<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet href="http://www.trend-watcher.org/styles/rss.css" type="text/css"?>
<rss version="0.91">

 <channel>
  <title>Trend-Watcher</title>
  <link>http://www.trend-watcher.org/blog/1</link>
  <description></description>
    <item>
   <title>On Death and Rollovers</title>
   <description>   I just posted this to the unbound-users list    In Geoff Huston's recent  ISP Column &quot;Roll Over and Die?&quot; , Roy Arends made a&nbsp;thorough analysis of the behavior of Unbound in the face of increased traffic towards authoritative servers after a failed key-rollover.  Key of Roy's analysis is the observation that Unbound holds back after finding a bogus DNSKEY but does that on a per query instead of&nbsp;a per zone basis.  	The default value of 60 seconds causes UNBOUND to restrain itself. However, since its a per-message cache, it only restrains itself&nbsp;for that qname/qclass/qtype tuple. Hence, if a different query is asked, UNBOUND needs to validate the response, sees a bogus DNSKEY&nbsp;in the cache and starts to re-fetch the dnskey keyset. In other words, a lame root key will cause DNSKEY queries for every unique&nbsp;query seen per 60 second window.   We will address this using a caching mechanism that will treat DNSSEC validation failures on a zone wide basis instead of treating&nbsp;them as intermittent RR-set failures. That should reduce the traffic to authoritative servers significantly.  The reason why this particular problem is interesting is that, as developers, we are constantly trying to make the tradeoff between&nbsp;the ability to recover from failure and the costs that those recovery mechanism impose on third parties. Failure to validate a&nbsp;signature can have many reasons, varying from misconfiguration or synchronization failure at the authoritative side, to on-path&nbsp;failure or attack, to misconfiguration a the receiving side. In this case we have not been conservative enough when making the trade-offs.&nbsp;  The fact that these sort of issues are identified are a healthy sign of what is still early deployment and we are eager to learn from&nbsp;these experiences. We use two resources for gathering experience that can help us making implementation choices: the IETF DNSOP&nbsp;working group and&nbsp; OARC . OARC is an organization where data is collected and shared so that impact of&nbsp;certain implementation behavior is quantified. We would like to ask people to contribute measurement data and share experiences.&nbsp;  Back to the particular issue of stale keys. The column points out that there are mechanisms to prevent stale keys being retained after&nbsp;a key rollover: the mechanism described in RFC5011. As of version 1.4.0 Unbound has native support for maintaining the trust-anchor&nbsp;for key-rollovers based on RFC5011. We have also made &quot;autotrust&quot; &lt;link&gt; available for cases where trust-anchors need to be maintained&nbsp;&nbsp;and Unbound is not used.  In the particular case described in the columnm, RFC5011 methodology might not have worked; an old OS distribution carrying a stale&nbsp;key that is several generations old cannot be tracked using RFC5011 techniques. Wijngaards and Kolkman have been working on a proposal&nbsp;to fix that particular issue: &quot; DNSSEC Trust Anchor History Service  </description>
   <link>http://www.trend-watcher.org/post/1/140</link>
      <pubDate>Fri, 12 Feb 2010 14:29:48 +0100</pubDate>   
  </item>
    <item>
   <title>Beef Wellington</title>
