Someone Forced World Internet Traffic Through Belarus and Iceland
allthingsd.com
allthingsd.com
In network security circles, this is what’s known as a Man-In-The-Middle attack. And for years it has been understood to be possible in theory, but never seen in practice.
Uh, no. What happened here was a BGP hijack, which has happened MULTIPLE times over the last few years. IIRC the one with the biggest fallout was some Pakistani ISP which fucked up a YouTube block order - they broadcasted the null-route to the entire Internet and Google couldn't do anything, lol.And even "normal" MITM attacks have been done for years now. Every ISP doing censorship, BitTorrent throttling and anything that interrupts normal packet flow does active MITM attacking, and the NSA listening posts are passive MITM posts.
edit: my point had nothing to do with the content of the article. It was more just saying "hey, effective written communication is a tricky thing. Where the author of the article may have failed in some of the important technical details of the article, you have also failed in presenting your corrections in a somewhat offensive manner. Maybe consider the _how_ next time in addition to _what_ you are trying to convey."
Remember, you're on Hacker News. Thanks to people like the author, the average person thinks you and I are criminals. Because, hackers.
You may be right about omitting that tone in general, but considering the feelings of media hacks is not a big motivator.
This hardly seems like a reasonable characterization. The author got a technical detail wrong. How does that connect him to people who vilify "hackers"? He didn't even use that term.
If you're in the media, don't talk about things you don't understand!
Second, if you're a journalist, you are pretty much guaranteed not to be an expert in the fields you report on, because you're a journalist, and not a networking engineer, or a software developer, or a doctor, or a lawyer, or a professional in whatever other field you might be reporting on. Journalists have an obligation to report factually and correctly to the best of their ability, but they are not infallible.
Also, the technically incorrect piece of this article seems pretty minor. I don't understand why some people are getting so worked up about it.
Because the effort it would have taken to not make the mistake is so minimal (Google: BGP, first result is wikipedia, read for a few minutes), that it carries rather unfortunate implications for the author and their attention to detail, and by extension their qualifications as a journalist.
Journalists have an obligation to report factually and correctly to the best of their ability, but they are not infallible.
With the above in mind, I'll bet you $large_amount_of_cash this is never corrected.
And you would be correct. It won't get corrected because no one cares, and no one cares because it is inconsequential.
Is it preferable for a newspaper to report on a new medical study and publish Yet Another(tm) "Researchers at [University] find cure to cancer" story, or, is it better for the newspaper to refrain from talking about the medical paper entirely?
Personally, I have to go with the later. Given the choice between botched reporting and no reporting, I'll go with no reporting. It is better to be uninformed than misinformed. It is easier to correct 'uninformed' and the state of 'uninformed' is easier for self-aware people to recognize in themselves.
Consider the fallout caused by the media botching the reporting of the FTL neutrino anomaly. People lost their jobs because reporters could not be arsed to do theirs.
"And for years it[either man-in-the-middle or BGP attacks] has been understood to be possible in theory, but never seen in practice[!?!]. That changed earlier this year when someone — it’s unclear who — diverted Internet traffic from some 150 cities around the world through networks in Belarus and Iceland."
It is worth noting how wrong that is but being accurate when you point to someone else's wrong stuff is one of the first principles.
Its easy to disregard tone when its somebody else's feelings at stake, much harder to look past tone when its your feelings on the line. Nobody is above the fray.
Maybe we need a robustness principle[1] for human communication. Be conservative in tone you send out, liberal in what you accept.
> Note that Crocker's Rules does not mean you can insult people; it means that other people don't have to worry about whether they are insulting you.
Your tone still matters unless you are communicating with someone else who is operating under Crocker's Rules.
While I like the idea of that in theory, I have to say I think it's operating on the somewhat flawed premise that tone and other flourishes offer no informational benefit. I view tone as a "hint" for the context of the surrounding statements, and as such, it can alter the interpretation of them. This is useful for efficient communication.
