Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
washingtonpost.com
washingtonpost.com
(via https://news.ycombinator.com/item?id=26924988, but no comments there to speak of)
What is the problem you're seeing?
In fact I really rarely have any issues with FF whatsoever, and if I do it is always either uBlock Origin blocking a little bit too much, or a site that specifically rules out Firefox (like https://business.apple.com ), probably for no real reason other than not bothering to test their site with it.
I've had better luck with subscription based aggregators, but nothing exciting enough to want to plug one in particular.
Always looking for new options to try.
This revealing interview gives an interesting perspective on the media business around the turn of the century. Note that this is a pdf archive copy saved to draw attention to a particular segment, and I'd urge you ignore that and rad the whole thing. I can't link to the original as it vanished some time ago, and this archive predates the establishment of the internet archive. Thus the presentation is biased (sorry) but it's the only complete copy of the interview I know of. https://zfacts.com/zfacts.com/metaPage/lib/Weekly_Standard_M...
In that regard, WaPo is pretty good but you can still do better: https://www.adfontesmedia.com/static-mbc/
If you want recent proof, look at that debacle with that Toledo kid. Some reported police shoot an armed thug, some report police shoot an unarmed kid. The video proof shows neither side is telling the whole truth.
Example: Cops have shot a thousand people a year for several years in a row (maybe a decade). About 300 of those each year have been black, which is a disproportionate amount by some measures.
However, it is nowhere near the biggest problem in our country even for black people. But because the media has chosen to report on that problem near constantly since Colin Kaepernick took a knee, it has dominated the public consciousness and therefore influences thousands of people to loot, burn, protest, riot and thousands more to develop opinions and attitudes that create more and more division in our country.
Most of what they report is factual but is it as important as the lofty position they are giving it in the news? Is it helping?
Even my comment is derivative, the point is that news and media outlets are able to control public opinion even by being honest and factual. By simply ignoring some facts it's trivial for these outlets to skew their audiences perspectives on current events. The whole "left vs right" ideology is toxic and cancerous to a healthy society and it sickens me. It's increasingly difficult to hold a moderate opinion about a subject without being demonized by one group of extremists or another.
The "you're either with us or against us" mentality leads to the eradication of moderates and further extremism.
A healthy society needs balance.
How can we counteract this?
Michelle Obama tried to make this her primary focus through the entire Obama administration. Like everything else the Obamas did, the Right wing that is currently engaging in the same whataboutism and dogwhistles as this sentence, chastised it at the time as elitist and un-american.
> let's revolt against black on black violence in the inner cities
* https://www.afterschoolalliance.org/afterschoolsnack/VOX-5-R...
* https://abcnews.go.com/US/black-black-crime-loaded-controver...
> let's "defund" platforms which encourage division and turmoil.
While I broadly agree with you that social media platforms are a problem that needs fixing, "defunding" them is a nonsensical statement that only makes sense in reference and in direct contrast to "defunding the police".
These platforms are not "funded" because "funding" in this context refers to allocation decisions of PUBLIC TAXPAYER FUNDS. Private companies are not collecting tax dollars then spending them on fun riot gear to go cosplaying in as they gas people exercising their first amendment rights.
The whole premise of "defunding the police" is to reallocate public funds to different programs that we currently task our police with (mental health, drug addiction, sex work, etc))
Cops have done horrible things to every race, they are especially aggressive with black people.
No, systemic racism caused by capitalism is the root cause of that.
The capitalist media is but one contributing factor of this.
The root cause for this rioting is hundreds of years of systemic oppression: redlining (now digital redlining in the digital age), racist banking policies (for a detailed analysis see ‘The Color of Money: Black Banks and the Racial Wealth Gap‘ and ‘How The Other Side Banks‘, both by law Professor Mehrsa Baradaran), the school to prison pipeline, the CIA and Reagan’s ‘war on drugs‘ that flooded inner cities with crack in the 1980’s causing the crack cocaine epidemic (journalist Gary Webb exposed this), the CIA also systemically murdered the leaders of socialist black liberation movements (Martin Luther King, Malcolm X, Fred Hampton, etc.), and more (these are only a few examples that I can think of right now).
Wage slavery of course exploits and oppresses all of the working class (the 99% of us who don’t own capitalist property: technology in the form of trade secrets, patent claims, etc. (the means of production)). Yet black and brown people (both in the global north and the global south) have especially had a harder time simply because of the color of their skin.
