Related post: https://www.airlinepilotforums.com/archive/index.php/t-56350...
873 karma · joined July 16, 2019
Related post: https://www.airlinepilotforums.com/archive/index.php/t-56350...
To be honest tho - this is the contract that both the company and union agreed to, so bad on the company for being okay and not making this a more serious infraction. I've talked to some of the union stewards about this and they basically said they wanted this data locked down harder. They said it's too easy to access and super temping and wished the company would put more protection around it. Go figure.
Also Brian Shul (the originator of this anecdote) and his RSO were the only SR71 crew removed from the program. There is a reason for that.
Agree that multiplayer how-to's is lacking.
A few years ago folks wanted to bake in additional functionality. For example, packet filters (aka ACLs) normally are deployed to router configuration files using each operators own tooling. To deploy this against hundreds or thousands of routers rapidly was a challenge for them (not good at swdev, etc.). So the idea was we already have a protocol that propagates state to every router rapidly in the network, let's find a way to bake ACLs into the BGP updates.
The result wasnt that good for a few reasons: 1) bgp state isn't sticky. If a router goes offline or bgp sessions reset, acls go away. That means if you are using flowspec for a critical need like always on packet filters you've got the wrong tool. 2) the implementation had various bugs. 3) most importantly it gave people a really easy way to hurt themselves globally. There was no phased deployment with pre and post checks. What you deployed led to packet filters being installed across the network in seconds. In most cases (depends on your config) the only way to remove it is remove the specific flowspec route or have bgp reset to it.
I've seen bad flowspec routes core dump the daemon on a router responsible for programming ACLs that led to them being unable to withdraw the programmed entry. I've seen as bugs on tcp/UDP port matches go wrong and eat lot more than intended. I've seen so many flowspec rules installed on a network where it exhausted routers ability to inspect and process packets and you'd see flat lining of packets being dropped.
In my opinion, it's a hack around not having a good ACL deployment tool that has led to many outages in its wake.
Edit: another flowspec gotcha. Some folks like to integrate ddos tooling systems into flowspec. An example of this is if I run a network and some IP address behind me gets lit up, deploy a rule for that specific IP and rate limit traffic to it. Unfortunately, sometimes folks don't put a lot of care into making sure it can't mess with internal IPs that should be off limits. Like route reflectors, router loopback IPs, etc. I've seen situations where some networks have had a bad day due to a ddos or traffic mis classified as ddos by auto installing rules to protect something but actually impair legitimate communications to network infrastructure which then causes the outage.
Also, flowspec doesn't work like regular ACLs where you have input and output on a per interface basis - it applies to all traffic traversing a router, which makes it difficult to say which interfaces should be exempt (think internal vs external).
Its a super useful tool if you want to blast out an ACL across your network in seconds (using BGP) but it has a number of sharp edges. Several networks, including Cloudflare have learned what it can do. I've seen a few networks basically blackhole traffic or even lock themselves out of routers due to a poorly made Flowspec rules or a bug in the implementation.
Outages and nanog lists are your best bet, short of being on the right IRC channels.
If people refuse to sign ROAs, then they don't get protection. The ARIN TAL thing is real and people have to keep fighting that.
As it is right now you can xfer v4 out of ARIN but not v6. So even if you wanted to you can't.
The books are meh because they're not written by operators. They're more academic and dated.
Plenty of clueful folks on the right IRC channels.
Example: https://mobile.twitter.com/TeliaCarrier/status/1300074378378...
Edit: if you are a Level3 customer shut your sessions down to them.
Coworker of mine was a sheriff deputy in Indiana and he confirmed this was a common practice.
The step up are the B1900s that CBP has which have additional sensor capabilities.
When I started at the phone company back in the day it was post breakup. The waste that went on when there was no competition was sickening. Many of my co-workers told me about all the abuse and theft that comes with being a monopoly - with the cost being passed down to the customer and the tax payer.
Also the world of the Internet, the openness of IP protocols disrupted them. They finally had to deal with technology that wasn't dictated and controlled by them.
BTW the scene in Robocop (the first one) where he plugs into a computer is actually a CO with DMS100s.
I've known a few folks who've got their own dark (or point to point wireless) to colos in downtown areas where they and their friends will rent half a rack or less to drop in a router and buy cheap transit and become their own little ISP.
There are folks on the left who aren't on board with net neutrality. I'd say the common ground between left and right is about having viable competition, which we don't have. But we kinda tried that with the 1996 telecom act and that failed.
I'd rather municipalities get in the broadband access game as a utility and be transparent about costs and utilization and provide interconnection to an ISP upstream at standard tariffed rates.