server for testing purposes that has an IP address that is easy to remember :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2009/12/06/google-public-dns/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Networking fun</title>
		<link>http://gpoul.strain.at/2009/11/12/networking-fun/</link>
		<comments>http://gpoul.strain.at/2009/11/12/networking-fun/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 21:34:33 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=819</guid>
		<description><![CDATA[For the last week we were only getting 4Mb/s to one of our test servers, which was actually supposed to have 100Mb/s rates. Transferring installation media is really a lot of fun that way. After hoping for the last week that the problem would go away on its own, we finally came to the conclusion [...]]]></description>
			<content:encoded><![CDATA[<p>For the last week we were only getting 4Mb/s to one of our test servers, which was actually supposed to have 100Mb/s rates. Transferring installation media is really a lot of fun that way. After hoping for the last week that the problem would go away on its own, we finally came to the conclusion that this is probably not going to happen any time soon.</p>
<p>So we played with a whole bunch of cables, two switches, one p5 550 with VIO, and a T61p, until we figured out what&#8217;s wrong. It just took us a whole day to figure it out, but it feels good that we did.</p>
<p>The root-cause was that auto-negotiation was disabled on the ethernet interface. Usually this is a good thing. This time it was not. Go figure.</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2009/11/12/networking-fun/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Craziest Data Center Ever</title>
		<link>http://gpoul.strain.at/2008/12/09/craziest-data-center-ever/</link>
		<comments>http://gpoul.strain.at/2008/12/09/craziest-data-center-ever/#comments</comments>
		<pubDate>Tue, 09 Dec 2008 18:38:02 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=383</guid>
		<description><![CDATA[I&#8217;ve seen quite a few data centers. I don&#8217;t really like them most of the time, but some of them might arguably look cool. &#8211; But the data center built by Stockholm ISP Bahnhof is just insane. If photos are not enough for you, you can get more details in an article written about the [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve seen quite a few data centers. I don&#8217;t really like them most of the time, but some of them might arguably look cool. &#8211; But the <a href="http://www.bahnhof.se/pionen/gallery/">data center</a> built by Stockholm ISP <a href="http://www.bahnhof.se">Bahnhof</a> is just <em>insane</em>.</p>
<p>If <a href="http://www.bahnhof.se/pionen/gallery/">photos</a> are not enough for you, you can get more details in an <a href="http://royal.pingdom.com/2008/11/14/the-worlds-most-super-designed-data-center-fit-for-a-james-bond-villain/">article</a> written about the data center. [via <a href="http://mbaierl.com/blog/2008/12/worlds-coolest-data-center.html">mbaierl.com</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2008/12/09/craziest-data-center-ever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon CDN</title>
		<link>http://gpoul.strain.at/2008/09/29/amazon-cdn/</link>
		<comments>http://gpoul.strain.at/2008/09/29/amazon-cdn/#comments</comments>
		<pubDate>Mon, 29 Sep 2008 16:51:55 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=329</guid>
		<description><![CDATA[Looks like Amazon will launch a CDN-like offering in the (near?) future. I guess we&#8217;ll have to wait a bit to find out if this is really something that can compete with companies like Akamai or not. For everyone who&#8217;s not seriously considering a CDN today an Amazon CDN will not be particularly interesting, because [...]]]></description>
			<content:encoded><![CDATA[<p>Looks like <a href="http://aws.typepad.com/aws/2008/09/were-never-cont.html">Amazon will launch a CDN-like offering</a> in the (near?) future. I guess we&#8217;ll have to wait a bit to find out if this is really something that can compete with companies like <a href="http://www.akamai.com">Akamai</a> or not. For everyone who&#8217;s not seriously considering a CDN today an Amazon CDN will not be particularly interesting, because why would you use it instead of S3?</p>
<p><strong>Update 11/26:</strong> The new CDN launched recently and it&#8217;s called <a href="http://aws.typepad.com/aws/2008/11/distribute-your-content-with-amazon-cloudfront.html">CloudFront</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2008/09/29/amazon-cdn/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>BGP MITM Vulnerability</title>