Something tells me you're not qualified to speak on the behalf of black people (even if you were black).
Something tells me that when you choose to categorize what is happening in the US as looting, burning, and rioting (with a casual acknowledgement to protest), then you don't have a very empathetic understanding of the message people are trying to carry across, or why they believe this is a much bigger problem than you deem it to be.
It's not about the pure numbers of deaths. It's about the countless other scenarios just like the infamous ones that led to deaths that black people encounter throughout the US every single day, and have to wonder if they're about to become yet another name, or worse, just a statistic. It's about living in a continual state of terror that the forces of the state that are OSTENSIBLY there to "protect and serve you" do anything but. It's like living in East Germany and being constantly afraid of the STASI, only it's 2020 and it's the US.
That can be a much bigger problem then poverty, drug addiction, or anything else you might point to as a "bigger problem in this country for black people".
personally I find outlets like NYT or NYPost to be too filled with the type of 'state-level bias' that I have a mental allergy to.
PS I understand that websites need to monetise.. But getting a subscription to read one linked article per month or so is just not going to happen. The sites I use a lot I do pay a membership for.
I actually had an online subscription to the Guardian for a while because they were really good on the privacy advocacy news. I wanted to support a paper with deep dives into privacy issues. However the last couple of years I got annoyed with too much Brexit stuff (not surprising for a UK based paper obviously but as I don't live in the UK I don't want to read about it every day). So I let it lapse.
But there's another thing holding me back. If I subscribe I have to give all my personal details. I don't want to have too many sites where I have that around, data leaks are now happening too often. Even a couple days ago I got yet another notification from haveibeenpwned (this time it was the Spanish company phonehouse.es that was hit).
Anyway, I just wanted to say that while I use paywall avoiding tools I'm not blind to the problem of monetisation and the cost of real journalism :)
I just keep it around next to my regular browser for the occasional paywall.
I wish they just supported sideloading of extensions. I wonder how developers are supposed to test their stuff on mobile.
curl https://www.washingtonpost.com/technology/2021/04/24/pentagon-internet-address-mystery/?outputType=amp |grep -o "<p data".*</p>" > 1.htm
firefox ./1.htmI'm partial to Reedy because it tends to fall "safe" and include more content rather than less, but other similar apps should work just as well (SmartNews has a similar function, as do Article Reader Offline, wallabag, and Webreader; I find Reedy has the best UI/feature set for my use).
https://www.tampabay.com/news/military/2021/04/24/pentagon-m...
This Sunbiz record has company principals and filings from 2007-2013 - inc names (not in TBT article) and another dropbox address, this one in Chicago
http://search.sunbiz.org/Inquiry/corporationsearch/SearchRes...
That Chicago dropbox address is currently shared by:
This intellectual property law firm https://www.greengriffith.com/contact/
This venture capital firm http://www.lakecapital.com/contact_location.asp
This management company adds another name and address and is tied to the FL addresses https://floridadb.com/company/M06000002257/filinet-llc
.
OpenCorpWiki has an additional dropbox addy down the street
https://opencorporates.com/companies/us_fl/M20000009226
note: The BBB listing confirms reconciles FL address w/ the domain https://opencorporates.com/companies/us_fl/M20000009226
This mailing list has been following the same trail I have https://www.mail-archive.com/nanog@nanog.org/msg112229.html
Both of these leads have a lot of "supposedly"s attached, but the one to the spam front is a lot more tenuous.
I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?
(Also, sorry to be That Guy, but this one always gets to me: in the sense you've used it, it's "faze", not "phase".)
It's the same problem as FAANG collecting mountains of "anonymous" metrics. Pretty soon, you can determine who the "anonymous" user is.
We had to run the whole project on a completely separate network from the rest of the business due to the classification of the software, which was driven entirely by a handful of frequencies used in testing; details of which were also broadly available from OSINT sources.
It sounds a bit weird they would have needed 170+M ips to get a good attack sample from the internet if the ip are contiguous, a few thousands would have sufficed. It sounds very weird to expect "China" to suddenly route Xi's dirty videos and why not Iran, Japan, everyone suddenly routing craps there, it's not very targetted and would cost quite a bit to read all the potential tcp packets that got lost by bad WAN vs LAN priority decisions in routers.
