.CYOU TLD - We See You Too Spammer

ShortDot SA, the top-level domain registry that brought us the infamous .ICU TLD is back with yet another useless domain extension. Say hello to .CYOU TLD, the “savvy and uber-cool domain”, at least according to ShortDot.

Did Microsoft just roll out MTA-STS and TLS-RPT?

A few months ago I was complaining about the lack of MTA-STS adaptation with major email service providers besides Google. Recently though, I’ve noticed a new player connecting to mta-sts.paranoidpenguin.net to retrieve my MTA-STS policy.

Outlook.com is no longer blocking my mail server

I’ve been getting quite a few emails from people wanting to know if I’ve made any progress on the deliverability issues I was facing when delivering email to outlook.com. As good fortune would have it, Microsoft accepted my request to delist my mail server from outlook.com’s internal IP blocklist.

Plausible Analytics review – Browser fingerprinting and CNAME cloaking

For the last few weeks, my feeds and federated timelines have been filled with absolutely brilliant marketing campaigns for Plausible Analytics, the new open-source privacy-focused website analytics tool. Plausible Analytics has enjoyed exponential growth and is frequently recommended by privacy-conscious voices in the FOSS community.

Self-hosting security challenge

If you’re a geek like me then you probably enjoy spending your time hardening and optimizing your servers to support modern security standards and policies. If so, I’d like to share my favorite online resources and encourage you to take up the challenge of beating paranoidpenguin.net.

Outlook.com is blocking my mail server

Recently, I was trying to respond to an email delivered to me from an outlook.com sender address. Unfortunately, my response immediately bounced back, and I was informed that my mail server’s IP address had been added to outlook.com’s internal blocklist.

How to back up your 2FA secret keys with KeePassXC

The amount of services offering (or even demanding) two-factor authentication (2FA) is ever-increasing. This has encouraged me to find a more resilient strategy for how I store, manage, and backup my secret keys. My old approach relied solely on using time-based one-time password (TOTP) applications capable of exporting and importing 2FA accounts.

Outlook.com phishing campaign hosted on Google's Firebase platform

Earlier this week I discovered an interesting Outlook.com phishing mail that had been caught by the anti-spam measures we deploy for our e-mail customers. Well, to be fair, the phishing attack itself was not anything new or sophisticated, but the choice of hosting provider was rather interesting.

Why doesn't www.bing.com redirect from HTTP to HTTPS?

On occasion, I’ve noticed the following HTTP referer when going through my server logs: http://www.bing.com/search?q=your+search&go=Search (notice the HTTP part). I thought it would be interesting to see if this HTTP referer was sent from Microsoft’s search engine as a result of someone performing a search over an unencrypted HTTP connection.

The best dark, gory and violent anime series of 2019

I figured there are already too many mediocre tech blogs on the Internet, so from here on out I’ll embrace my true passion instead. Well, anime blogging is over-saturated as well, so my niche will be the sick and depraved side of anime. Thankfully, there are plenty of riches to choose from.

Content warning: The following post contains violent imagery and descriptions and absolutely no mention of Fruits Basket.

Self-hosting email in 2020 – Joe Nobody vs. World

I recently moved my self-hosted email service from Scaleway to DigitalOcean. After receiving a new IP address for my mail server, I’m effectively once again the new kid on the block. Let’s find out if the big kids are willing to talk with me if I play nice and put on my best behavior.

How to configure Hugo as a Tor hidden service

After migrating my blog from WordPress to Hugo, I wanted to find a simple solution that allowed me to mirror my blog content effortlessly to my hidden services. As Hugo is a static content generator, I didn’t have the opportunity to dynamically rewrite content on the fly by pulling the HTTP host from the current request.

Kerberos added to Slackware-current

Back in 2018, Patrick Volkerding mentioned that he was testing PAM and Kerberos to provide proper support for Active Directory and NFS on Slackware Linux. It seems like Mr. Volkerding has finally reached a decision.

.ICU TLD spammers move to the .XYZ TLD

After noticing that the majority of the .ICU spam campaigns were drying up, I headed over to Namecheap to find out which gTLD was the next likely target for abuse. Well, what do you know, Namecheap was throwing out .XYZ domains for 1$ a pop.

.BEST TLD - Spam Like the Best

I’ve made the decision to go ahead and block another one of those pesky new gTLDs that are seemingly exclusively used by malicious actors. Email delivery from .best domains will no longer get past any spam filter under my control.

Enterprise support for Slackware

As a managed service provider (MSP) we’re using an off the shelf remote monitoring and management (RMM) platform. Recently, and just for curiosity’s sake, I decided to take a closer look at the Linux agent offered by this platform. I’ll admit to being somewhat shell-shocked when I discovered that the installer had Slackware Linux on the list of supported distributions.

Blogger.com powered cryptocurrency scam

Over the last several months, I’ve seen a steady flow of spam emails containing only a single line of text encouraging recipients to visit a blogspot.com address. Should the recipient choose to follow the link, they would soon find themselves on a cryptocurrency scam site with amazing propositions.