   <description>  Beef Wellington is a dish made with a fine piece Tenderloin ('Ossehaas' in Dutch). It is a good piece of meat for days with festivities because part of the preparation can be done in the morning (they take about 30 min) and part of the preparation can be done approximately one hour before the dish is to be served. Since it needs to sit in the oven for about 30 min+ 5-10 min resting time. You have a time slot to prepare for your vegetables.  &nbsp;  Early in the day.  &nbsp;  Clarify butter.  &nbsp;    Starts off by preparing 'Duxelles'. A dry mixture of finely chopped shallots and mushroom.  &nbsp;   					 500 gr finely chopped mushrooms 				 3-4 shallots finely chopped shallots 				 4 tablespoons of Madeira (you can use Port wine too) 				 4 tablespoons of cream    Fry the shallots and mushrooms in the clarified butter until all moisture has evaporated from the mix. Then add the Madeira and the cream. Keep steering until the mix occurs dry. If the mix is to wet it will interact badly with the dough in bad ways later.   &nbsp;   &nbsp;&nbsp;Next step is to brown the beef (a Tenderloin of 1-1.5 kg). As always with beef use a heavy pan (high heat capacity), make sure you use plenty of fat (also heat capacity) and keep moving the meet around while browning it. In about 5 minutes your beef will be golden brow. Let it rest for at least 10 min (but you can allow it to cool down until the afternoon).   Timewarp    About 1 hour before serving you will need to finish the Duxelles by mixing it with about 125 gr of Pate de Foix Gras d'Oi. Then take your beef and cover the lot with the Duxelles.  &nbsp;  Now take sufficient leaves of prefab (ouch) puff pastry and stick them together with egg-whites. You should have sufficient area to cover the whole beef. Put the Beef on top of the pastry and close the pastry. Put the lot on a piece of baking paper with the puff pastry seams down. Cut a few figures and put on top. Cover with egg-yoke in order to achieve a nice color. Bake in the oven for about 30 minutes and let rest for another 10 minutes. &nbsp;     &nbsp;       </description>
   <link>http://www.trend-watcher.org/post/1/139</link>
      <pubDate>Sun, 27 Dec 2009 15:40:34 +0100</pubDate>   
  </item>
    <item>
   <title>Ringo Kun</title>
   <description>  To be posted in the&nbsp; IETF Journal  &nbsp;  &nbsp;   Although the result is seemingly trivial this cartoon was a bit of a challenge as I was trying to get a Manga look and feel. Both sketching and inking and the digital post-processing took some practicing and a few retries.&nbsp;  The puny-code and the two big characters represent the word &quot;Manga&quot;. The name of the protagonist in this cartoon 'Ringo Kun' is written in the head band. The name is a obscure reference... a bit of a bad joke actually. </description>
   <link>http://www.trend-watcher.org/post/1/138</link>
      <pubDate>Mon, 21 Dec 2009 13:16:31 +0100</pubDate>   
  </item>
    <item>
   <title>Old documentation</title>
   <description>    In 1993 I had to serve and as my civil service I worked on the User Documentation for the Westerbork Synthesis Radio telescope. I found the material in a forgotten directory. I looked whether it was still available on the web but couldn't find it. For historic purposes and sentimental reasons:   	  Part 0 &nbsp;THE WESTERBORK SYNTHESIS RADIO TELESCOPE USER DOCUMENTATION 	  Part 1 &nbsp;PROPOSING FOR WSRT OBSERVING TIME 	  Part 2 &nbsp;INTRODUCTION TO THE THEORY OF APERTURE SYNTHESIS 	  Part 3 &nbsp;SPECIFIC ASPECTS OF THE WSRT 	  Part 4 &nbsp;CALIBRATION AND REDUCTION OF WSRT DATA 	  Part 5 &nbsp;VARIOUS 	  Update 1 &nbsp;UPDATE    All this material is hopelessly out of date. Check&nbsp; http://www.astron.nl/ &nbsp;for current information on the WSRT.  &nbsp; </description>
   <link>http://www.trend-watcher.org/post/1/137</link>
      <pubDate>Wed, 30 Sep 2009 23:39:17 +0200</pubDate>   
  </item>
    <item>
   <title>Net Neutrality</title>
   <description>  To be posted in the&nbsp; IETF Journal  &nbsp;  &nbsp;    </description>
   <link>http://www.trend-watcher.org/post/1/136</link>
      <pubDate>Tue, 22 Sep 2009 12:08:02 +0200</pubDate>   
  </item>
    <item>
   <title>woord van de dag</title>
   <description>  draalloos   synoniem voor  onverwijld  (het woord van de week) </description>
