Am I missing something about how this story went missing from the front page? There is at least one story with less points posted 12 hours earlier that is still visisble there.
I'm the author of this post. What people who are unaware of the layout of the congress center don't realize is that the video starts when we were leaving. The door "inside" is actually to get "outside". I was told to leave in 5 minutes, I stayed where I was maybe 2 minutes and started walking (I'm not leaving anything out, it was just more of the first audio recording), and then was prevented from leaving the event by masked thugs who pretend to be real security guards on paper.
People assume I did something to deserve this, and I can live with that. But in reality it was nothing more than the list of domain names I own. I did my best to describe that here.
Sure, the mail storage currently takes up 1.01TB, using dovecot's mdbox. This mail store started in January 2016, after the service got raided twice by german authorities[0] (at request of u.s. gov), otherwise it would be larger.
I'm not going to run like per-user stats but I know historically there's been about 11kb per E-mail on average, so that's about 90 million mails stored. The MTA itself sends and receives a bit over 20 million E-mails annually, so the extra from that is probably from the mailing list I run on the same server (where each message only counts as 1 for statistical purposes)
How I prevent outgoing abuse is a black box, but I do it well enough that mail from my server almost never ends up in spam. But given that it's a free service I definitely don't have the budget to warm up and dynamically scatter mail across IP space to maximize deliverability. Cool technique, though!
I run an E-mail server with over 250,000 users. I started by following some generic "dovecot+postfix+mysql" tutorial on howtoforge and I'm still using mostly the same setup over 4 years later.
>Then your email doesn't work and you could be missing out on important communications
Pretty much every E-mail server will retry sending your E-mail for a long time (like 2 days is default on postfix). Once your mail server comes back up all of your E-mail you missed during the downtime will come in slowly as messages are retried
>you're scrambling to figure out how the spammers managed to exploit your setup this time
Any tutorial should point you in the right direction restricting open relay on your mail server, just basically requiring authentication to send E-mail outside of your server.
>I started writing an SMTP protocol handler in Haskell
Do you have any link to your progress? Postfix's configuration definitely shows age, but all of the options do important things that you could actually want to change. It seems other MTAs either have just as complicated configuration (to do the same things), or have stunted functionality.
>being secure and resistant to attacks by default
I agree about sensible and more secure defaults in configuration. But the application security of postfix and dovecot are both pretty robust[0][1]. Considering they are 19 and 15 years old, both applications have seen several developer-lifetimes of effort.
>we need more guides like this for us poor souls who do go down this route
I agree, though mediocre howtoforge tutorials seem to have worked fine for this poor soul.
I use PGP every day. Who messages me, how often, and at what times, is still private information and I should have a say in where and how that happens. My PGP-encrypted conversations tend to be much more sensitive than any other medium I use.
The cryptography is almost certainly not broken. That does not mean it won't be broken in the future. I would have the same concern if my TLS-encrypted traffic was being saved. If my ISP was saving TLS traffic or my XMPP provider (the one that I don't host, anyway) was saving OTR conversations, I would be equally concerned.
Even worse, actually. TLS (usually, nowadays) and OTR both employ forward secrecy. PGP does not, at least traditionally.
What bugs me about the direction Keybase is going is that they still have not implemented a way of disabling the ability for users to send me encrypted messages.
I do not want Keybase to hoard encrypted messages I will never be able to read because I do not want to install their application on my computer. My Github issue for this has gone largely ignored:
I am thinking I am long overdue to placeholder my account until this is solved. I already have 10 encrypted messages I will never be able to read. I joined Keybase as a public key repository with external verification support, not for them to store private conversations -- encrypted or not.
I'm an experienced linux system administrator currently employed for a U.S. company. In my spare time I run a public E-mail provider with 132,000 users, and a VPS provider with >$1K MRR. I'm interested in positions in the security or sysadmin space, with bonus points for companies providing services that respect users' privacy, or provide a tangibly beneficial product or service as part of their business model. I'm also open to development work but only as an aside. Sysadmin first, programmer second. A sense of humor is required as my side projects aren't exactly politically correct, though I keep work and my personal ventures completely separate.
Due to my work providing privacy-oriented services, I recently had $2,000 worth of electronics seized at the U.S. border because I refused to decrypt my electronic devices. Because of this, relocating to the U.S. is not an option.
I'm the author of OP's post. Can you provide me more information about this? I've always wondered if that was the case, but I was once given a lengthy interview in the Amsterdam airport on my way to DEFCON last year, which gave the opposite impression.
This is probably because I had set up DNSSEC on my nameservers, but my registrar doesn't yet support DNSSEC for .li. I plan on moving to another registrar once the domain is closer to expiry. I guess I'll try to do something sooner than that to remove the DNSSEC entries that my nameserver is returning.
I'm the author of the OP's post. When I left the U.S. one of the questions that I was asked (that I refused to answer) was whether I used any social media and what the accounts were. The sites that they listed as examples were Facebook and WhatsApp, which I found particularly interesting.
https://archive.is/dtRg2 https://archive.is/8HK5y https://archive.is/yk5uU
Is there any transparency that could tell us why this change was made?