Meetups/Infra/2026-08-10
(Preamble:
= Meetup - Infra = https://www.noisebridge.net/wiki/Meetups/Infra https://www.noisebridge.net/wiki/Meetups/Infra/2026-..-.. )
2026-08-10m Meetups/Infra
| Noisebridge | About | Visit | 272 | Manual | Contact | Guilds | Stuff | Events | Projects | Meetings | Donate | E |
| Events | 5MoF | Hosting | Streaming | Meetup | Classes | Anniversaries | Hackathons Upcoming Events | External Events | Past Events | Future Events | Noisetabling |
E |
| Meetups / Infra: 2026 | Template | Pad (live notes) | Jitsi (video call/screen sharing) | (M | lu.ma | discord events | chat) | V · T · E |
(TODO summary)
Welcome[edit | edit source]
Hacker Jeopardy[edit | edit source]
thank you Jet for hosting
Introductions[edit | edit source]
- [name] - [background]. [goals for meetup, or interests to explore]
- Loren - worked on cloud and infra in past, wants to review noisegarden
- Ciara - fellow noise-gardener, noisy-gardener - hit me with your best topic
- Meghan - Software engineer, fellow noise gardener
- Renaud - Software engineer, likes computer
- Derek - new job! new stability!
- Doug - underqualified, likes computers and likes to learn
- Abhinav - Software Engineer, started self hosting earlier this year
- Frank - Software Engineer, amazaed by the detail about accidental attack on HuggingFace
- WeZ - Likes to write verilog and system verilog, ask about yosys and other HDL tooling, enjoys mobile apps
- MJ - noisebridge; likes coming to meetings and meetups
- Jet - Max Chillin.
- Gwen - Life long learner,
- Jake - software engineer, platform engineer -- last time here, I heard a lot about k8s
- Mister_name - Just hangin' out. like SW engineering
Lesson or Demo[edit | edit source]
- Read aloud: clarify for meetup. We are taking notes in a riseup pad (or I am--help appreciated, and links). We have meeting notes posted to the wiki. noisebridge.net, search Infra, or Meetups/Infra. (the Infrastructure page has a disambiguation link.)
- Shell, web services, self-hosting, networking!
- DNS - Alias --
- CNAME, like a pointer from one domain to another
What kind of bytes Declare and end point
$ORIGIN example.com.
bar.example.com ... foo.eample.com. foo.examle.com ... 102.0.2.23
new alias record, created beccasue CNAME doesn't like when the name that you map to doesn't have a subdomain. When the source of the CNAME, when the root of the name, when ... that's when you use an alias record.
RFC: 1034, last updated earlier 2026 https://datatracker.ietf.org/doc/html/rfc1034#section-5.2.2 https://datatracker.ietf.org/doc/search/?name=rfc%201034&rfcs=on&activedrafts=on&olddrafts=on
draft: https://datatracker.ietf.org/doc/html/draft-dnsop-eden-alias-rr-type-00
Why are CNAMES on root not allowed?
Does this explain why things are hosted at www.hostname.tld
Instead of foo.example.com, if you've CNAMED the root; then...
Kevin Trivia: Earlier days of the internet, when ppl brought up their first websites. Sysadmins did not want to put a listener on port 80. web developers were tasked with the responsibilty of domain tasks related to the www subdomain.
http query verb TLS
- QUIC -
- https://datatracker.ietf.org/doc/html/rfc9000
- HTTP/1 to 2 adds better multi-plexing, but over a single TCP connection
- HTTP/2 to 3 - ... -
- Very intense multiplexing over UDP
HTTP/2 had head of line blocking, queueing issue, operating over a single TCP stream, interleaving sequentially, needs to reach completed stream or partial completion. Typical webbrowsing. Immediately load hundreds of resources, images, CSS, javascript in parallel, advertisers care about immediately seeing content. Each resource, previously over HTTP/1, so browsers will happily open dozens of connections upstream to resources, empirically better through tracking congestion, lovers of systems sees room for improvement
The Tail at Scale - Jeffrey Dean, Luiz André Barroso https://research.google/pubs/the-tail-at-scale/
Can people handle their own protocols instead of web sockets? What can you do to determine which.
Through the OSI Stack for keywords
Elan : Clarifying Question These standards are building on top of UDP, destination IP and Port. Can build TCP on top of UDP? Yes, but even more wild than that. (Least Common denominator) Host Roaming, maintaining connections Multiple streams can make progress on the same connection not blocking each other. Buffers for 5 requests in parallel Share Congestion Windows Congestion control algoritms, there are 5, just good enough solutions, some great papers available. 1) Vegas 2) Tahoe 3) Biggest ? 4) 5)
Some people complain about anonymously slow open connection behavior
If you have an app with low latency data requirements, retry and...
Optimize Bandwith or Latency, tradeoff between the two. If you want to
Video Games?
Browsers,
HLS Video Streaming
OwnCast, multiple streams to the same host
If you have HTTP/2+ Multistream
QUIC promises up to reliable transpost across multiple streams in parrallel spearate part of standard unreliable trasnport different stream can have different reliablilty
- Connection Ids ?
Superscalars (Google, Cloudflare, Netflix) Don't want servers to block to unable load balanaces.
Let's Check What's the best way to check?
Existing protocols are ossified on middle boxes
Kernel inflexibility, userspace application deployment, greater flexibility
Chrome updates weekly, but
- TLS - ML-KEM --
- https://csrc.nist.gov/pubs/fips/203/final
Why do we have symmetric and public/private keys
symmetric uses for key exchange
AES uses 128,192,256 bit length for
X25519MLKEM768
Galois Counter Mode.
