frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

RFC 6677 DNS Transport over TCP – Implementation Requirements

https://www.ietf.org/rfc/rfc7766.txt
6•1vuio0pswjnm7•1h ago

Comments

themafia•9m ago
> The growing deployment of DNS Security (DNSSEC) and IPv6 has increased response sizes and therefore the use of TCP.

Yes, but doesn't IPv6 also increase the "maximum safe UDP packet size" from 512 bytes to 1280?

> Existing deployments of DNSSEC [RFC4033] have shown that truncation at the 512-byte boundary is now commonplace. For example, a Non-Existent Domain (NXDOMAIN) (RCODE == 3) response from a DNSSEC-signed zone using NextSECure 3 (NSEC3) [RFC5155] is almost invariably larger than 512 bytes.

This has been a flagged issue in DNSSEC since it was originally considered. This was a massive oversight on their part and was only added because DNSSEC originally made it quite easy to probe entire DNS trees and expose obscured RRs.

> The MTU most commonly found in the core of the Internet is around 1500 bytes, and even that limit is routinely exceeded by DNSSEC-signed responses.

> Stub resolver implementations (e.g., an operating system's DNS resolution library) MUST support TCP since to do otherwise would limit the interoperability between their own clients and upstream servers.

Fair enough but are network clients actually meant to use DNSSEC? Isn't this just an issue for authoritative and recursive DNSSEC resolvers to and down the roots?

GPT-5.2

https://openai.com/index/introducing-gpt-5-2/
618•atgctg•5h ago•494 comments

Denial of service and source code exposure in React Server Components

https://react.dev/blog/2025/12/11/denial-of-service-and-source-code-exposure-in-react-server-comp...
133•sangeeth96•2h ago•54 comments

Rivian Unveils Custom Silicon, R2 Lidar Roadmap, and Universal Hands Free

https://riviantrackr.com/news/rivian-unveils-custom-silicon-r2-lidar-roadmap-universal-hands-free...
158•doctoboggan•4h ago•205 comments

An SVG is all you need

https://jon.recoil.org/blog/2025/12/an-svg-is-all-you-need.html
91•sadiq•3h ago•36 comments

The highest quality codebase

https://gricha.dev/blog/the-highest-quality-codebase
373•Gricha•3d ago•269 comments

Litestream VFS

https://fly.io/blog/litestream-vfs/
189•emschwartz•5h ago•63 comments

The architecture of “not bad”: Decoding the Chinese source code of the void

https://suggger.substack.com/p/the-architecture-of-not-bad-decoding
37•Suggger•8h ago•31 comments

Show HN: Sim – Apache-2.0 n8n alternative

https://github.com/simstudioai/sim
113•waleedlatif1•5h ago•15 comments

Programmers and software developers lost the plot on naming their tools

https://larr.net/p/namings.html
98•todsacerdoti•5h ago•145 comments

Almond (YC X25) Is Hiring SWEs and MechEs

https://www.ycombinator.com/companies/almond-2/jobs
1•shawnpatel•2h ago

UK House of Lords attempting to ban use of VPNs by anyone under 16

https://alecmuffett.com/article/134925
176•nvarsj•2h ago•133 comments

Craft software that makes people feel something

https://rapha.land/craft-software-that-makes-people-feel-something/
210•lukeio•9h ago•110 comments

My productivity app is a never-ending .txt file (2020)

https://jeffhuang.com/productivity_text_file/
119•simonebrunozzi•3h ago•79 comments

Powder and Stone. Or, Why Medieval Rulers Loved Castles

https://1517.substack.com/p/powder-and-stone-or-why-medieval
4•areoform•1h ago•0 comments

Prove It All Night: With no fame or fortune, what keeps a band onstage? (1999)

https://chicagoreader.com/news/prove-it-all-night/
49•NaOH•1w ago•16 comments

The Walt Disney Company and OpenAI Partner on Sora

https://openai.com/index/disney-sora-agreement/
112•inesranzo•9h ago•384 comments

Launch HN: BrowserBook (YC F24) – IDE for deterministic browser automation

58•cschlaepfer•7h ago•31 comments

An Orbital House of Cards: Frequent Megaconstellation Close Conjunctions

https://arxiv.org/abs/2512.09643
74•rapnie•8h ago•41 comments

Auto-grading decade-old Hacker News discussions with hindsight

https://karpathy.bearblog.dev/auto-grade-hn/
555•__rito__•1d ago•247 comments

Going Through Snowden Documents, Part 1

https://libroot.org/posts/going-through-snowden-documents-part-1/
160•libroot•4h ago•89 comments

You gotta push if you wanna pull

https://www.morling.dev/blog/you-gotta-push-if-you-wanna-pull/
6•ingve•3d ago•1 comments

French supermarket's Christmas advert is worldwide hit (without AI) [video]

https://www.youtube.com/watch?v=Na9VmMNJvsA
169•gbugniot•9h ago•94 comments

iPhone Typos? It's Not Just You – The iOS Keyboard Is Broken [video]

https://www.youtube.com/watch?v=hksVvXONrIo
400•walterbell•7h ago•296 comments

Golang optimizations for high‑volume services

https://packagemain.tech/p/golang-optimizations-for-highvolume
33•der_gopher•3d ago•9 comments

RFC 6677 DNS Transport over TCP – Implementation Requirements

https://www.ietf.org/rfc/rfc7766.txt
6•1vuio0pswjnm7•1h ago•1 comments

EFF launches Age Verification Hub

https://www.eff.org/press/releases/eff-launches-age-verification-hub-resource-against-misguided-laws
189•iamnothere•1d ago•181 comments

Contact Sheet Prompting

https://www.willienotwilly.com/contact-sheet-prompting
14•handfuloflight•3d ago•2 comments

Deprecate like you mean it

https://entropicthoughts.com/deprecate-like-you-mean-it
49•todsacerdoti•7h ago•124 comments

Show HN: Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

https://github.com/privacyshield-ai/privacy-firewall
94•arnabkarsarkar•2d ago•40 comments

Helldivers 2 on-disk size 85% reduction

https://store.steampowered.com/news/app/553850/view/491583942944621371
239•SergeAx•1w ago•250 comments