<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems.]]></title><description><![CDATA[<p>I reported an insecure DKIM key to Deutsche Telekom / T-Systems. They first asked me to further explain things (not sure why 'Here's your DKIM private key' needs more explanation, but whatever...). Then they told me it's out of scope for their bugbounty.</p><p>I guess then there's really no reason not to tell you: They have a 384 bit RSA DKIM key configured at: dkim._domainkey.t-systems.nl</p><p>384 bit RSA is... how shall I put it? I think 512 bit is the lowest RSA key size that was ever really used. 384 bit RSA is crackable in a few hours on a modern PC (using cado-nfs). The private key is:<br />-----BEGIN RSA PRIVATE KEY-----<br />MIHxAgEAAjEAtTliQYV2Xvx1OGkDyOL799BTFEuobY2dn2AgtiKCQgrh78NVK1JK<br />j0yRXgNnPpGBAgMBAAECMF0t+TBZUCi8xATSMij7VLTxv5Xi5OIXesNiXOKtYIRP<br />LkpYfR5PggaMScfbmqSssQIZAMwOhm9d7Y7Qi7I2j1AlYbiqdtqO54T7FQIZAONa<br />9dJFkC6lM3EPXR+0SZ4dqwwpiM0nvQIYYgz8thi5JK264ohq9sTvnu9yKvUN9I09<br />AhgfgMYZKcxtujRjkSZtMzUUNLYzzDmJe90CGDKwqcBI0v9ChaR8WHht+/chMdxj<br />7ez94w==<br />-----END RSA PRIVATE KEY-----</p>]]></description><link>https://forum.fedi.dk/topic/564bbb5b-889b-419a-9d93-f846c14fec8b/i-reported-an-insecure-dkim-key-to-deutsche-telekom-t-systems.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 27 Apr 2026 13:54:23 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/564bbb5b-889b-419a-9d93-f846c14fec8b.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 15 Apr 2026 07:34:51 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Thu, 16 Apr 2026 07:27:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> Hab mich damit auch schon herum geärgert und mit einem "Musterbrief" frei gekauft: <a href="https://beko.famkos.net/2023/06/02/%c2%b7t%c2%b7%c2%b7%c2%b7error/" rel="nofollow noopener"><span>https://</span><span>beko.famkos.net/2023/06/02/%c2</span><span>%b7t%c2%b7%c2%b7%c2%b7error/</span></a></p><p>Die haben doch echt nicht mehr alle Latten am Zaun o0</p>]]></description><link>https://forum.fedi.dk/post/https://indieweb.social/users/bekopharm/statuses/116413198864958767</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://indieweb.social/users/bekopharm/statuses/116413198864958767</guid><dc:creator><![CDATA[bekopharm@indieweb.social]]></dc:creator><pubDate>Thu, 16 Apr 2026 07:27:25 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 23:04:33 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.social/@keksdosenmann">@<span>keksdosenmann</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> </p><p>Die schaffen uns. <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f62e.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--open_mouth" style="height:23px;width:auto;vertical-align:middle" title="😮" alt="😮" />‍<img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f4a8.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--dash" style="height:23px;width:auto;vertical-align:middle" title="💨" alt="💨" /></p>]]></description><link>https://forum.fedi.dk/post/https://23.social/users/christianrickert/statuses/116411221540254669</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://23.social/users/christianrickert/statuses/116411221540254669</guid><dc:creator><![CDATA[christianrickert@23.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 23:04:33 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 22:30:17 GMT]]></title><description><![CDATA[<p>things. And are shocked that email can be provided by something else then Google, outlook or Apple. On which of these is our email hosted I was asked. I had to explain very slowly that we are on the small option "other".<br /><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> <span><a href="https://social.bund.de/@BNetzA">@<span>BNetzA</span></a></span> <span><a href="/user/eucommission%40ec.social-network.europa.eu">@<span>EUCommission</span></a></span>  <span><a href="/user/bebef%40mastodon.social">@<span>Bebef</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411086772153234</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411086772153234</guid><dc:creator><![CDATA[yacc143@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 22:30:17 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 22:30:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/bebef%40mastodon.social">@<span>Bebef</span></a></span><br />The really odd thing is it's not the oldies that nowadays are a problem, it's the youngsters, we literally had a complaint today about the PIM/office suite we use, our CEO nicely played that one. He's open to all proposals for alternatives from a company headquartered in the EEA for legal reasons.