digitalcourage.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Diese Instanz wird betrieben von Digitalcourage e.V. für die Allgemeinheit. Damit wir das nachhaltig tun können, erheben wir einen jährlichen Vorausbeitrag von 1€/Monat per SEPA-Lastschrifteinzug.

Server stats:

859
active users

Christian Pietsch (old acct.)

Reading about the recent SMTP and SSH vulnerabilities, I get the impression that open source projects, proprietary vendors and government agencies such as @certbund don't know how to talk to each other. They should at least have something like a red phone.

Please comment here if you have a constructive idea on how to improve the situation! seems to assume that everyone uses , a CMU service I had never heard of.

:
sec-consult.com/blog/detail/sm
postfix.org/smtp-smuggling.htm

:
terrapin-attack.com/patches.ht

@chpietsch They comminicated through a clothing store? Okay, with the name "VINCE" nothing shows up. And wow does this site show much use. 13 public entries this year.

@chpietsch @certbund maybe I misunderstood something, but the terrapin stuff seems a good approach: taking list of implementations and contact them. Took me < 10 seconds from SMTP Wikipedia to Software list en.m.wikipedia.org/wiki/List_o of course this is an extra workload, but acting responsible is always more work, otherwise anyone would always act responsible.

en.m.wikipedia.orgList of mail server software - Wikipedia

@Lurkars Yes, they tried hard but still were not able to contact some important actors. From the screenshot:

“Due to the lack of proper security contacts and response, we were not able to disclose our findings to some of them.

AbsoluteTelnet (Celestial Software)
Amazon AWS
CERT-Bund
Cisco
Ericsson
Microsoft
Mikrotik
Partnered CERTs of CERT-Bund (via CERT-Bund)
SSH Server for Windows (Georgia Softworks)
Tectia SSH (SSH Communications Security, Inc.)
Termius (Termius Corporation)”

/cc @certbund

@chpietsch @certbund haha okay, yes than I misunderstood/misread. Thought they contacted them AND the list. Of course those are still two different problems:
- who to contact
- how to contact/reach e.g. how to act if not reachable

Thanks for clarification.

@chpietsch @certbund @AlisonW then the challenge is to hack the red phone…

Interestingly, I learned the other day that the red phone was made up for dramatic purposes in Dr Strangelove - following which the US and USSR eventually ended up adopting a system of telex machines for said purpose, because less room for mistranslation.