I think Crocker's Rules will help people will communicate the correct information efficiently, but I don't think it's necessarily in the minimum amount of time, just a better average case time. It's probably very useful in situations where the shared social context of the communicating parties are distinct enough that the hinting provided by tone is misinterpreted, which can be common on the internet, where disparate cultures clash and there's no visual channel to additionally help communication.
For a very simple example, tone may convey confidence. If that confidence is in a statement that people find reasons to doubt or disagree with, depending on their own confidence they may feel more or less compelled to disagree.
It's good to point out the faults where the information is wrong - but relax on the tone.
Beside this technical blunder, the article is actually informative.
The statement that follows is even worse. It's just outright wrong.
If someone writes an article claiming someone is a murderer and they use DNA evidence to back their story, except they have no idea how DNA evidence even works or what DNA even is and, more so, the evidence does not actually back up their claims, well, that person is deserving of ridicule. It's not those who do the ridiculing who have breached the wall of propriety, it is the author who has done so.
The same is the case here. If you want people to treat your mistakes kindly, if you want to be treated with propriety and respect, then you need to be fucking circumspect about the allegations you lay down and you need to have an understanding of the lines of evidence you purport to bring to bear.
Check out the researchers' article for tracerout data and other interesting details: http://www.renesys.com/2013/11/mitm-internet-hijacking/
And if you're interested in how the internet works at this level (BGP, peering, ISPs), the book "Tubes: A Journey to the Center of the Internet" is interesting reading.
> a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.
In the article, the connection is being controlled by the attacker after breaking into and controlling an innocent ISP's BGP advertisements. The attacker also provide a means to route the data back out another connection as well, which implies something was sitting in the middle of the connection grabbing and redirecting data to another connection that hadn't had it's BGP tables altered. (If it hadn't, the data would have just gone in a loop at the ISP.)
In the other cases of BGP 'hijacking', the data simply disappeared because it wasn't routed back out to the Internets. If someone null routed Gmail, well, it won't work because I wouldn't get any data back to run the browser view. In this case, the data made it back to where it was going, which implies the conversation is being controlled by the attacker.
I'm ignoring your last point as it seems a bit off topic. Censorship and subversive BGP activities have little to do with each other.
IIRC the one with the biggest fallout was some Pakistani ISP which fucked up a YouTube block order - they broadcasted the null-route to the entire Internet and Google couldn't do anything, lol.
I never heard the 'Pakistan shutting off Youtube globally'-story, so for those equally interested:
http://www.renesys.com/wp-content/uploads/2013/05/nanog43-hi...Furthermore, he goes on to explain that this was a BGP hijack, and even mentions the Pakistani incident you just brought up.
[0] - http://www.renesys.com/2013/11/mitm-internet-hijacking/
[1] http://en.wikipedia.org/wiki/Hanlon's_razor
[2] https://ftp.apnic.net/meetings/22/docs/tut-routing-pres-bgp-...
Obviously this is an entertainment piece, not a technical write up. If you think the content isn't right for you then read something else.
So, can't you just asked the ISPs who announced those fake routes if they were hacked, and if not, demand an explanation? (And if no explanation comes forth, stop peering with them)
It is currently the most effective and useless DDOS strategy to push a black hole route out for the 'target.' Effective since all their packets will stop getting to them, useless because it points exactly at the point where it is coming from, and NOCs have gotten reasonably good at working around bogus advertisements. So it is short lived.
How can an ISP tell if a route is "false"?
Unless I am missing something?
:)
Take-away: To improve time spent on site, and return visitors computing.co.uk should increase the font size!
That just reminded me of an (urban) story where a man went to Fairy Liquid and offered to increase their profits by 25%. He wanted 5% of the 25% increase. They signed contracts and agreed to the deal. The simple solution was to make the hole 25% bigger. The customers squeezed just the same and 25% more came out. Profit.
The stars are big and so I guess it's just very rough placement.