</p><p>Interestingly the C level has no problem IMAP, and accessing the calendar over CalDAV. But the youngsters have never heard of these   <span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> <span><a href="https://social.bund.de/@BNetzA">@<span>BNetzA</span></a></span> <span><a href="/user/eucommission%40ec.social-network.europa.eu">@<span>EUCommission</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411086704805720</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411086704805720</guid><dc:creator><![CDATA[yacc143@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 22:30:16 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 22:28:42 GMT]]></title><description><![CDATA[<p><a href="https://infosec.exchange/@badkeys">@badkeys@infosec.exchange</a> ..OMFG ..​<img class="not-responsive emoji" src="https://misskey-taube.s3.eu-central-1.wasabisys.com/files/e8f397af-5ff2-4f9c-9f70-94724ed5c263" title=":ablobcatcrumpled:" />​</p>]]></description><link>https://forum.fedi.dk/post/https://mk.absturztau.be/notes/al46s2kws91z0027</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mk.absturztau.be/notes/al46s2kws91z0027</guid><dc:creator><![CDATA[kate@mk.absturztau.be]]></dc:creator><pubDate>Wed, 15 Apr 2026 22:28:42 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 22:17:31 GMT]]></title><description><![CDATA[<p><span><a href="/user/bebef%40mastodon.social">@<span>Bebef</span></a></span><br />It's probably not, some countries have really tough laws that they apply to email delivery and privacy that makes even spam filtering a legally dicey proposition</p><p>But let me put it like this, who wants to sue a company that has a legal budget bigger than the whole government budget of some of the poorer EU MS?</p><p>And in the end as long as the users won't start moving their fat posteriors away from the big tech monopolies, ...<br /><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> <span><a href="https://social.bund.de/@BNetzA">@<span>BNetzA</span></a></span> <span><a href="/user/eucommission%40ec.social-network.europa.eu">@<span>EUCommission</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411036560307936</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116411036560307936</guid><dc:creator><![CDATA[yacc143@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 22:17:31 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 20:56:28 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> Telekom. Die machen das.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/keksdosenmann/statuses/116410717850657902</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/keksdosenmann/statuses/116410717850657902</guid><dc:creator><![CDATA[keksdosenmann@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 20:56:28 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 20:31:02 GMT]]></title><description><![CDATA[<p><span><a href="https://glauca.space/@q" rel="nofollow noopener">@<span>q</span></a></span> <span><a href="/user/16af93%40wetdry.world" rel="nofollow noopener">@<span>16af93</span></a></span> <span><a href="/user/badkeys%40infosec.exchange" rel="nofollow noopener">@<span>badkeys</span></a></span> iirc 256-bit rsa is satcomms 'standards'</p>]]></description><link>https://forum.fedi.dk/post/https://www.librepunk.club/users/sys64738/statuses/116410617868295662</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://www.librepunk.club/users/sys64738/statuses/116410617868295662</guid><dc:creator><![CDATA[sys64738@www.librepunk.club]]></dc:creator><pubDate>Wed, 15 Apr 2026 20:31:02 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 20:17:32 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span><br />That was crackable with private entity resources decades ago. </p><p>That's not even funny.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116410564778733371</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/yacc143/statuses/116410564778733371</guid><dc:creator><![CDATA[yacc143@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 20:17:32 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 20:15:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/16af93%40wetdry.world" rel="nofollow noopener">@<span>16af93</span></a></span> <span><a href="/user/badkeys%40infosec.exchange" rel="nofollow noopener">@<span>badkeys</span></a></span> for once, its not the Germans</p>]]></description><link>https://forum.fedi.dk/post/https://glauca.space/users/q/statuses/116410556353269138</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://glauca.space/users/q/statuses/116410556353269138</guid><dc:creator><![CDATA[q@glauca.space]]></dc:creator><pubDate>Wed, 15 Apr 2026 20:15:24 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 20:00:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/kkarhan%40jorts.horse">@<span>kkarhan</span></a></span> <span><a href="/user/momo%40social.linux.pizza">@<span>momo</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> <span><a href="https://social.bund.de/@BNetzA">@<span>BNetzA</span></a></span> <span><a href="/user/eucommission%40ec.social-network.europa.eu">@<span>EUCommission</span></a></span> Had the same issue just recently. I wonder how this can even be legal. <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f914.png?v=7979fdcf9c7" class="not-responsive emoji emoji-android emoji--thinking_face" style="height:23px;width:auto;vertical-align:middle" title="🤔" alt="🤔" /></p><p>I wanted to ask a lawyer about this, but never came around doing so.