What is Hackers' Pub?

Hackers' Pub is a place for software engineers to share their knowledge and experience with each other. It's also an ActivityPub-enabled social network, so you can follow your favorite hackers in the fediverse and get their latest posts in your feed.

0
0
0
0
0
0
0
0
0
2
0
1
1
0

Key serialization formats can be - uh - the source of "interesting" issues. It appears the whole internet technically uses DKIM the wrong way, but it's more or less the fault of the standard.
DKIM uses public keys in DNS, usually RSA, but how are they encoded? There are two common RSA public key formats, SPKI and PKCS#1.
The DKIM spec RFC 6376 says this should be an RSAPublicKey and references RFC 3447, which is PKCS #1. So it's PKCS #1, right?
Well... there's an "INFORMATIVE" part of the RFC that lists openssl commands to encode a key, with an example. And that's... the openssl command to generate SPKI. The example shown is also an SPKI key.

The Internet has voted with its feet and everyone uses SPKI. From previous research, I had a collection of ~35k DKIM keys, and there are zero PKCS#1 keys in there.

This appears to be known and is mentioned in the errata.

It's quite an unfortunate situation. Technically, everyone's doing it wrong. However, if you would happen to be so brave to try to do it right, you'll probably just run into problems. While I haven't tested it, my best guess is that you will almost certianly find some receivers accepting PKCS#1 and others not. (Many crypto library APIs autodetect the format, but given *noone* is using PKCS#1, I'm sure there will be ones only accepting SPKI.)

0
0
0
0
0
0
0
0
0

Just a little reminder to the fedi admins:

One of the most effective ways of curbing spam is keeping your instances small-ish and having approved registrations enabled. Almost all instance software supports this nowadays and it lets you prevent spam before it happens.

basically, Open Signups Bad

Of course this is just one tool in your arsenal, but please use it, it is very effective.


#fediAdmin
0
0
1
0
0
0
1

Did you know that there’s a premium version of Whatsapp which :

- Has no advertising
- Has no mandatory AI integration
- Has no tracking and does not gather your personnal data
- Has increased privacy and stronger encryption
- Is exclusive and allows you to chat with other premium members

Best of all ? It is currently free to join!

Go now to your app store and install it before it is too late!

It is called "Signal"

ploum.net/2025-05-23-chats-dig

0
0
0
1
0
0
0
0
0
0
0
0
0

이스라엘, 굶주려 식량 기다리는 가자 주민에 총격… 59명 사망 | 서울경제
m.sedaily.com/NewsView/2GU4DNY
“우리는 아이들을 먹일 음식을 얻을 수 있을 것으로 생각해 그곳에 갔지만, 그곳은 함정과 죽음이었다”
....와 ...할 말이 없다

0
0

Today for day, our new split aircon has been on from 10:30 am. In June. In Switzerland.

Yes, I know using it is an issue, and yes, we live in an overpriced poorly insulated apartment. Thinking of all the people who are too warm, without electricity and/or means to get cooler. 💔 Thinking of European forests that won’t be able to adapt 💔 Thinking of corporations and politicians ☠️

showyourstripes.info/l/europe/

Show your stripes - temperature changes in Switzerland since 1864.
0
0
0
0
0
0
0
0
0
0
1
0
1
1
0
1
1