		<link>http://gpoul.strain.at/2008/08/31/bgp-mitm-vulnerability/</link>
		<comments>http://gpoul.strain.at/2008/08/31/bgp-mitm-vulnerability/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 17:02:37 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=306</guid>
		<description><![CDATA[I&#8217;m not sure this whole BGP MITM vulnerability hasn&#8217;t been blown way out of proportion. A few more details than mentioned in the articles can be found in the defcon presentation. [via arstechnica] The whole point for the Internet is for communication to work and as mentioned in the article someone who redirects even a [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m not sure this whole <a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">BGP MITM vulnerability</a> hasn&#8217;t been blown way out of proportion. A few more details than mentioned in the articles can be found in the <a href="https://www.defcon.org/images/defcon-16/dc16-presentations/defcon-16-pilosov-kapela.pdf">defcon presentation</a>. [via <a href="http://arstechnica.com/news.ars/post/20080827-inherent-security-flaw-poses-risk-to-internet-users.html">arstechnica</a>]</p>
<p>The whole point for the Internet is for communication to work and as mentioned in the article someone who redirects even a portion of the Internet traffic, even for a small prefix, is crazy to begin with. Not only because it will be noticed but more likely because you&#8217;re duplicating traffic because you need to resend the outbound packets for people not to notice that you&#8217;re intercepting traffic.</p>
<p>We&#8217;ve told people for years that their data on the Internet, if unencrypted, is not safe and never will be. The Internet is a dumb network and it will stay that way. I just can&#8217;t imagine each router validating a cryptographic signature on a BGP announcement for each AS in the AS-path. How should that work? It would be interesting to measure the impact that would have on the processor time required.</p>
<p>It&#8217;s also interesting to think about the trust-chain and information that would be required to not only know if an announcement really originated in a given AS but also if that AS is authorized to announce that network.</p>
<p>If people are not able to configure BGP filtering correctly how do we think they&#8217;re going to be able to deploy any cryptographic solution correctly to even get it to work on a global level? &#8211; Not to mention that certificates will expire and need to be replaced.</p>
<p>btw: this has also been blogged about by <a href="http://www.schneier.com/blog/archives/2008/08/border_gateway.html">Bruce Schneier</a> and <a href="http://www.doxpara.com/?p=1231">Dan Kaminsky</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2008/08/31/bgp-mitm-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNS trouble at the NSA</title>
		<link>http://gpoul.strain.at/2008/05/17/dns-trouble-at-the-nsa/</link>
		<comments>http://gpoul.strain.at/2008/05/17/dns-trouble-at-the-nsa/#comments</comments>
		<pubDate>Sat, 17 May 2008 11:29:39 +0000</pubDate>
		<dc:creator>gpoul</dc:creator>
				<category><![CDATA[Networks]]></category>

		<guid isPermaLink="false">http://gpoul.strain.at/?p=254</guid>
		<description><![CDATA[Looks like the NSA had some DNS troubles recently. I didn&#8217;t know that this also happened to YouTube; I read in IPJ that there was a YouTube problem related to a BGP announcement, but maybe that&#8217;s a different incident. I don&#8217;t really get why the article states that it&#8217;s embarrassing for the NSA. &#8211; After [...]]]></description>
			<content:encoded><![CDATA[<p>Looks like the <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9085940">NSA had some DNS troubles recently</a>. I didn&#8217;t know that this also happened to YouTube; I read in IPJ that there was a <a href="http://www.ripe.net/news/study-youtube-hijacking.html">YouTube problem related to a BGP announcement</a>, but maybe that&#8217;s a different incident.</p>
<p>I don&#8217;t really get why the article states that it&#8217;s embarrassing for the NSA. &#8211; After all the most secure server is one that is offline and I hope not too much critical business at the NSA is done using e-mail over the Internet, but it might be annoying to call the next pizza place instead of ordering it online ;-)</p>
]]></content:encoded>
			<wfw:commentRss>http://gpoul.strain.at/2008/05/17/dns-trouble-at-the-nsa/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

