Cybersecurity and cloud computing organization Akamai signs multi-year agreement to host https://kernel.org
https://www.linux-magazine.com/Online/News/Akamai-Will-Host-kernel.org?utm_source=SM
#Linux #kernel #Akamai #hosting #infrastructure #CNCF #AlpineLinux #containers #cloud #cybersecurity
Of course, there are other ways to configure sensitive values but I don't think it's necessarily obvious or front of mind when updating config and I honestly can't see (as someone who configures multiple services on Akamai regularly) why this feature is needed.
Unsure if it can be disabled or auth'd but I don't see any way to do that.
There are some docs which cover it a little bit: https://techdocs.akamai.com/download-delivery/docs/test-your-dd-property#4-install-an-extension.
Just though it might not be common knowledge.
2/2
#Akamai #InfoSec #ReadTeam #BlueTeam
Akamai has what I personally think is a seriously risky mechanism for debugging HTTP requests/responses. You can send an HTTP request header of `pragma: akamai-x-get-extracted-values` for a URL served via Akamai & it'll return `x-akamai-session-info` response headers which include user-defined config variables - that's where the main risk is IMO. People may well not realise this feature exists & use the vars for sensitive info e.g. backend auth keys.
1/2
#Akamai #InfoSec #ReadTeam #BlueTeam
oh man i'm stoked to share this one.
so at akamai we have these huge research reports called the State of the Internet (SOTIs) that we put out. they're typically pretty high level, showing what we've seen in a particular topic since such a huge portion of the internet runs on our stuff lol BUT this time, they let us try something new.
This time, we pulled together some pretty deep, low-level technical research on risk scoring, a few botnets, vpn abuse, XSS, and k8s and collated it into an anthology designed for the defenders themselves. this was honestly a passion project of sorts (y'all know my nerdy ass loves this shit) and it turned out pretty great i think. i'll probs share it a few different times, it's a dense report lol
the vpn stuff in particular is interesting - they found a permados vuln in fortiOS
https://www.akamai.com/lp/soti/cybersecurity-defense-guide-2025
Great post from #Akamai's VP of Diversity, Inclusion, and Engagement reiterating Akamai's commitment to both our FlexBase flexible workspace program and our Diversity, Inclusion, and Engagement efforts. It is things like this which help Akamai have such a great culture and are reasons why I've stuck around for 25 years.
I signed up for an attended one of our DI&E trainings last week (seemed appropriate) and while I've heard most of the content before, one of the things that it made clear is how critical it is for a global company like ours to have a robust program that helps us have awesome people from all over the globe collaborating to solve tough problems, and to feel engaged and included in ways that foster collaboration and increased productivity.
https://www.linkedin.com/feed/update/urn:li:activity:7290096754098675712/
MasterCard DNS Error Went Unnoticed for Years
https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/
#HowtoBreakIntoSecurity #az.mastercard.com #PhilippeCaturegli #ALittleSunshine #awsdns-06.ne #CloudFlare #mastercard #akam.net #Bugcrowd #akam.ne #Seralys #Akamai #google #Azure
MasterCard DNS Error Went Unnoticed for Years - The payment card giant MasterCard just fixed a glaring error in its domain name se... https://krebsonsecurity.com/2025/01/mastercard-dns-error-went-unnoticed-for-years/ #howtobreakintosecurity #az.mastercard.com #philippecaturegli #alittlesunshine #awsdns-06.ne #cloudflare #mastercard #akam.net #bugcrowd #akam.ne #seralys #akamai #google #azure
@gameplayer @atomicpoet Given the cost and overhead of facilitating a private network at scale to do so, I'd say that doesn't fly.
#aws is way more convenient for such a job...
#Piracy is a #Service Problem.
https://www.youtube.com/watch?v=SWmufgTp6EQ
Piracy will exist as long as #corporate #greed will exist.
If it was my decision #Copyright and #patents would be contingent on the #media / #technology being produced and offered for sale.
Espechally since we live in the #AgeOfAbundance and nowadays the cost for distributing even a #AAA #Game or #Movie is merely the cost of #Storage and #Bandwith, so at worst a whole Euro if we're talking #PayAsYouGo - #Akamai with no minimums to get stuff distributed.
#Akamai is hiring for a Senior Product Architect in the US for our designing the next generation of our Compute Networking (eg, #Linode and more) solutions such as VPC, L4 Load Balancing, Cloud Firewall, etc. This is a great opportunity to design #IPv6 centric systems (but still needing to support Legacy IPv4).
I've been at Akamai for 25+ years and love working here, with both flexible work options, great colleagues, and an inclusive environment.
#Akamai shares their contributions to the #CNCF and to #Flatcar #Container #Linux , and @ahrkrak provides a brief project status at the #KubeCon Day 3 keynote last week: https://youtu.be/f8ornY7h2KE?si=YcNXLXI-TPe4F-_8&t=144
The cloud-native community is awesome and we're super happy to be part of it.
@chiefgyk3d granted, IPFS has it's own URL and there are just few IPFS relays like https://ipfs.io
And to answer @damon's question:
https://social.wedistribute.org/objects/bf2aab09-d3b0-4cd2-b382-0ae1db6db0fc
@chiefgyk3d Also fir #decentralized storage there are better options like #IPFS...
I've yet to find any #blockchain that is even remotely competitive with #Akamai as a #CDN in terms of #Storage and one would be better off building a personal "HarderDrive" by using i.e. https://oshi.at ...
#Akamai announces its PQ-TLS plans:https://www.akamai.com/blog/security/taking-steps-to-prepare-for-quantum-advantage
What it doesn't say: Kyber/25519 Akamai to origin before end of year. Enabled for all, start upgrading your origins now :)
Soon, ML-KEM/25519 and ML-KEM/P256 in addition to Kyber/25519 client to Akamai. That might require an opt-in configuration.
Shortly thereafter, all internal Akamai connections will do ML-KEM/P256 to get both PQ safety and FIPS.
@alterelefant @HauntedOwlbear OFC for some corporations, it may be useful to i.e. scale stuff spontaneously.
Akamai + #streaming - pain = #dacast
That being said, I don't get why anyone would want to use #AWS, #Azure, #GCP or whatever due to their extremely high and complex pricing structures alone.
And there was the very first victim of #september11, Danny Lewin, founder of #akamai and a former #IDF soldier who, on #Flight11, tried to fight the #AlQueda terrorists highjacking the plane who slit his throat…
https://www.tabletmag.com/sections/news/articles/fighting-genius-on-flight-11
Updating this to mention that this #Chrome issue with #Chrome128 appears to be connected with #Akamai CDN and cacheable content returning 304s.
@campuscodi And #Akamai says that half of the traffic on the internet is generated by bots.
https://www.techspot.com/news/103664-almost-half-all-web-traffic-bots-they-mostly.html