Also, it's one shot, so why now ? They would have just lost a huge weapon, if true, in a very public manner, for no particular visible threat, not precise target and at great cost possibly.
I'm okay to believe this was possibly just an inventory/activation exercise because someone noticed they owned stuff they can't use until they register them.
> What is clear, however, is the Global Resource Systems announcements directed a fire hose of Internet traffic toward the Defense Department addresses. Madory said his monitoring showed the broad movements of Internet traffic began immediately after the IP addresses were announced Jan. 20.
> Madory said such large amounts of data could provide several benefits for those in a position to collect and analyze it for threat intelligence and other purposes.
It's interesting how this is framed as something "defensive in nature", when it's yet another massive funnel for data being slurped up by a US government agency.
If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies, I doubt anybody would believe a benign "Just checking our security!" explanation.
It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it.
It is not "rerouting a ton of traffic", the traffic was destined toward them in the first place.
The DoD sitting on all that unused address space actively contributed to that problem and now it's exploiting band-aid fixes around it to once again play data kranken of the world under the guise of "We are just fighting APT!".
Somehow the discussion seem to point to China and Russia, but I know a ton of EU companies that use these ranges.
I wouldn't be surprised.
If you drive around with a WiFi stumbler running, you'll run into networks with names like "UTAH DATA CENTER" and "SIPRnet", etc for the same reason.
Made me wanna climb out of my FBI Surveillance Van and have a word with them.
In that case there's never any chance it'll be needed by people using the public internet there, and never any chance it'll be used suddenly by a deployed internal service somewhere else from an outside vendor.
The default should reserve a single ip range and simply fail (with a nice message) if more are needed.
Classic merger "solution".
Company A uses 10/8 Company B uses 10/8, company A buys company B and orders new subsidiary B to renumber into 11/8 "All you have to do is change every first octet to 11"
If your ISP doesn't provide it, get one that does. They should allocate you a /56 by default per connection, if not something larger like a /48 if you have multiple locations.
Subnet the /48 for each connection, subnet each /56 into /64 subnets. reserve one of the /56's for site-to-site if needed.
Done.
How would you "simply add two top octets"? The address fields in the IPv4 header are a fixed size of 32 bits. Every time this is discussed, someone comes up with this suggestion to "just make the addresses longer and change nothing else", but there's no way to make the addresses longer without changing something else. And that's before considering compatibility with older hosts or routers; how would an old host talk to a new host, or two new hosts talk one to another with an old router in the path? In the end, what you'd have would be two separate networks, with some hosts being in both networks, which is exactly what we have with IPv4 and IPv6.
Yeah, it works well enough until it doesn't: I love when VoIP calls have one-way audio or when I have to map ports because the traversal method used by this P2P app is not working. When run at the ISP level it's even more fun: remember when wikipedia blocked the whole Qatar?
Screw DNS. Screw the recommendation to stay away from IP's. If it's important enough to be on the network, it's important enough to have a static IP.
And by "stupid addressing scheme" do you mean it's too big, or what? You can ignore all that stuff with mac addresses and make all your addresses go like prefix:subnet::1 prefix:subnet::2 prefix:subnet::3 if you want to.
Every networking problem in the world can be solved with more NAT or more encapsulation :)
https://www.cisco.com/c/en/us/support/docs/ip/network-addres...
In both cases RFC1918 was used throughout their global network and while not fully used, had become highly fragmented over time.
They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were unique. I'm sure they had several partners who used 10/8 internally.
In my work we use 10.0.0.0/8 but of course some people use the same at home even though 192.168/16 is way more common. In general I find 172.16/12 the least common in the field.
It just looks nicer to me which shows the power of Apple and how easily I am influenced.
And many are surprised to find that there are 172.* that are routable.
Still gives you fun issues though.
You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracking botnet C&C traffic seems like a reasonable play.
You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing shit networking but not CCP-relevant things ?
And the amount of botnets we have in China that are to scam each other that even the CCP doesn't want ? :D
Suddenly advertise this never-used block, and you're just going to get a massive torrent of previously-internal traffic from bazillions of organizations all over the planet that used it for something internal and were slightly lazy and didn't set up their routing quite right. Probably 99.9% of it is of no use whatsoever to anyone outside that org. It's tough to imagine that anyone thought they'd get any useful information on any hostile CCP activity by doing this.
I would also expect that any department doing hostile things on the net would be at least smart enough to not let any of their internal traffic leak out like that, no matter who they actually worked for.
