Banner image

Technology and Innovation

Latest articles

vulnerability

1000 Third Parties Could Have Stolen RIPE NCC Session Tokens - By Design

Author image
Sasha Romijn

10 min read

In this guest post, Sasha Romijn details how the scope of a single authentication cookie created a potential path to full account compromise across RIPE NCC services.

Article tags:

2 Please read the article before liking.
0
digital sovereignty

Sustaining the Commons in an Age of Digital Sovereignty

Author image
Hisham Ibrahim

12 min read

Digital sovereignty raises legitimate questions about dependency, resilience and control. It can strengthen the Internet when it builds capacity and meaningful choice. It becomes risky when it is pursued as control over the common layer that keeps the global Internet interoperable.

Article tags:

6 Please read the article before liking.
0
non human identity

Non-Human Identity for Workloads and AI Agents

Author image
Kathleen Moriarty

5 min read

Passwords and API keys are giving way to a new generation of short-lived machine credentials. But as non-human identities scale rapidly, the growing question is how much trust and assurance those identities should carry.

Article tags:

27 Please read the article before liking.
0
legacy II

Legacy Out of Contract

Author image
Qasim Lone

19 min read

Last time, we looked at legacy address space in terms of contract coverage, ROA coverage, and proportion of announced prefixes. Now it’s time to take a closer look at those blocks still to be brought under contract and get a clearer picture of what kind of behaviour we see coming from them.

Article tags:

38 Please read the article before liking.
0

All articles

ADoX Deployment in the Wild cover

ADoX Deployment in the Wild

Author image
Yevheniya Nosyk

11 min read

Encryption between DNS resolvers and users is growing - but what about the next hop? We measure the real-world deployment of encrypted resolver-to-authoritative DNS (ADoX), finding limited, highly concentrated adoption and little support among resolvers.

Article tags:

27 Please read the article before liking.
0
quic_cover

Using QUIC Backscatter to Infer Hypergiant Deployment Configurations

Author image
Jonas Mücke

10 min read

QUIC enhances privacy, but passive measurements still reveal deployment details. Using network telescope data, we analyse QUIC behaviour across major content providers and validate our findings with flow data and active measurements.

Article tags:

35 Please read the article before liking.
0
noise

Noisy Routers: Investigating the Make-Up of Route Collector Data

Author image
Ebrima Jaw

11 min read

Analysis of 80B+ BGP updates shows repeated "noise" is highly concentrated in a small set of peers, sessions, and prefixes, inflating datasets. Researchers from Twente, CAIDA, SIDN Labs, and IIJ examine impacts on measurement and operations.

Article tags:

151 Please read the article before liking.
0
ott-apps

Beyond the Network View: DNS-Driven Application Visibility

Author image
Danny Lachos

6 min read

Network operators often lack visibility into which applications drive their traffic. We present an open-source DNS-based correlation method that enriches NetFlow and BGP data with application and CDN information. This enables a shift from a network-centric to an application-oriented view of traffic.

Article tags:

45 Please read the article before liking.
0
break_loop_cover

Make This One Change to Prevent Routing Loops in Your Network

Author image
Maynard Koch

5 min read

Routing loops can trap packets between routers, preventing them from reaching their destination. In some cases, routers even duplicate looping packets, amplifying traffic and threatening Internet stability. We look at how this happens and how operators can prevent it.

Article tags:

139 Please read the article before liking.
0
forward_hell_cover

Forward to Hell? On Misusing Transparent DNS Forwarders For Amplification Attacks

Author image
Maynard Koch

10 min read

DNS infrastructure is infamous for facilitating reflective amplification attacks. Countermeasures such as server shielding, access control, rate limiting and protocol restrictions have improved the situation, but DNS-based reflective amplification attacks persist. Focusing on the threat vector intr…

Article tags:

163 Please read the article before liking.
0

Showing 248 article(s)

Previous
1 2 3 ... 25
Next