Long Strange Trip

  • The case of the missing pyrex stopper: 3D printing to the rescue

    The case of the missing pyrex stopper: 3D printing to the rescue

    We have these Pyrex bowls with lids with a stopper. And, the stoppers seem to migrate. Or escape. Or hang out with the dryer socks, who knows. The net effect is there are more lids than stoppers. And over time, this gets to be an expensive and wasteful proposition, buying new bowls (and their lids),…

  • The invisible pimp hand of the FCC keeping Huawei out

    The invisible pimp hand of the FCC keeping Huawei out

    I’ve long been a big believer in the Adam Smith invisible hand. The concept that small economic tilt creates huge output affect. Seems like the current US telecom regulator reads that too. You see, in the US, telecom subsidies (universal service funds) are a big thing for a lot of telecom. And now, if you…

  • How’s your dnssec?

    How’s your dnssec?

    With so many things relying on the security of DNS (it controls your SPF, your DKIM, your CAA, generating SSL for your domain, …), and with DNS security being one of the keys to avoiding a man-in-the-middle attack, it behooves us to make sure it is ultimately very secure. This means the usual (2-factor authentication,…

  • What, another new DNS record to add? The CAA record and your SSL certificate

    What, another new DNS record to add? The CAA record and your SSL certificate

    OK, not all DNS providers support this. But, if yours does, consider adding a CAA record. What is a CAA record you ask? Its a DNS Certification Authority Authorisation, and its a very simple thing to add and use that increases your security. It allows one to assert, via DNS, which certificate authorities can issue certificates…

  • Its happening: the distrust of Symantec certificates, and e-commerce

    Its happening: the distrust of Symantec certificates, and e-commerce

    I was listening to ‘Masters of Scale‘ and episode #22 is with Sara Blakely of Spanx. So I clicked on their website. And my browser blocked it, the SSL site is not valid. So I did a quick check (side note: please test every site you own or influence on www.sslabs.com, it takes only a second.…