How Egypt Switched Off The Internet
gigaom.com
gigaom.com
There is an interesting initiative in Spain (http://guifi.net/en/what_is_guifinet) that's trying to build an open (wifi-based, mesh-structured) network. Although the idea always seemed really cool to me, I thought that it was a hopeless effort. On the one hand, the "mainstream" network is much faster and reliable. On the other hand, you need a proxy node to reach the actual Internet.
Nonetheless, this specific news has opened my eyes about the importance of such non-government-controllable networks. For one, it would allow citizens to get in touch with eachother, escaping the government control. Additionally, a single proxy in a neighboring country would be enough so that news could leak.
For these reasons, I'm going to try to join this network asap. Further, I encourage you all to join any similar project going on near you, or try to build one if it doesn't exist.
Let the networking begin!
Related: http://en.wikipedia.org/wiki/List_of_wireless_community_netw...
Where can that be fixed? The nodes need to have the intelligence to route around potential rogue nodes.
In the UK the spectrum regulator is looking into "white space" use - basically even though this frequency is licensable, if you are using it in an area where no licensee's are, and you're under a certain power, that's fine. Assume that we can disconnect from their geo-location control databases, and burst transmit across many frequencies - jammers become an unrealistic problem.
But I fear that the actual end result will be an Egypt ruled by one of the Muslim extremist groups that operate there and which are far more organized and poised to take advantage of a power vacuum.
Does anyone know of an open-source stack for handsets?
That said I think it's excellent for the direction of future telco developments.
Even IM, SMS, and small still images are a threat to such regimes, especially in times like this.
Sure, GSM is ubiquitous, but WiFi is getting there and more commoditized. (Completely O.T. but I find the lack of people hacking their HP printers with WiFi in, quite a lack!)
We get closer and closer to a William Gibson-esque world all the time.
This is well within the budget for a well publicized Kickstarter campaign. Just a dozen of those in the capital city for 1 week would be extremely valuable.
But yes, I've been considering getting one on and off for 12 years. Sadly data over amateur radio doesn't appear to have progressed much in that time. Still, as voice comms it's pretty solid! Some countries UHF radio is still very popular (e.g. Australia).
I was looking at building a AX.25 node 10 years ago, with a 15km range on a basic amateur license, with maybe 28kbps. Almost all integrated into a radio with a digital output that cost the same as a PC.
That's what I mean about lack of progress... not much advanced today - it's a bit cheaper and easier, with better range, but no better bandwidth. If the frequencies & range are a fundamental issue, OK. When I was reading 10 years ago there was a strong dis-interest in data from my local groups, who thought it was ruining their voice comms. Still today I find the local amateur radio groups have little interest in packet radio beyond maybe running a webcam over AX.25. The interested HAMs are running community WiFi projects.
HAM radio is interesting, because it is the most decentralized form of communications. Cell phones are internet and land lines are all routed through some corporation or government entity. HAM radio relies only on RF propagation. Repeaters are another matter, they can be knocked out, but a decent HF tx will get you a good distance.
http://werebuild.eu/wiki/Egypt/Main_Page#Hamradio
"40m band, ~7-7.3 MHz LSB, 318.5 degrees(northwest/north from cairo), Friday night until the morning (16:00-05:00 UTC). ON/KC0SJH will be calling CQ"
They also seem to be coordinating free dialup links. Biggup.
it's trivial to jam most ham frequencies.
Edit: For comparison Egypt is about 387,000 sq miles.
I realize that you would not have to cover the entire country to be effective, but probably at least 90% of residential areas. Especially in Europe where the radio operators only need to reach over a nearby border.
will cover very sizable area without a problem.
When I lived in NYC I was really surprised to find out that most transatlantic cables terminated in this tall windowless building on Duane and Chambers street. If you basically took that building away you probably could turn off the internet for a good portion of people in the US. Or at the very least make it hard.
My point being - in Egypt there probably is a similar building that houses all of their DNS servers, lines to other countries, etc. So its not hard to believe that someone just decided to walk in and turn off the power.
In a nicely Pharaonic touch, one of the six ducts going
into the ground here is the sole property of President
Hosni Mubarak, or (presumably) whoever succeeds him as
head of state. It is hard to envision why a head of state
would want or need his own private tube full of air running
underneath the Sahara. The obvious guess is that the duct
might be used to create a secure communications system,
independent of the civilian and military systems (the
Egyptian military will own one of the six ducts, and ARENTO
will own three). This, in and of itself, says something
about the relationship between the military and the
government in Egypt.