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/Bebef/statuses/116410499242582380</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/Bebef/statuses/116410499242582380</guid><dc:creator><![CDATA[bebef@mastodon.social]]></dc:creator><pubDate>Wed, 15 Apr 2026 20:00:52 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 19:58:14 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@badkeys" rel="nofollow noopener">@<span>badkeys@infosec.exchange</span></a></span></p><p>send an email coming from them.</p>]]></description><link>https://forum.fedi.dk/post/https://app.wafrn.net/fediverse/post/6e4be629-dd7e-4221-8ab5-79fa53503073</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://app.wafrn.net/fediverse/post/6e4be629-dd7e-4221-8ab5-79fa53503073</guid><dc:creator><![CDATA[irelephant@app.wafrn.net]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:58:14 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 19:20:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/millie%40infosec.exchange">@<span>millie</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> thank you, I get it now.  Iguess I'm having a slow day!</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116410341219776870</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116410341219776870</guid><dc:creator><![CDATA[dragonfrog@mastodon.sdf.org]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:20:41 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 19:17:36 GMT]]></title><description><![CDATA[<span><a href="/user/mcr314%40todon.nl" rel="ugc">@<span>mcr314</span></a></span> <span><a href="https://infosec.exchange/@badkeys" rel="ugc">@<span>badkeys</span></a></span> Source? I doubt someone who makes a mistake like this knows what ECDSA is.]]></description><link>https://forum.fedi.dk/post/https://infosec.place/objects/c41c11ad-f601-412a-8472-f24609810b57</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.place/objects/c41c11ad-f601-412a-8472-f24609810b57</guid><dc:creator><![CDATA[buherator@infosec.place]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:17:36 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 19:12:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/dragonfrog%40mastodon.sdf.org">@<span>dragonfrog</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> No, the private key was never published by t-systems, but it's so weak that it's very easy to crack. OP cracked and published the private key.</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/millie/statuses/116410309670796122</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/millie/statuses/116410309670796122</guid><dc:creator><![CDATA[millie@infosec.exchange]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:12:39 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 19:10:43 GMT]]></title><description><![CDATA[<p><span><a href="/user/millie%40infosec.exchange">@<span>millie</span></a></span> <span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> <br />Oh gosh, so they've removed the private key, but it's still the public key that goes with a private key that they already published.</p><p>A sound as if a thousand faces rested in a thousand palms, and a thousand IT people sighed heavily...</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116410302054379571</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116410302054379571</guid><dc:creator><![CDATA[dragonfrog@mastodon.sdf.org]]></dc:creator><pubDate>Wed, 15 Apr 2026 19:10:43 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 18:50:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place">@<span>buherator</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> No, they thought they were generating an ECDSA key, for which a 256 or 384 bit would be strong.  But, they didn't provide the right arguments, and wound up with RSA.  I think the OP posted the private key that they were able to crack trivially.</p>]]></description><link>https://forum.fedi.dk/post/https://todon.nl/users/mcr314/statuses/116410223621733588</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://todon.nl/users/mcr314/statuses/116410223621733588</guid><dc:creator><![CDATA[mcr314@todon.nl]]></dc:creator><pubDate>Wed, 15 Apr 2026 18:50:46 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 18:45:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/dragonfrog%40mastodon.sdf.org">@<span>dragonfrog</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> Most people might not be fluent in base64-encoded ASN.1, but a trained eye can see that it's the same key.