Live data from Hacker News

Tech CEO sentenced to 5 years in IP address scheme

krebsonsecurity.com

181–190 of 311 posts

Re: Tech CEO sentenced to 5 years in IP address scheme

#182
post #41

I know somebody who basically stole a class A IP network many years ago, in the very early days of IPV4. (He wouldn't tell me which one, but he had inside knowledge of how the system worked, and I know his background, so I believe him. ;) The huge company that owned it went out of business, so he registered their domain name, and sent in an email to authorize the transfer. Once you've got a hot class A network on you…

Nobody's going to run a /8 on a single LAN segment. If you want maximum efficiency, your hosts all have RFC1918 IPs and you route the public IP addresses to them. zero wastage, everything usable.

When I went to college in the mid 90's, the entire campus was on a /16, flat network, every machine had a 255.255.0.0 netmask. There was no subnetting, everything was switched (they said "bridged" at the time.)

With today's switches, you could do much crazier things. Definitely not an /8 though.

Re: Tech CEO sentenced to 5 years in IP address scheme

#183
post #148
post #121

Earlier quoted context omitted.

https://www.youtube.com/watch?v=jDmA2xoIoFU

I mean, if we're going there , there is this comical yet informative and strangely relevant Brooklyn Nine-Nine (thanks djbusby, for the correction) scene: https://www.youtube.com/watch?v=N5S74kKimFs Jake (Andy Samberg) and Charles (Joe Lo Truglio) form an unlikely alliance with Jack Danger (Ed Helms), a nerdy lead investigator at the United States Postal Inspection Service, as they embark on a mission to crack the ca…

It's B99 not 30 Rock

Re: Tech CEO sentenced to 5 years in IP address scheme

#184

Earlier quoted context omitted.

Yes. Also, you do not want the Postal Inspectors showing up looking for you. Like, for real.

Story time? What makes Postal Inspectors so feared.

Some agencies, ones you might not even expect like the USPS and FDA, also have law enforcement powers, but have very narrow jurisdiction (relative to general law enforcement agencies like the FBI). So when a case actually does fall under their jurisdiction, they execute their duties "with extreme prejudice", so to speak. Assuming the story from the OP you replied to is true, the fact that they arrested the police officers would show how seriously they take their duties, even if the officers tampering with the mail was due to carelessness while they themselves were performing their duty.

Re: Tech CEO sentenced to 5 years in IP address scheme

#185

Earlier quoted context omitted.

That's impossible if the devices have privacy extensions enabled, which is the default on all major OSes. My house has a /64 IPv6 prefix. Inside that, the computer I'm writing this on has 8 temporary IPv6 addresses it's using at this moment. An ad company can no more track my individual computer inside my house than it could your computer inside yours. The only difference is that your network is a black box behind pu…

> That's impossible if the devices have privacy extensions enabled Wrong. Try what I said. It was recent enough the results are reproducible. > An ad company can no more track my individual computer inside my house than it could your computer inside yours. Yes, they can and my testing showed me, they do: https://johannaullrich.eu/assets/papers/ullrich2015_raid.pdf

> Wrong. Try what I said. It was recent enough the results are reproducible.

Nope. What really happened is that an ad company might have started collecting information about your IPv6 prefix, precisely like they might store information about your IPv4 address. That's all the information they can reconstruct about the hosts inside your LAN.

The paper you linked showed that if a host uses the method for generating pseudorandom addresses described in RFC 4941 instead of using completely random one, and if the attacker has a complete history of your generated pseudorandom addresses, and if the attacker has successfully defeated MD5 on a practical time scale, then it's possible that they could guess your future pseudorandom address.

In practice, most OSes generate truly random addresses, and an advertiser doesn't have your complete history of generated addresses, and the advertiser wouldn't spend all those resources to track you specifically anyway. In other words, that 8 year old paper isn't relevant to the situation today.

Re: Tech CEO sentenced to 5 years in IP address scheme

#186

Earlier quoted context omitted.

