Post B0MoL09MXuFwSVjUIa by bagder@mastodon.social
 (DIR) More posts by bagder@mastodon.social
 (DIR) Post #B0MabjO0jAcC21fR4K by bortzmeyer@mastodon.gougere.fr
       2025-11-18T07:46:43Z
       
       0 likes, 0 repeats
       
       Good morning, Luxembourg! First of the Luxembourg Internet Days https://luxembourg-internet-days.com/Sent through the free Wifi access in the tramway :-)And sorry for not writing in Luxembourgish.
       
 (DIR) Post #B0MeGjoCMU5T4qA4qe by bortzmeyer@mastodon.gougere.fr
       2025-11-18T08:27:44Z
       
       0 likes, 0 repeats
       
       OK, now, what is the hashtag for the Luxembourg Internet Days?
       
 (DIR) Post #B0MeVNHeOJZNYpuuB6 by bortzmeyer@mastodon.gougere.fr
       2025-11-18T08:30:16Z
       
       0 likes, 0 repeats
       
       Why Lessons not Learned Become Incidents Repeated – Pro-active vs Reactive Cyber-Defence and why After the Attack is Before the AttackFirst round table at Luxembourg Internet Days. What do you think we need to do to save the Internet?
       
 (DIR) Post #B0MfIFVE6qnncNZX0a by bortzmeyer@mastodon.gougere.fr
       2025-11-18T08:39:12Z
       
       0 likes, 0 repeats
       
       « L'union fait la force » (in French, about cybersecurity)"Humans learn to walk by falling. Why don't we learn from cyberattacks? Are there not enough incidents?"
       
 (DIR) Post #B0Mfk30KAiSCxmNCC0 by trix@social.c3l.lu
       2025-11-18T08:43:48Z
       
       0 likes, 0 repeats
       
       @bortzmeyer it seems like some people are using #LuxembourgInternetDays over on LinkedIn
       
 (DIR) Post #B0Mfnx4GBZOVi44kvQ by bortzmeyer@mastodon.gougere.fr
       2025-11-18T08:44:12Z
       
       0 likes, 0 repeats
       
       "Not learning from mistakes is part of the human nature."A lot of catch phrases for my next slides on cybersecurity :-) #LuxembourgInternetDays
       
 (DIR) Post #B0MfrkiS3EB0YlgfhI by bortzmeyer@mastodon.gougere.fr
       2025-11-18T08:44:26Z
       
       0 likes, 0 repeats
       
       @trix OK, a bit long but it will do.
       
 (DIR) Post #B0MhwhPlx6ixg3R94C by bortzmeyer@mastodon.gougere.fr
       2025-11-18T09:08:59Z
       
       0 likes, 0 repeats
       
       "whois is a kind of repository". Awfully wrong, of course, but I noticed that .lu don't give a lot of details via whois, even, for corporations (try whois microsoft.lu)#LuxembourgInternetDays
       
 (DIR) Post #B0Mi6WhucK5jMfbjOK by bortzmeyer@mastodon.gougere.fr
       2025-11-18T09:10:46Z
       
       0 likes, 0 repeats
       
       "It is hard to notify people of security issues. There is a standard security.txt [RFC 9116] but nobody uses it."Correction, I do: https://www.bortzmeyer.org/.well-known/security.txt#LuxembourgInternetDays
       
 (DIR) Post #B0MiRzgW4gpdJmBuVM by bortzmeyer@mastodon.gougere.fr
       2025-11-18T09:14:37Z
       
       0 likes, 0 repeats
       
       Discussion about notification. Even when you get an email address, people don't reply to it / do nothing. One of the big frustrations in cybersecurity.#LuxembourgInternetDays(On the other hand, many reports are spurious, ask @bagder )
       
 (DIR) Post #B0Mj0n5EuxGAN5Lc0W by trix@social.c3l.lu
       2025-11-18T09:20:51Z
       
       0 likes, 0 repeats
       
       @bortzmeyer This makes me wonder, how "Expires" plays a role regarding PGP keys? Sure, the link might be the same, but the key('s expiry) could be updated.For instancesecurity,txt:> Expires: 2030-01-01T00:00:00Zlinked PGP key (at time of writing):> pub   rsa4096 2014-02-08 [SC] [expires: 2027-09-16]
       
 (DIR) Post #B0Mj72ugyXMjCjOfR2 by bortzmeyer@mastodon.gougere.fr
       2025-11-18T09:21:42Z
       
       0 likes, 0 repeats
       
       @trix Because there is other stuff in security.txt than PGP keys?
       
 (DIR) Post #B0MjC9XFmZyNBprvPc by gregr@mamot.fr
       2025-11-18T09:22:55Z
       
       0 likes, 0 repeats
       
       @bortzmeyer Microsoft toohttps://microsoft.com/.well-known/security.txt
       
 (DIR) Post #B0Mjdgv1luG8Xt7VxY by trix@social.c3l.lu
       2025-11-18T09:27:54Z
       
       0 likes, 0 repeats
       
       @bortzmeyer Nono, obviously the information is still valid, and technically the *link* to the PGP key is also still valid, even after an update.
       