</p><p>Hint: A sufficiently strong RSA key cannot possibly be that short, and you know it's a DER-encoded pubkey because it starts with "ME"  and ends with "AQAB" (0x10001, common RSA public exponent)</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/millie/statuses/116410201410937005</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/millie/statuses/116410201410937005</guid><dc:creator><![CDATA[millie@infosec.exchange]]></dc:creator><pubDate>Wed, 15 Apr 2026 18:45:08 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 18:29:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/buherator%40infosec.place">@<span>buherator</span></a></span> <span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> </p><p>I installed a MariaDB cluster backed set of PowerDNS servers for that exact reason!  There were a couple of other reasons but that was what finally made me roll up my sleeves.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodonapp.uk/users/gerdesj/statuses/116410141872272493</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodonapp.uk/users/gerdesj/statuses/116410141872272493</guid><dc:creator><![CDATA[gerdesj@mastodonapp.uk]]></dc:creator><pubDate>Wed, 15 Apr 2026 18:29:59 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 18:02:53 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span> bruh</p>]]></description><link>https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116410035292999169</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://ioc.exchange/users/wall_e/statuses/116410035292999169</guid><dc:creator><![CDATA[wall_e@ioc.exchange]]></dc:creator><pubDate>Wed, 15 Apr 2026 18:02:53 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 16:46:36 GMT]]></title><description><![CDATA[<span><a href="https://infosec.exchange/@badkeys" rel="ugc">@<span>badkeys</span></a></span> My educated guess is they couldn't fit larger keys into their DNS records...]]></description><link>https://forum.fedi.dk/post/https://infosec.place/objects/ced8b468-c85d-4b8d-9fae-d275d56f8ff5</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.place/objects/ced8b468-c85d-4b8d-9fae-d275d56f8ff5</guid><dc:creator><![CDATA[buherator@infosec.place]]></dc:creator><pubDate>Wed, 15 Apr 2026 16:46:36 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 16:41:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/momo%40social.linux.pizza" rel="nofollow noopener noreferrer">@<span>momo</span></a></span> <span><a href="https://infosec.exchange/@badkeys" rel="nofollow noopener noreferrer">@<span>badkeys</span></a></span> sadly this is being normalized today.</p><ul><li><a href="https://jorts.horse/tags/Microsoft" rel="tag">#<span>Microsoft</span></a> literally demands people to self-d0x or they just silently drop all eMails, even replies to their customers.<ul><li>And OFC neither <span><a href="https://social.bund.de/@BNetzA" rel="nofollow noopener noreferrer">@<span>BNetzA</span></a></span> nor <span><a href="/user/eucommission%40ec.social-network.europa.eu" rel="nofollow noopener noreferrer">@<span>EUCommission</span></a></span>  did anything about this.</li></ul></li></ul>]]></description><link>https://forum.fedi.dk/post/https://jorts.horse/users/kkarhan/statuses/116409716311917598</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://jorts.horse/users/kkarhan/statuses/116409716311917598</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Wed, 15 Apr 2026 16:41:46 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 16:35:35 GMT]]></title><description><![CDATA[<p><span><a href="/user/badkeys%40infosec.exchange">@<span>badkeys</span></a></span> <br />Looks like they've fixed it now (?)</p><p>The TXT record is now<br />"v=DKIM1; k=rsa; g=*; s=email; p=MEwwDQYJKoZIhvcNAQEBBQADOwAwOAIxALU5YkGFdl78dThpA8ji+/fQUxRLqG2NnZ9gILYigkIK4e/DVStSSo9MkV4DZz6RgQIDAQAB"</p><p>I really hope they generated a new key, and didn't just switch from publishing the private key to the corresponding public one...</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116409692026086423</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.sdf.org/users/dragonfrog/statuses/116409692026086423</guid><dc:creator><![CDATA[dragonfrog@mastodon.sdf.org]]></dc:creator><pubDate>Wed, 15 Apr 2026 16:35:35 GMT</pubDate></item><item><title><![CDATA[Reply to I reported an insecure DKIM key to Deutsche Telekom &#x2F; T-Systems. on Wed, 15 Apr 2026 15:37:27 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@badkeys">@<span>badkeys</span></a></span><br />Do they accept mails from noncommercial mailservers at their nl branch or do they refuse them with "554 None/Bad Reputation" as the german branch does, unless the mail admin publishes full personal (!) contact infos on a webserver hosted on the smtp machine? Just asking, because THOSE guys behave like they wrote the SMTP RFCs all by themselves...</p>]]></description><link>https://forum.fedi.dk/post/https://social.linux.pizza/users/momo/statuses/116409463450565355</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://social.linux.pizza/users/momo/statuses/116409463450565355</guid><dc:creator><![CDATA[momo@social.linux.pizza]]></dc:creator><pubDate>Wed, 15 Apr 2026 15:37:27 GMT</pubDate></item></channel></rss>