If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is intentionally dialing the department of defence, you probably have some kind of problem at hand. In theory this might become a huge problem, but in practice it probably won't.
[1]: https://www.juniper.net/documentation/en_US/vmx/information-...
[2]: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf...
[3]: https://security.stackexchange.com/questions/157682/why-does...
E.g. https://www.defense.gov/Resources/Military-Departments/A-Z-L...
If network operators are taking the theoretical network blocks provided in training examples and attempting to copy and paste them into real world use, that is a whole other problem with training and education. And lack of oversight by senior people who should know better at their company.
1/8 is also a whole other thing because it's a legitimately announced block controlled by, as I recall, APNIC. If it's in some peoples' 20 year old bogon folded that's their problem, not apnic's.
All I had to do to make it work, IIRC, was add an ip routing rule to prioritize our internal routing for traffic on 11.0.0.0/8 instead of sending it over the default interface.
This solution worked fine, but it broke in weird ways and I remember one time I did arp -a on one of the Amazon boxes and saw some DoD registered addresses, which was a little alarming, but I just chalked it up to my not understanding the details.
And then ultimately because of refusal to get over the technical hurdle of using IPv6 for internal management.
It looks like they're not just announcing 11.0.0.0/8 but also a bunch of more specific routes, including 11.0.0.0/13 and 11.0.0.0/24
It looks like currently their only peer is Hurricane Electric: https://ipinfo.io/AS6939
If you traceroute to any of the announced prefixes you'll see that you enter HE space (but as far as I know won't ever get a ping to the destination IP).
It is very much worth asking who this legal entity is and why a private company is better suited to these efforts than the government.
As an interesting fact, when searching “aliyun 11.0.0.0” which is the mentioned Chinese cloud provider I believe, they apparently has been using that as internal IPs since 2015 as well
Other folks are definitely using those DoD addresses. For example, I see a bunch being announced by AS23352 / Server Central: https://bgp.he.net/AS23352#_prefixes
If you announce it as DoD then it may scare off the others.
In any good investigation, you want to shroud the data/intel collection. Using a front company, or series of levels of fronts, is the way you have to go about it.
In short, a honeypot.
The Delaware company is registered there as a an "outside of the state of Florida" entity operating in Florida. Some actual people names are listed. I'm fairly confident it's the same company, as the Plantation, FL address is there.
Wait until you read about Air America - an actual airline started by Claire Chennault (of Flying Tigers fame), that was bought by the CIA in the post WW-II years and used to run missions in Southeast Asia up until the mid 1970's.
> Created in 2015, the DDS operates a Silicon Valley-like office within the Pentagon.
Edit: more info at https://www.dds.mil/about
A) the usual senior military slow-roll* in the way of these fixes
B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech.
DDS Hires a lot of motivated engineers who would be in civil service but for the $180k -> $90k paycuts and fear of bureaucratic hell. It is run by one of the ~founders of opentable who, post opentable riches, was flying on 9/11/01, decided to join the Chicago PD as a result, did west Chicago homicide until the PD discovered his past, he then stood up Chicago’s data-based policing technical approaches, and eventually the Obama admin heads about him asked him to take over DDS (iirc, +/- details there).
Cool stuff and I’d work for them in a second, probably need another few years in private sector though.
DDS's founding head was Chris Lynch, who served in that role until the middle of the Trump administration, when he left government service and that's when Brett got the job.
I saw him present on DDS and his backstory at BSidesLV a few years ago and did a bit of non-profit govt<>tech chatter with the team there.
Correct, it was in the middle of the Trump Admin.
Some of the projects they talk about doing have huge value-adds to technically underserved groups like military families during mandatory base moves every few years. Those groups are totally dependent on following the system as designed (get your travel voucher here, your goods shipped here, etc) and much of it depends on single option, very janky govt, almost intranet-like, porfals. Iirc, one of their projects was fixing a portal was leaking SSNs like gangbusters. Normal times, that’s a 6 month -> 10 year process to work with the contractor. DDS did it fairly quickly.
I wish USDS would do this as well; I feel like they'd attract a lot more talent. Although perhaps they want to attract exactly the kind of talent who would take a big pay cut out of a sense of service/duty.
