• 0 Posts
  • 32 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle


  • I’m not sure I necessarily agree. Your assessment is correct, but I don’t really think this situation is security by obscurity. Like most things in computer security, you have to weight the pros and cons to each approach.

    Yubico used components that all passed Common Criteria certification and built their product in a read-only configuration to prevent any potential shenanigans with vulnerable firmware updates. This approach almost entirely protects them from supply-chain attacks like what happened with ZX a few months back.

    To exploit this vulnerability you need physical access to the device, a ton of expensive equipment, and an incredibly deep knowledge in digital cryptography. This is effectively a non-issue for your average Yubikey user. The people this does affect will be retiring and replacing their Yubikeys with the newest models ASAP.











  • Yes, it’s possible

    You need a SIP trunk to connect to and a PBX server. I would also recommend a proxy server to obfuscate your SIP server as it will be constantly attacked.

    It doesn’t technically need its own network, but having it on its own VLAN is recommended as you will want to have some QoS policies for the UDP voice traffic otherwise your call audio will be choppy




  • Godort@lemm.eetoSelfhosted@lemmy.worldThe domain aftermarket has a big problem
    link
    fedilink
    English
    arrow-up
    76
    arrow-down
    2
    ·
    8 months ago

    Domain squatting is incredibly scummy, but I have no idea how it would be possible to have any other system.

    My understanding is that domains do expire unless you pay the fee to renew for another year.

    Regarding unused domain names, how would anyone know if a particular name is being unused? Domain names are used for more things than browsable websites. You’d have to have a system that could determine if traffic is going to those names, which seems bad from a privacy standpoint and also pretty easy to script around.