Pentagon retakes control of IP addresses it moved in last minutes of presidency
washingtonpost.com
washingtonpost.com
Wasn't the US Government looking to sell these unused addresses to bring money in?
What if this secretive shell company is just something run by a great campaign donor or someone close to the administration who planned on a good cut of these profits?
It makes me very curious who is really behind this storefront in Plantation, FL.
People get thrown off by it being the Pentagon and come up with all these James-Bond-level theories. But DoD just happens to be the owner for historic reason.
Supports which baseless claim, that the orange Florida man paid kickbacks with ipv4 space? With a Florida registered foreign LLC pointing back to Delaware? Seriously?
The EDNS client subnet feature reveals the clients subnet (but not entire IP) to the nameserver that answers the DNS query, which is then cached by Cloudflare/Google. This allows the nameserver to do geolocation at the DNS stage and direct the end user to a server with minimal latency.
Without EDNS client subnet, you could get the IP for an archive.is frontend in a different continent and have a slow site experience. While the frontend server will get your IP, it's too late to do much about it under normal circumstances. An HTTP redirect would cost time, and you'd have to have different domains for each data center/region which is one thing you can avoid with the client subnet feature to start with.
You can serve UDP services (eg DNS) by anycast, but if you hosted a tcp service, there's no guarantee the same server would receive consecutive packets from the tcp stream
https://vincent.bernat.ch/en/blog/2018-multi-tier-loadbalanc...
https://blog.cloudflare.com/high-availability-load-balancers...
https://engineering.linkedin.com/network-performance/tcp-ove...
How do CDNs work without controlling DNS resolution by source subnet?
Not if you're using a VPN in addition to Cloudflare servers.
Also I can't imagine why you might think that "You're not meant to use DNS fallback for different providers." That was precisely the point it was originally designed for. The whole point of multiple resolvers is to have diversity of risk. If both your resolvers are from the same organization there's a higher chance that whatever took one out took the other out as well.
In any case in order to maintain privacy I use https://dnscrypt.info it has an anonymized DNS option https://github.com/DNSCrypt/dnscrypt-proxy/wiki/Anonymized-D...
I then just use unbound and forward that to DNSCrypt on my router. https://wiki.archlinux.org/title/DNSCrypt#Unbound
This can be tuned, but often goes in order of connected, static, external BGP, followed by internal BGP and other interior gateway protocols.
So, yeah if you learn a route from eBGP, you very well may take that path out of your own AS out to the global Internet, as opposed to internally where you are (incorrectly) using someone else's public space.
(Edit: network here includes a prefix length, where more specific prefixes are chosen over less specific ones. In the case, the public announcement is 11.0.0.0/8. If you were using this space internally, you would presumably have more specific routes than a /8)
> Goldstein described the project as one of the Defense Department's "many efforts focused on continually improving our cyber posture and defense in response to advanced persistent threats. We are partnering throughout DoD to ensure potential vulnerabilities are mitigated."
> Expanding on his [Madory] point that the Defense Department may want to "scare off any would-be squatters," he wrote that "there is a vast world of fraudulent BGP routing out there. As I've documented over the years, various types of bad actors use unrouted address space to bypass blocklists in order to send spam and other types of malicious traffic."
> On the Defense Department's goal of collecting "background Internet traffic for threat intelligence," Madory noted that "there is a lot of background noise that can be scooped up when announcing large ranges of IPv4 address space."
[1] https://arstechnica.com/information-technology/2021/04/penta...
Edit: added the word still. I know the history but that was like 20 years or more ago.
Why did they still have so much IP space?
Who's going to take it off them?
Universities who got on the bandwagon first also tended to have multiple class B addresses.
Also, early owners got huge allocations. And the US government is an early owner.
https://www.iana.org/assignments/ipv4-address-space/ipv4-add...
https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing...
Coincidentally, CIDR doesn't conflict with the HN comment syntax.
Sometimes shortened to 17/8, but… I wouldn't recommend that.
This isn't Ipv6! :P
You bet everybody already jumped in that boat. It would be interesting to know who and how.
The Pentagon owns a big chunk of the internet because the Pentagon paid for the internet, basically. The more interesting bit is how much it they gave away for free, not how much it kept.
I would have expected them to have deteriorated to a point where restoring them becomes a bigger effort than building new planes.
Consider that the Iowa class battleships spent some decades deactivated, sitting in salt water, before being reactivated several times.
If you made a list of “most popular concerns about the Internet in 2021,” the size of U.S. federal IP space would be pretty far down.
IPV6 is the solution but has been in adoption forever.
I just don't understand what the government needs with all of those IP addresses and what kind of sneaky stuff it's doing behind the scenes.