> Cool stuff and I’d work for them in a second
For myself, while I recognize that military is a necessary evil in the world we live in, and I have a ton of respect for the people who put themselves in harm's way, working for an org with a .mil address would be against my values. I'm so torn, though, since (e.g.) the Internet itself came out of the DoD. It's a hard pill to swallow for me sometimes that a lot of essential civilian tech was originally developed by or for the military.
It’s the whole those who seek power are least suited to it schtick.
I understand your reluctance and you of course make your own life choices but something to consider.
90% (might be a bit generous) of the people so attracted will not be the kind.
A ton of folks want to have a free lunch in that respect, especially in tech. God help them if Amazon wins the JEDI contract while they work there, but other nefarious work FAANGs get up to while employed at one is ok as long as it’s ~out of sight. Like the Dragonfly project at GOOG...
Similarly, there’s this issue of so much fundamental tech came out of huge DARPA grants, NIST work, and so on. It’s ok if you don’t want to be the one working with DARPA/DDS, but tech’s roots are so tied to them that it has to be ack’d.
The line of folks who “would be in the DoD but for X” is long, and it’s a comically reoccurring conversation for people who do DoD work. That conversation is much different if that awareness exists, though.
I wonder if it came about because how much of a dumpster fire the first version of healthcare.gov was for the premier of the Affordable Care Act. That probably embarrassed a lot of people.
To your first point, it'd be more accurate to say that many government offices often don't hire any programmers, which can (among other issues) make it challenging for those offices to select strong contractors.
> How do you feel about the cloud? Specifically, what are your thoughts on the cumulus clouds of Bespin? Do you believe Cloud City is composed of only cumulus clouds? Do you have any idea about what we are asking? If your answer is yes, definitely read on. If no, still read on, but we might find your lack of faith disturbing!
Once every t1 drops invalid prefixes, then rpki will effectively mean no T1 can turn off the internet for other ASNs, but everyone signing their prefixes is required to mean nobody can fake announce an IP.
It looks like the DOD's routes are indeed signed[3].
1: https://www.thousandeyes.com/learning/glossary/bgp-route-hij...
The prefixes are in the https://www.radb.net
Somebody (as everybody can do this with radb) said to RADB that 8003 is the correct origin for these prefixes.
Considering the DoD hasnt rained hell on the RADB, Id guess theyre good as well, but its not RPKI signed.
Much better to see what the situation is for IRR/RPKI for a prefix/AS:
Cloudflare: http://irrexplorer.nlnog.net/search/1.1.1.0/24
One of the prefixes this thread is about: http://irrexplorer.nlnog.net/search/7.0.0.0/24
Interesting, seems an effort to find out who was abusing ranges that were exclusively allowed or disallowed based on the ranges. Malware that tries to look like something else that uses a state level IP range to evade blocking, or check for blocks.[1]
>I interpret this to mean that the objectives of this effort are twofold. First, to announce this address space to scare off any would-be squatters, and secondly, to collect a massive amount of background internet traffic for threat intelligence.
>On the first point, there is a vast world of fraudulent BGP routing out there. As I’ve documented over the years, various types of bad actors use unrouted address space to bypass blocklists in order to send spam and other types of malicious traffic.
Cloudflare example shows how much traffic some of these ranges that are included/excluded have when turned on.
>On the second, there is a lot of background noise that can be scooped up when announcing large ranges of IPv4 address space. A recent example is Cloudflare’s announcement of 1.1.1.0/24 and 1.0.0.0/24 in 2018.
>For decades, internet routing operated with a widespread assumption that ASes didn’t route these prefixes on the internet (perhaps because they were canonical examples from networking textbooks). According to their blog post soon after the launch, Cloudflare received “~10Gbps of unsolicited background traffic” on their interfaces.
>And that was just for 512 IPv4 addresses! Of course, those addresses were very special, but it stands to reason that 175 million IPv4 addresses will attract orders of magnitude more traffic. More misconfigured devices and networks that mistakenly assumed that all of this DoD address space would never see the light of day.
Looks like a new cybersecurity policy/process started on inauguration day. Probably a defensive or offensive measure to combat the supply chain attacks that may well have used those ranges in evading blocking.
Why use a front company? As a honeypot.
If other scammers are using spoofing the ranges then another company does it, that doesn't raise alarm in the other entities abusing the same trick. If you announce it as DoD then it may scare off the others.
In any good investigation, you want to shroud the data/intel collection. Using a front company, or series of levels of fronts, is the way you have to go about it.