Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

101–110 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#101
post #55

Earlier quoted context omitted.

If that were true, depending on path inforation, any botnet or other traffic destined to those networks would end up in this new AS8003 traffic sink, which would create a map of candidate CCP assets to target on the internet. You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracki…

But the internet is not just CCP vs Captain America. I mean my home network has random ips and a shit network admin, so I will also send crap data to the DOD, from Hong Kong. You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing…

Yeah, that's why the stated explanation sounds weird.

Suddenly advertise this never-used block, and you're just going to get a massive torrent of previously-internal traffic from bazillions of organizations all over the planet that used it for something internal and were slightly lazy and didn't set up their routing quite right. Probably 99.9% of it is of no use whatsoever to anyone outside that org. It's tough to imagine that anyone thought they'd get any useful information on any hostile CCP activity by doing this.

I would also expect that any department doing hostile things on the net would be at least smart enough to not let any of their internal traffic leak out like that, no matter who they actually worked for.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#102
post #2

Paywall-free link: https://archive.is/tKOOA

Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.

https://github.com/iamadamdev/bypass-paywalls-chrome also really works well on the desktop. Unfortunately I haven't found a way to get it working on Firefox on mobile (the chrome repo also contains the FF one now ;) ). Thanks for the archive link.

PS I understand that websites need to monetise.. But getting a subscription to read one linked article per month or so is just not going to happen. The sites I use a lot I do pay a membership for.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#103
post #16
post #8

Earlier quoted context omitted.

These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.

Why would you do that though when there are perfectly fine internal address ranges available?

In our case, we were setting up VPN tunnels to a partner, who for some reason required that the addresses on our side should (appear to be) public IP addresses. So we couldn't use 10/8 or 192.168/16 in (that part of) our network.

They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were unique. I'm sure they had several partners who used 10/8 internally.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#104
post #13

Earlier quoted context omitted.

I don’t know why you’re being down voted. It’s an interesting idea.

I didnt downvote, but random speculation with no evidence doesn't get upvotes on hacker news; a discussion of things you find interesting that others find baseless with get you downvotes immediately.

Well, the article sort of requires discussion on what might be happening here, not?

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#105
post #103
post #16

Earlier quoted context omitted.

Why would you do that though when there are perfectly fine internal address ranges available?

In our case, we were setting up VPN tunnels to a partner, who for some reason required that the addresses on our side should (appear to be) public IP addresses. So we couldn't use 10/8 or 192.168/16 in (that part of) our network. They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were uniqu…

There's also 172.16/12 :) But yeah I agree. If you're running a VPN for a large company it's kinda hard to avoid such conflicts.

In my work we use 10.0.0.0/8 but of course some people use the same at home even though 192.168/16 is way more common. In general I find 172.16/12 the least common in the field.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#106
post #102

Earlier quoted context omitted.

Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.

https://github.com/iamadamdev/bypass-paywalls-chrome also really works well on the desktop. Unfortunately I haven't found a way to get it working on Firefox on mobile (the chrome repo also contains the FF one now ;) ). Thanks for the archive link. PS I understand that websites need to monetise.. But getting a subscription to read one linked article per month or so is just not going to happen. The sites I use a lot I…

perhaps you should consider getting a subscription one month per year and using the extension the other 11 if you think that's a more fair price to pay

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#107

Earlier quoted context omitted.

Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.

Thank you! Had to use Safari on mobile as the captcha did not play well with Firefox.

Google recaptcha? I get the same problem continuously on FX desktop and Android :(

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#108
post #80

Earlier quoted context omitted.

"edit: Downvotes? Really?" is a surefire method of attracting downvotes.

I got -4 in downvotes. (-2 before my edit.) I don't know what's going on. I understand when I call out Apple or Google for bad behavior that I can attract downvotes. Sometimes my posts are snarky, and I understand in that case too. But I can point to instances where posts I made days ago were all downvoted in unison. Or completely informational threads where every single one of my comments gets a downvote or two. Jus…

I upvoted, if nothing else it's a perfectly reasonable comment with an interesting hypothesis.

HN karma is a little weird. IMO, if you've never been downvoted to -4, then you've never said anything really interesting. It's easy to just tell the crowd what they want to hear, saying true and important things doesn't always go down so well. Don't sweat it too hard. Sometimes posts do acquire downvotes at suspicious times and rates. Makes me wonder if some external orgs managed to build downvote bots for HN or are directing voting somehow.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#109
post #83
post #7

"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems" I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?

Alibaba for example use DoD address ranges for their management servers running Alicloud services. They assumed since nothing in their cloud platform would connect to those addresses they can use these them to alleviate IPv4 shortage. In Alicloud, the customer have the right to use any RFC1918 addresses, so they had to be creative since they didn’t have sufficient IPv4 addresses.

but if they're not filtering BGP announcements for those ranges (however unlikely), and the GFW isn't blocking traffic out to those addresses (even more unlikely), and the internal metrics were high (super unlikely), I guess it'd slurp out all the traffic? maybe this was a weird smash-and-grab.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#110
when digging though some of the IPs, i came across 22.0.0.0/8, which if you look at the DNS tab of bgp.he.net (https://bgp.he.net/net/22.0.0.0/8#_dns) shows a LOT of people are "using" those IPs... which means a LOT of people wont be happy that their sites, email, dns, etc, are now essentially being blackholed... for me (I run AS204994), the traffic hits Frankfurt (i peer with HE there) goes over their network though Paris, then to Ashburn and then is blackholed... gone after that... wondering how much traffic is being seen by he.net with this...
Post reply on HN