The Pirate Bay – North Korean hosting? No, it’s fake
rdns.im
rdns.im
rrbone UG (haftungsbeschraenkt)
Leibnizstr. 8a
44147 Dortmund
GERMANY
https://rdns.im/the-pirate-bay-north-korean-hosting-no-its-f...
The easiest thing to do is to put up caching reverse proxies on big providers that respond immediately and only slow down on "dynamic" content, which we all assume to be slower anyway.
A more non-conventional approach would be to break the embedded OS of an intermediate router or network device (can you count how many transparent filtering network devices there are between you and a random website?) and have it return false data or provide static NAT to establish connections before they actually reach the destination.
The spoofed packets seems the most likely explanation. It's just not the only possibility :-)
Edit: The real tragedy is the people excusing NK so they can have their way. I'm not saying they are dumb, just unlucky at thinking.
Edit2: No defense of hackivists making a mockery of themselves? How much does TPB make?
I've read this sentence a few times, left, come back, and re-read it a few times, and I still can't really make heads or tails of it.
Are you saying that people doing this (pretending their website is hosted in North Korea) makes light of the suffering of people who live in North Korea? I don't understand how you can conclude that: The whole point is that, as bad as North Korea is, it still doesn't go after torrent sites. It wouldn't work if North Korea were replaced with a country that actually has a lot of freedoms.
Are you implying that people should be working to end what's going on in North Korea? Well, what can anyone do? Any serious attempt to force change would simply lead to a massive, destructive war, killing most of the people that the outside world wants to help.
You might be unlucky at thinking.
Besides, that's their thinking, not mine. If anyone's unlucky it's them.
Because they don't have any? I think I'll stick with my previous answer.
My assumption was that they'd picked NK as their joke destination because TPB would be seen as a glorious anti-capitalist organisation there, undermining the evil Hollywood fascists. Or maybe I read too much into it...
If the provider isn't filtering, sure.
> Most edge routes are configured to simply trust routes as they come in
Actually, edge routers are where your prefix filtering takes place. It's much more difficult to filter at the "core".
This is why my comment posted in the recent CloudFlare post mortem talks about good network engineers and the misunderstanding of many 'technical savvy' folks that know enough to do some really dumb things architecturally.
This lends credence to the fact that, this is well understood if you've spun up peering sessions more than once. I find it slightly embarrassing most people don't realize how fragile a framework BGP really is. But it definitely comes to light reading through forums like HN that lean towards the developer side of readership.
If you advertise /31s and /32s, well, you shouldn't be redistributing into BGP and, of course, your upstream should be filtering those prefixes and throwing them away. Problem solved.
Perhaps the majority of people here on HN don't understand BGP. Then again, most of them probably don't need to.
http://tech.slashdot.org/story/12/11/06/2040226/why-google-w...
Syria being taken offline was also via BGP
blumentopf am 04. March 2013 um 22:06: "Note that 175.45.176.0/22 is visible behind China Unicom in the global routing table (shortest AS path ends with 4837 131279), whereas 194.71.107.0/24 is only visible behind Intelsat (22351 131279 51040). It should therefore not come as a surprise that you see a different route when you’re doing a traceroute directly to 175.45.177.217.
While you could be right it’s also conceivable that there’s a link between Cambodia and North Korea and that the next hop behind 202.72.96.6 is indeed 175.45.177.217 (in North Korea, not just a transit net for BGP handoff). So I don’t see this as conclusive evidence that it’s a fake."
Now I'm just going to tell my mum I'm in the LA Times.
This wasn't the case an hour ago. I was able to get 50ms RTT from TCP port 80 but now they probably added fake lag with tc(linux traffic shaping tool)
# tcptraceroute -f 128 -m 128 thepiratebay.se
traceroute to thepiratebay.se (194.71.107.15), 128 hops max, 60 byte packets
128 thepiratebay.org (194.71.107.15) <syn,ack> 38.726 ms 39.877 ms 39.333 ms"In the end i will also solve the mystery of the REAL hosting location, with proof."
Luckily, AFAIK, BGP is trust-based, so things go to normal pretty quickly.
http://www.ripe.net/internet-coordination/news/industry-deve...
In reality, most ISPs (that I've dealt with, anyway) do prefix filtering to prevent just this sort of thing.
There are rather obvious limits, however, for example you will likely have to believe your ISP C if he says ‘I AM ISP B NOW, TOO’. If you then connect to another ISP D, and tell him ‘I KNOW ISP B’, D will have to decide whether to trust you (likely if you are a large telecom company) or not (if you just happen to have two 10 MBit/s lines to C and D each).
Not quite.
WHOIS tells you the address of the organization (as they supply it) the IP addresses are allocated to, nothing more.
> BGP determines where the IP is actually located
No, BGP determines the path through the Internet, via various ISPs, that your packets take to get to their destination.
Well, okay. Don't touch it. It ain't broken. I don't think there's anything wrong with showing people who are not network experts how easy it is to (believably) route things into nirvana. I guess the effects of fake routes being propagated could have been a lot worse than this. Why not promote some discussion and thought around BGP and friends? Maybe we can come up with something more resistant.
but yeah, the title of the other thread is wrong.