If you have StyleBot, this makes it a lot more readable:http://www.wired.com/wired/archive/4.12/ffglass_pr.html
body {
width: 600px;
margin: auto;
line-height: 1.7;
}From what it seems like in the article, the Egyptian government coordinated with ISPs or forced ISPs to simply clear all of these entries. So for IP addresses in Egypt there are no corresponding routing rules, making them for all practical purposes completely taken off the internet since there is now no way to route traffic there.
http://news.bbc.co.uk/2/hi/7218008.stm
and this
A complete border shutdown might have been easier, but Egypt has made sure that there should be no downstream impact, no loss of traffic in countries further down the cables.
Would someone with more network knowledge speak to the role Border Gateway Protocol plays here?
Some of those radical activists with ocean-going ships should get themselves some kit to handle this eventuality. You could fit a lot of comm gear and some capable uplinks onboard. It would be a lot more useful than throwing debris at Japanese whalers.
What Egypt have done would be the equivalent of saying to it's air controllers "Any plane incoming for an Egyptian airport, tell them we don't know where it is." And the only option that plane has is to return home (real analogy: the message gets sent to the source airport and the plane disappears into a black hole).
However, any plane that wishes to fly through Egyptian airspace to reach other countries, that's fine, and get's it's routing directions just fine.
The alternatives that the article are talking about, closing down the "bottom" routers: close down all the airports, instead of the whole airspace. This has the same effect, but is harder to co-ordinate.
A complete border shutdown would be like unplugging the cables... any aircraft flying through the airspace would be blackholed, and aircraft attempting to fly in will be blackholed, any attempting to fly through will be blackholed... all with a polite notice of course.
DNS would be equivalent of keeping the airports open & saying "shut down all the screens and don't let any airline attendant tell people the gate that their plane is flying from" (except that are millions of gates...). If you're smart enough to have written it down (cached), or know the gate directly, then you're still going to make your flight. If you don't, you've no chance of making it. (Let's not add vhosts into the mix... okay, maybe for fun... like arriving at the plane, and them saying "this service stops at 100s of destinations, and you've lost your ticket, so we can't let you board").
Connectivity status for Egypt - http://mailman.nanog.org/pipermail/nanog/2011-January/031313... Egypt Telecom AS isolation - http://mailman.nanog.org/pipermail/nanog/2011-January/031377... 3500 Egyptian prefixes? - http://mailman.nanog.org/pipermail/nanog/2011-January/031407...
Personally the most interesting thing I see is O3b, which is maybe a year away.
Ku and L are good for limited markets, but just cost too much for YouTube users anywhere with terrestrial alternatives.
Bandwidth efficient protocols and proxies, combined with wifi and pirate gsm mesh networks, which can talk to unmodified laptops and cellphones for end users, are probably the best tech for situations like Egypt or post natural disaster.
Half of India's traffic to the rest of the world goes through Egypt (remember the undersea anchor incident?) and East Asia can route through Suez as well. If Suez goes down as a fiber gateway, suddenly all Asia <-> Europe traffic is forced to go through the US which would have implications
I don't think this instance proves how fragile the technology is, rather it proves that you can use this technology to build a system that is easily controlled from a central point. The same technology could have been used to build a robust system that was not easy to shut down completely.
More interesting would be if you happened to have satellite equipment already in country that they didn't know about or ask to have shut down. You can get a little l band terminal the size of a laptop, and a lotnof remote sites in egypt have real vsat links too.
Conceivably a problem if your providers billing server is in Egypt, even if your downlink is elsewhere, as the RAS probably can't talk to your authorisation server in your billing system...
So let that be a lesson to you if you buy a satellite service as a backup - go to a neighbouring country to get it! :-)
So your main issue is for .eg urls that are not cached in the DNS hierarchy you are using. Basically the root servers will direct you to one of (approx) three eg. root servers. These are probably down, or unreachable (due to BGP drops).
To my (basic) understanding of DNS, once your local server knows that ns[1-4].google.com is responsible for this domain, it doesn't need to go to the eg./eg.com. root servers to get updates.
And yes, you're probably getting directed to a "local" version of google.com.eg.