 (DIR) Post #B0MnlC7qXlxTAvwviq by bortzmeyer@mastodon.gougere.fr
       2025-11-18T10:14:04Z
       
       0 likes, 0 repeats
       
       Official welcome speeches, now, at #LuxembourgIntenetDaysFirst, the chairman of the local exchange point https://www.lu-cix.lu/ insisting on the role of "open source" [sic] sofwtare in sovereignty (example of Matrix, which is not software, by the way, but a protocol).Then, a remote video from European commission '"Europe has three million open source developers", it seems a lot, I'm not sure I heard correctly). "We need more AI.'.
       
 (DIR) Post #B0MoDskzdPjDVDwIaW by bortzmeyer@mastodon.gougere.fr
       2025-11-18T10:19:17Z
       
       0 likes, 0 repeats
       
       Welcome talk by the Chamber of Commerce at #LuxembourgInternetDays.I learn about the Luxembourg super AI computer, #Meluxina.(I'm a  bit worried when people ask for more AI in the name of cybersecurity...)
       
 (DIR) Post #B0MoL09MXuFwSVjUIa by bagder@mastodon.social
       2025-11-18T10:19:48Z
       
       0 likes, 0 repeats
       
       @bortzmeyer I would be very interested to learn how they get to the number 3M and what they qualify as an open source developer in that context
       
 (DIR) Post #B0MoL1E0Y7Z9nCuiB6 by bortzmeyer@mastodon.gougere.fr
       2025-11-18T10:20:27Z
       
       0 likes, 0 repeats
       
       @bagder Yes, I was very surprised, too. May be a misunderstanding from me.
       
 (DIR) Post #B0MtCdc0xNyw0rxvo8 by bortzmeyer@mastodon.gougere.fr
       2025-11-18T11:14:56Z
       
       0 likes, 0 repeats
       
       Alain Courson, an insurance broker, on cybersecurity insurance at #LuxembourgInternetDays : "many companies are underinsured" I know next to nothing about financial issues in cybersecurity so it is interesting.What is *excluded* from insurance claims: gross negligence,failure to maintain security hygiene, missing backups... (It seems to me it will exclude most organisations.)
       
 (DIR) Post #B0Mtlvv8sVLyvnk6OO by bortzmeyer@mastodon.gougere.fr
       2025-11-18T11:21:30Z
       
       0 likes, 0 repeats
       
       I learn that insurance companies can pay the ransom. But it is typically the smallest expense in an attack.#ransomware #LuxembourgInternetDays
       
 (DIR) Post #B0N3F0brQGZxSXfAHo by bortzmeyer@mastodon.gougere.fr
       2025-11-18T13:07:32Z
       
       0 likes, 0 repeats
       
       Sovereignty at Stake: Protecting Critical SystemsA perfect title to restart#LuxembourgInternetDaysafter lunch.#Cloudflare
       
 (DIR) Post #B0N42OyPcy0NDBlPY8 by bortzmeyer@mastodon.gougere.fr
       2025-11-18T13:16:26Z
       
       0 likes, 0 repeats
       
       Proposed : "federated sovereign WAN"  (I guess it will be more swiss propaganda for Scion).#LuxembourgInternetDays
       
 (DIR) Post #B0N7UzBWt3V9UUDk3M by gjherbiet@mamot.fr
       2025-11-18T13:55:15Z
       
       1 likes, 2 repeats
       
       @bortzmeyer I suggest you check whether the home site of each presenter’s company is still up while #cloudflare is down and only listen if it works…
       
 (DIR) Post #B0N7bw2Czx8dkOAsrY by bortzmeyer@mastodon.gougere.fr
       2025-11-18T13:55:59Z
       
       0 likes, 0 repeats
       
       @gjherbiet You're too mean :-) #LuxembourgInternetDays
       
 (DIR) Post #B0N7fT8qMbZVINxm6q by bortzmeyer@mastodon.gougere.fr
       2025-11-18T13:56:46Z
       
       0 likes, 0 repeats
       
       @gjherbiet The current speaker: https://www.mtxc.eu/
       
 (DIR) Post #B0N9FmwCL7ap4Svkjg by bortzmeyer@mastodon.gougere.fr
       2025-11-18T14:14:58Z
       
       0 likes, 0 repeats
       
       The national data protection authority https://cnpd.public.lu/fr.html is not on Cloudflare (unlike the French one). @gjherbiet #LuxembourgInternetDays
       
 (DIR) Post #B0N9pBsXbLtkYl6KHI by bortzmeyer@mastodon.gougere.fr
       2025-11-18T14:21:22Z
       
       0 likes, 0 repeats
       
       Cyber Resilience Act: challenges & considerationsStarts with a demonstration about trust and quality, with chocolate (will you try it?)#LuxembourgInternetDays
       
 (DIR) Post #B0NA70CvjWBXZh8CKe by R1Rail@pouet.chapril.org
       2025-11-18T14:23:29Z
       
       0 likes, 0 repeats
       
       @bortzmeyer Cyberresilence, un jour de panne de cloudflare, y'a plein d'exemples là...
       
