<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Security on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/security/</link>
    <description>Recent content in Security on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 27 Sep 2026 18:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DNSSEC: Protecting Your Traffic From Forgery</title>
      <link>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</link>
      <pubDate>Sun, 27 Sep 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</guid>
      <description>Counted from the live root zone: 1,351 of 1,438 TLDs are signed, every single gTLD among them. Then it stops. 39 of 2,390 live gov.uk domains, 1 of 9 certificate authorities, and windowsupdate.com has no DS at all. What DNSSEC stops, what is really blocking it, and whether the problem is that we still do not understand DNS.</description>
    </item>
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
    <item>
      <title>Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.</title>
      <link>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</link>
      <pubDate>Mon, 14 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</guid>
      <description>A NAT helper reads the inside of your packets and opens inbound ports on what it finds there. Anyone can write that text — a web page has been enough since 2010. How helpers work, how crafted packets turn them into a port-opening service for strangers, what IPsec pass-through does, why they fail Cyber Essentials, and how to switch the lot off.</description>
    </item>
    <item>
      <title>What Your MSP Built You, And Who Else Can Reach It</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</link>
      <pubDate>Fri, 28 Aug 2026 17:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</guid>
      <description>Part 2 of 3. Cloud for a business all in one building. The firewall brand with the most exploited vulnerabilities on CISA&amp;#39;s list. Backups nobody has restored, reports that never reach you, an agent on every machine answering to a console you have never seen. What the ICO found at Advanced and Capita, and the keys that open all of it.</description>
    </item>
    <item>
      <title>Backdoors, and Who Gets Accused of Them</title>
      <link>https://blogs.damiendye.uk/en/random/backdoors-and-who-is-accused/</link>
      <pubDate>Tue, 25 Aug 2026 07:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/backdoors-and-who-is-accused/</guid>
      <description>Part 6 of 8. Barring a supplier on security grounds needs a standard applied evenly. A Swiss inquiry confirmed two intelligence services owned an encryption firm and sold weakened machines to 120&#43; governments; a crypto standard was pulled over a suspected weakness; kit gets intercepted in transit. Then the 2024 event that settled it.</description>
    </item>
    <item>
      <title>Samba4 and Securing AD Records Using DNSSEC</title>
      <link>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</link>
      <pubDate>Mon, 24 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</guid>
      <description>Every domain-joined machine finds its DC by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you have. Signing them from a Samba4 DC: BIND with dlz_bind9, inline signing, a hidden primary, dynamic updates kept out of the locator zone, then forcing Windows and Linux clients to validate the signatures.</description>
    </item>
  </channel>
</rss>