   <link>http://www.trend-watcher.org/post/1/135</link>
      <pubDate>Fri, 03 Jul 2009 15:01:10 +0200</pubDate>   
  </item>
    <item>
   <title>Limerick of the day</title>
   <description>     Waarschuwing   &nbsp;  Aan meisjes met kokette laarsjes  voor een man die woont in De Baarsjes  wees &nbsp;op je hoede  voor die engerd z'n roede  want hij steekt hem heel gaarne in aarsjes&nbsp;  &nbsp;   &nbsp;    (S  preek uit : k   o   -kette in plaats van ko-k   e   tte)&nbsp;  </description>
   <link>http://www.trend-watcher.org/post/1/134</link>
      <pubDate>Wed, 01 Jul 2009 13:18:53 +0200</pubDate>   
  </item>
    <item>
   <title>Marvelous Idea</title>
   <description>    &nbsp;  To be posted in the&nbsp; IETF Journal   &nbsp;  &nbsp;  &nbsp;   &nbsp; </description>
   <link>http://www.trend-watcher.org/post/1/133</link>
      <pubDate>Thu, 14 May 2009 23:46:10 +0200</pubDate>   
  </item>
    <item>
   <title>Welcome Wagon (Welcome to)</title>
   <description>  A few weeks ago I listened to &quot;Welcome to the Welcome Wagon&quot; on the excellent VPRO Luisterpaal (http://3voor12.vpro.nl/luisterpaal/). I ordered the CD and today it has been delivered by mail.    The reason I happily pay a few extra bucks for a CD is that there is artwork included and in this case the artwork provides a little background about the work.  This album was recorded and produced by Sufjan Steven and his musical touch stands out. What I did not know is that the music was composed and performed by Pastor Vito Aiuto and his Monique Aiuto. The music classifies itself as folk/gospel.  I do not regularly look at music in the Gospel category. The reason is twofold. First the message does not appeal to me, and second, and more important, is that Gospel music is often stereotypical and not inspired.  This album is different. Although it clearly has a religious message it is inspired,  made with the appropriate lower belly feelings, and sometimes has a touch of humor. The album is cleanly produced, lighthearted but still has balls. Proof? At the moment I wrote this paragraph the tune &quot;American Legion&quot; is played, it brings tears to my eyes...  While I do not believe in God there are emotions that one could classify as religious.  Sometimes they are communicated through music. And while not true for all tracks this album contains such an examples.  Read more about &quot;Welcome to the Welcome Wagon&quot; at&nbsp; Asthmatic Kitty Records .&nbsp;  &nbsp;&nbsp;      </description>
   <link>http://www.trend-watcher.org/post/1/132</link>
      <pubDate>Fri, 16 Jan 2009 14:13:51 +0100</pubDate>   
  </item>
    <item>
   <title>Pillow Talk</title>
   <description> &nbsp;  	 	 	B : I hate your guts 	 	D : Why? Do I remind you of yourself? 	 	B : Nah... you murdering sonofabitch. I only scare them, break their 	legs, and occasionally cause a cardiac arrest --frighten them to death-- while 	you continue to cross the line. 	 	D : Which line, your line? 	I never cross my line. Harry's code helps me to ... 	 	B : Henry's fucking code. You working on my nerves, damned.	It never takes more than 20 seconds before you bring up Henry's 	code. Its a damned lame excuse for your nocturnal cutting-a-psychopath	tours. 	 	D : And how are those different from your nocturnal scaring-a-psychopath	tour? 	...  [silence] ... 	 D : and his name is Harry, not Henry, you fuckface 	 B : You sound like your sister now 	..  [silence] ... 	 D : According to the code I should kill you 	 	B : And I should make you relive your worst nightmare a dozen times...	That kind of terror worked with others. 	 	D : Not with me, not with me, thanks to Harry. 	 	B : Fuck Harry. 	 	D : Fuck you, Bruce 	 	B : Not today Dexter, sleep well. 	 	D : sleep well, sweet dreams   </description>
   <link>http://www.trend-watcher.org/post/1/131</link>
      <pubDate>Tue, 06 Jan 2009 20:59:32 +0100</pubDate>   
  </item>
   </channel>
</rss>