 (DIR) Post #B0NA70z8qGkXzDghTk by bortzmeyer@mastodon.gougere.fr
       2025-11-18T14:24:23Z
       
       0 likes, 0 repeats
       
       @R1Rail Au moins, l'oratrice de la CNPD a un site Web pro qui marche, contrairement aux DPA de France ou de Grande-Bretagne, qui sont chez Clouflare.
       
 (DIR) Post #B0NArvaEk8IyqNPO1w by bortzmeyer@mastodon.gougere.fr
       2025-11-18T14:33:05Z
       
       0 likes, 0 repeats
       
       I got one to test.
       
 (DIR) Post #B0NBnNhqr6sGZUMlQe by bortzmeyer@mastodon.gougere.fr
       2025-11-18T14:43:25Z
       
       0 likes, 0 repeats
       
       I did not know DRaaS (Digital Recovery as a Service). But it seems just an empty marketing term.#LuxembourgInternetDays
       
 (DIR) Post #B0NEMqkt2mz6i0pIJs by bortzmeyer@mastodon.gougere.fr
       2025-11-18T15:12:16Z
       
       0 likes, 0 repeats
       
       Switching to French because the talk is in FrenchLuxchat4Pro – La messagerie instantanée souveraine pour les professionnels#Luxchat  est opéré par LU-CIX, le point d'échange.Il utilise #Matrix (comme le #Tchap français, mais Luxchat est ouvert au public.) Chiffrement de bout-en-bout, serveur au Luxembourg.#LuxembourgInternetDays
       
 (DIR) Post #B0NFCZf5qGtSkjmS24 by gmassen@mastodon.opencloud.lu
       2025-11-18T15:21:31Z
       
       0 likes, 0 repeats
       
       @bortzmeyer You guessed well :-)
       
 (DIR) Post #B0NFIw1jbN71r3P61Y by rafi0t@social.yoyodyne-it.eu
       2025-11-18T15:17:11Z
       
       0 likes, 0 repeats
       
       @bortzmeyer c'est juste un peu fédéré par contre: https://www.luxchat.lu/ecosysteme/
       
 (DIR) Post #B0NFIxAdLlpDOwZiXA by bortzmeyer@mastodon.gougere.fr
       2025-11-18T15:22:43Z
       
       0 likes, 0 repeats
       
       @rafi0t Oui, l'orateur confirme. C'est fermé par défaut.
       
 (DIR) Post #B0NFN2omILGU4iIqjQ by adulau@infosec.exchange
       2025-11-18T15:17:39Z
       
       0 likes, 0 repeats
       
       @bortzmeyer La fédération n'est pas activée sauf avec quelques serveurs matrix. Tout est chouette sauf cette partie.
       
 (DIR) Post #B0NFN4CDAhbULgH4tc by bortzmeyer@mastodon.gougere.fr
       2025-11-18T15:22:47Z
       
       0 likes, 0 repeats
       
       @adulau Oui, l'orateur confirme. C'est fermé par défaut.
       
 (DIR) Post #B0NFdh5oK25NcOD1Ye by gmassen@mastodon.opencloud.lu
       2025-11-18T15:26:28Z
       
       0 likes, 0 repeats
       
       @bortzmeyer @adulau Il y a des raisons pertinentes. Qui ne convainquent pas tout le monde, mais au moins c'est fondé.
       
 (DIR) Post #B0NFgfn5cS2CRtsBYu by adulau@infosec.exchange
       2025-11-18T15:25:28Z
       
       0 likes, 0 repeats
       
       @bortzmeyer C'est vraiment dommage, car cela aurait pu faire la différence.
       
 (DIR) Post #B0NFghGY8PC51YfE7U by bortzmeyer@mastodon.gougere.fr
       2025-11-18T15:26:50Z
       
       0 likes, 0 repeats
       
       @adulau Et l'argument du spam cité par l'orateur, n'est pas très convaincant. Le serveur publlc que j'utilise ne voit guère de spam. En fait, l'absence de spam montre que Matrix n'est pas largement adopté.
       
 (DIR) Post #B0NTKGx4giEAOqkwJk by gub@framapiaf.org
       2025-11-18T17:59:49Z
       
       0 likes, 0 repeats
       
       @bortzmeyer Tu as trouvé un easter egg ?
       
 (DIR) Post #B0P6P341qBSW96El1s by formidableinc@framapiaf.org
       2025-11-19T12:52:26Z
       
       0 likes, 0 repeats
       
       @bortzmeyer ah le sondage est très bipolarisé et je n'aurai pas imaginé cet ensemble :)