I worked for a dial-up ISP that was going out of business and their last hurrah was selling renting servers doling out clean IPs from their /16 blocks so the clients could spam like crazy. Then we encountered these spammers were willing to forge BGP LOA stating that they could announce certain, defunct and unused blocks on BGP. I left there in a hurry, but it seems like they got away with it for a while. It would've…

Of course if the transit providers did a better job (to be fair you're talking about years ago when this wasn't close to practical) they'd reject the announcements as bogus, no need for administrative punishment if it just doesn't work so nobody tries it. Today RPKI means that machines can in effect authenticate the LOA, the same way your web server is able to prove it's itchyouch.example (or whatever) to a web brows…

Last I checked, RPKI was still not in use for the majority of prefixes: https://rpki-monitor.antd.nist.gov/ROV

This is likely true for much of the legacy space in the US, since ARIN requires you sign their registry agreement and actually pay fees to enable RPKI. It's not grandfathered.

Re: Tech CEO sentenced to 5 years in IP address scheme

#187

Honest question, why are we not all just on IPV6 now? It seems like at this point almost all the underlying hardware and software should support it? It seems like the only argument for sticking with IPv4 is NAT, but I can't think of a technical reason we couldn't do NAT with IPv6?

The effort required to make a company IPv6-enabled is not to be underestimated.

Good thing people have had years, even decades, to make it happen, then.

Re: Tech CEO sentenced to 5 years in IP address scheme

#188

Honest question, why are we not all just on IPV6 now? It seems like at this point almost all the underlying hardware and software should support it? It seems like the only argument for sticking with IPv4 is NAT, but I can't think of a technical reason we couldn't do NAT with IPv6?

> but I can't think of a technical reason we couldn't do NAT with IPv6?

We absolutely can do NAT with IPv6, but there's no reason why anyone should (aside from stateless NAT66 in case you get a dynamic prefix that changes every now and then, but that's about the only use case)

Re: Tech CEO sentenced to 5 years in IP address scheme

#189

Earlier quoted context omitted.

Texan billionaire Robert Brockman sued an Australian for stealing $20 million from his trust in 2020 [1]. A few months later, he was indicted for hiding $2 billion of income from the IRS [2]. He died before trial took place anyway.. 1- https://amp.smh.com.au/national/australian-barrister-denies-... 2- https://www.justice.gov/opa/pr/ceo-multibillion-dollar-softw...

Did he actually die, or conveniently “die”? I guess it’s hard to know.

He'd be 82 so it's not implausible that he actually died last year - though he claimed he couldn't participate in his defense against the IRS charges since he had dementia and the government called 'bullshit' on that. Amusingly, the government has some funny details like he learned that his Bermuda-based co-conspirator had been raided by tax officials while on a fishing trip in Alaska, and then 1 day later emailed a neurologist seeking an appointment to diagnose dementia.

Looks like it was a successful Trump-like attempt to just delay things forever by filing dozens of motions; First mention of a competency hearing was in January 2020, they assigned experts, delayed the examination a bunch of times, appealed certain aspects of it, eventually in August 2020 the experts found him competent, which he then appealed again, and again and again -- after several more hearings and briefs where his lawyers lied about the expert testimony, it was nearly 15 months later that he was formerly found competent to stand trial in May 2021

Vista Partners evaded billions in taxes for almost two decades, it was investigated and exposed in 2018, IRS/DOJ filed charges in 2020, his partner pleaded guilty in late 2020, Brockman was charged in Jan 2021, found competent in May 2022 and then died in August 2022 a free man.

Sounds like a real scumbag.

Re: Tech CEO sentenced to 5 years in IP address scheme

#190
post #55

Earlier quoted context omitted.

NAT is a strong argument against IPv4 -- it's an absolute pain in the ass for bidirectional communication. Yeah, NAT acts as a defacto firewall, but you can just... use a real firewall.

> it's an absolute pain in the ass for bidirectional communication You're right and that's what I love about NAT, IPv6 in contrast is a hacker/spy tracking digital superhighway right through my front door and straight into my devices.

> IPv6 in contrast is a hacker/spy tracking digital superhighway right through my front door and straight into my devices.

I'm fairly confident that nobody is ever going to scan a single /64 of IPv6 addresses within our lifetimes.

In comparison, scanning the ENTIRE IPv4 internet on a single port can be done by anybody at all and it's going to take about 40 minutes.

Post reply on HN