MLKM
Use a differeny cipher native to platform back in the day, we had 10 different cipher schemes to cover all applicable operating system. Has the number of schemes grown.
There is a trade off between device attacks
What are actually the number of schemes being used
TLS .. org?
one of the weuird corners of .. design, connecting over an untrustsed network, part of the... bind the transcirpt of connection, include bipher suites offering and the hash of those is part of the transcript, the hash becomes part of the secrete, if you and the server sobjserev different order, then the connection would ffail to create a failed key; downgrade attack to a weaker version of encruption
We need to bind intent of connection so people can't drop parts of the suites offered.
https://tls13.xargs.org/ https://datatracker.ietf.org/doc/html/rfc8446 https://badssl.com https://revoked.badssl.com
see how your browser deals with validation interception certificates broken cryptography secure
don't only accept good data, but also reject bad data
First apple announce that on ios devices any certificate have expired over 369 days, if touching apples network stack, revocation doesn't work in practice, drive towards "we have a big system, ... the world can get better"
-meghan
i hit mitm in the wild https://github.com/lastlogin-net/obligator/issues/55
What is the bottle neck for hitting certs,
What is the reason let's encrypt limit the number of cert requests.
synology had great cert generation
For a lot of people....
Corrolary
If I wanted to open Elan's house of certs, it's not just limited by compute
Two different bottle necks Setting up multiple certs, issuing certs?
If you make it too easy if
Wildcard certs, the whole transparency pipeline
Would be cool if want cert to expire in a week and reduce the API overhead
In the TLS
Securtity Main Origin Connection Protocol
Certificate Transparency, are CT logs valuable.
What is the, let domains owners know if
cetnrally google has been a target of intelligence agency
issuoing fake cert spoof connection with middle man CT Log has been used to punish the CA by taking away their
Cert Famously Verisign
https://www.youtube.com/watch?v=y6bhoF-VtZA F8 2018: Certificate Transparency: Detecting Malicious Certificates and Phishing Attacks
- HTTP Query Verb
replaces people using POST It's GET with a body
https://www.rfc-editor.org/info/rfc10008/
The reason query is beting a thing, wehn adding parameters to GET, which limited arg numbers. Sick of using POST requests. All JQueries fault, (4096 parameters) Not enough for js slop environment
Jet: graphql default is to use post browser url limits - http://reference.bitty.site/
common use of GET for a query.
Query is designed to be safe. Idempotent: retries ok, state respecting over multiple requests, don't repeat actions.
If change on server then use POST.
AIP-131, What is good practice, if something is guarenteed idempotent, generate a replay key, if you're caching the results, great; but on the server side, if you have an expensiev operatiob don't do it twice.
What's a way to .. Entity Tags, ETag header; a hash of the contents https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/ETag
- DEFCON -
Fun bits of DEFCON?!?! Jet:
Open Sauce will start a non-profit devision Hacker Jeopardy is the best part of defcon Jet is very bad at feet feud (search feet ... snickers ...) WeZ said wha.... ?
https://www.youtube.com/watch?v=87DyyMV0kCY Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
- NoiseGarden
Motto: "More 9's than before." Lost no monies.
Daniel has been adding more CI features Elan is learning what it takes to stand up media wiki instance
https://github.com/noisebridge/noisebridge-wiki
Conventional commits https://www.conventionalcommits.org/en/v1.0.0/
Are you adding a new feature Is the entire tree stable? (don't add commit that isn't stable) Label the commit
FEAT: details ... \n moar info
Loren says: "commit early, often, well scoped"
- We-z - OpenAI - cyber-security challenge
- Palantir partners
- NoiseGarden
outage, 5m self-hosting - "downtime doesn't matter if you're not using it" - meghan https://chuffed.noisegarden.nexus/
https://www.conventionalcommits.org/en/v1.0.0/
Outros[edit | edit source]
- Ciara - will play more with noisegarden, & learned today ETag! and TLS cipher negotiation!
- Loren - (besides NG self-enrollment) history of incidents in TLS, leading to current system
- Meghan - learned ARP, Address-Resolution Protocol - IP-to-MAC-addr association
- Erik - going to learn how to make pizza dough
- Renaud - Gone
- Derek - hash ETag, will look into, saves on re-creating content
- Doug - leared not to play jepoardy, commit to last weeks intent
- Abhinav - QUIC & HTTP/3 stuff is pretty cool—will check Caddy config, if doing that as well--(Ciara: note firewall, 443/udp, not just TCP)
- Eugene - gonna commit to writing his commits. https://www.asd-ste100.org/
- Frank - state of http/3 for mobile app, plans to improve it.
- Elan - on the http/3 chain do a plug for connect RPC support for all the protocols, try to get wiki-alpha & meme(/gen)
- Jake - Feels more prepared for protocol section of hacker jeopardy,
- Nixxy - talked about secrets w/ HMAC
- Loren - Cable evaluators. Is your HDMI cable good? (Let's make some ourselves)
https://www.youtube.com/watch?v=OT_iyvOy0Tk
HMAC Tutorial. https://drhodes.github.io/macaroon-tutorial/lab/index.html?mode=single-document
Obsidean? Log Seq? Log Seek?
Questions, Discussion, or Coworking[edit | edit source]
- [Issue]
For next time[edit | edit source]
Questions[edit | edit source]
Readings & Exercises[edit | edit source]
- Readings
- Exercises
Join online[edit | edit source]
- Try it yourself!
- Join libera.chat #nb-meetup-infra