873 karma · joined July 16, 2019
Except China. China to rest of world is not via backbone.
For example, running tests to a signed, unsigned and invalid prefix can provide insight into how other networks are routing to them.
One example is a beacon to probe to determine if a network has enabled origin validation. Failure to connect, or a change in the routing path can provide insight into which networks on the internet have enabled origin validation.
Same issue with internet peering in quite a few cities (no viable 2nd location, costs a lot of money to double up the gear, additona optical transport).
It could be that they had to de-energizd some equipment to perform inspection and work within the facility. I know our facility had a number of procedures on how to de-energize parts of the building and inhibit the generators from feeding that area (a lesson learned in the Hinsdale CO fire years ago).
During Hurricane Katrina a number of us had to invent a procedure for de-energizing non critical equipment to reduce power load in order to keep critical services running for an extended period of time since it was clear we werent going to get utility and resupplies for awhile.
Interconnection facilities are the best places to be (or rather what you want to be connected to in order to establish as many adjacencies). 111 8th in NYC. 165 Halsey in Newark. 350 easy cermak in chicago. Palo alto for the bay (but also eqx in San Jose). Infomart in dfw. Etc.
Cable landing stations generally service one cable and the actual networks that use it are generally some distance away.
Remember that only a handful of companies today have the infrastructure to handle large attacks.
The big things these days are:
spoofers who generate a ton of syns to legit destinations which result in a lot of syn+ack to the victim. Bcp38 would help here.
Botnets generating a ton of UDP to destinations. Hosters, cloud providers (especially those with vulnerable/open EMR clusters) and broadband ISPs with easily compromised customers are the problem here. Kudos to those who take down the botnet command and controls.
Memached/ntp/cldap amplifiers. Still out there, still a problem. Thankfully a few of these services are policed at large peering interconnection points.
The challenge is some of thr broadband networks aren't being transparent about it. They won't admit to it, etc. Luckily I've found folks in a few companies who are willing to go off the record and explain what is the state of the last mile and give dates around planned upgrades (which are impacted due to permitting delays due to city employees struggling with covid restrictions).
I highly recommend getting two ISPs at home (cable + DSL/fttx/etc.) if you can.
As for Corp networks...they should be doing more with providing their employees some tooling to indicate if the issue is their ISP or the Corp network. It's a sad state that VPN appliances cost as much as they do (surprise - you could probably build a cheaper/better one but something something no one ever got fired for buying Cisco/etc).
(I have to deal with hijacks frequently and part of our investigation is beating on folks who have permissive filters and pressuring their peers to improve things)
There is a whole industry around salvaging old jet aircraft for parts, movie sets, furniture, etc.
An old 747 fuselage would be well under a million. Even less for 727s and 737-200s.
It wasn't super notable. What was more horrific was the amount of windows machines that had tcp ports for various windows services open to the internet that led to not only crashing but remote compromise and rootkits/botnet stuff. That went on for years and only got mitigated by people deploying routers with fw/Nat functionality.
Lots of great radio programs. This American Life, Art Bell, Hearts of Space. Hell going back far enough even Loveline had it's moments. I forget which university (in Burlington) had a great radio station that played good music and recorded every episode. Would get home and download the recordings and still listen to them (introduced me to a bunch of artists I didn't know).