Job Snijders

RPKI/BGP subject matter expert, Internet routing security hacker-for-hire, OpenBSD developer

Job Snijdersjob@bsd.network
2025-06-07

I authored a new Policy Proposal: "Revocation of Persistently Non-functional Delegated RPKI CAs"

Policy proposal itself: ripe.net/community/policies/pr
Discussion: mailman.ripe.net/archives/list

Consider chiming in!

Job Snijdersjob@bsd.network
2025-04-29

@pesco @canadianbryan @prahou about 10 bucks/euros

Job Snijdersjob@bsd.network
2025-04-28

@canadianbryan @prahou made the art

Job Snijdersjob@bsd.network
2025-04-28

@OpenBSDAms @biglinter I didn't make one, but you can!

Job Snijdersjob@bsd.network
2025-04-27

OpenBSD 7.7 has been released! openbsd.org/77.html

OpenBSD 7.7 release poster titled "LIfe Of A Fish"
Job Snijders boosted:
bgp.tools Updatesbgptools@bgp.tools
2025-02-17

Ooh a cat drawn out by making IP addresses ping!

https://bgp.tools/prefix/185.87.56.0/22

A screenshot of bgp.tools, showing an IP block from portfast Ltd, the hilbert IP map displays a cat
Job Snijders boosted:
2025-01-17
Job Snijdersjob@bsd.network
2025-01-09
Job standing in snowstorm
Job Snijdersjob@bsd.network
2025-01-08

For more background on the ultra long-lived root certificates, see mailarchive.ietf.org/arch/msg/

Job Snijdersjob@bsd.network
2025-01-08

rpki-client 9.4 has been released! This release imposes restrictions on Trust Anchor certificate validity periods, includes ASPA support for BIRD2, protection against AS0 TALs, and various reliability improvements. Read the release notes here: cdn.openbsd.org/pub/OpenBSD/rp

Job Snijders boosted:
2024-12-16

The key words "MUST", "MUST NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED BUT REPULSIVE", "WRONG BUT WROMANTIC", "FREQUENTLY MISUNDERSTOOD", "NOBODY BOTHERS WITH THIS BIT", "SHOULDN'T REALLY BUT WE WON'T JUDGE", "REQUIRED IN ORDER TO WORK AROUND EVERYONE ELSE'S BUGS", "YOU DO YOU", and "OBVIOUSLY ABSURD BUT VERY COMMON FOR SOME REASON" in this document are to be interpreted as described in RFC 2119.

Job Snijdersjob@bsd.network
2024-12-14

New (short) RFC: Detecting RPKI Repository Delta Protocol (RRDP) Session Desynchronization rfc-editor.org/rfc/rfc9697.htm Rpki-client was the first to implement Ties’s clever concept

Job Snijders boosted:
Philippe Smetpfsmet
2024-12-13

Juicht, allen, juicht! Dankzij de hemelmechanica gaat de zon *vanaf morgen* al iets later onder. Geniet ervan! 😎
(De nachten worden korter vanaf 21/12; 's ochtends is het nog wachten tot 31/12 eer de zon weer vroeger opkomt.)

Grafiek van het tijdstip van zonsondergang voor de maand december. Vanaf 13/12 gaat de zon elke avond iets later onder.
Job Snijders boosted:
2024-12-05

RFC 9674: Same-Origin Policy for the RPKI Repository Delta Protocol (RRDP), J. Snijders, rfc-editor.org/info/rfc9674 #RFC This document describes a Same-Origin Policy (SOP) requirement for Resource Public Key Infrastructure (RPKI) Repository Delta Protocol (RRDP) servers and clients. Application of a SOP in RRDP client/server communication isolates resources such as Delta and 1/2

Job Snijders boosted:
2024-11-06

RFC 9687: Border Gateway Protocol 4 (BGP-4) Send Hold Timer, J. Snijders, et al., rfc-editor.org/info/rfc9687 #RFC This document defines the SendHoldTimer, along with the SendHoldTimer_Expires event, for the Border Gateway Protocol (BGP) Finite State Machine (FSM). Implementation of the SendHoldTimer helps overcome situations where a BGP connection is not terminated after the 1/2

Job Snijdersjob@bsd.network
2024-11-06

Our favorite Internet routing protocol - BGP - just got an update!

The mechanism in this RFC should help a bit against zombie routes and other problems rfc-editor.org/rfc/rfc9687.htm

hat tip to @benjojo and Yingzhen Qu for sticking it out with me

Job Snijdersjob@bsd.network
2024-08-24

rpki-client 9.2 has just now been released! \o/ This is a bugfix release, it is recommended that all users upgrade to this version for improved reliability. Release notes are here marc.info/?l=openbsd-announce&

Job Snijdersjob@bsd.network
2024-06-23

OpenBSD rpki-client 9.1 has been released. This release contains novel replay attack & DoS countermeasures, bug fixes, and more. Read the full announcement here: marc.info/?l=openbsd-announce&

Proudly made without AI πŸ™‚

Job Snijders boosted:
Chris Gioran πŸ’”chrisg@fosstodon.org
2024-06-18

The year is 2030.

Computers boot directly into the browser. IDEs are just a web app now, running in the GPU. No one knows why. Or how.

All programs run in 4 nested containers on top of a hypervisor abstracting over the 5 major computational clouds. The last time a branch was predicted correctly, in any CPU anywhere, was 4 years ago.

Cloud costs are withdrawn directly from your retirement fund.

Ext7 just came out, it's written in Javascript and uses AI to guess what the file may contain.

Job Snijdersjob@bsd.network
2024-05-30

Expiration of ROAs - what is it and how does it work? What to monitor for @dougmadory
and I teamed up to analyze and visualize what's happening under the hood of the RPKI. fastly.com/blog/times-up-how-r

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst