Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

111–120 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#111
post #43

Earlier quoted context omitted.

It also explains the lack of public commentary.

Not sure. If the government is doing something large-scale in public (like construction projects [or maybe global IP routing]), they should communicate what is happening before doing it, in order to not phase people.

Right, because if there's anything the Pentagon has been known for over the past seven decades or so it's clear publication and transparent disclosure of all its large scale classified projects so as not to phase the public.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#112
post #16
post #8

Earlier quoted context omitted.

These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.

Why would you do that though when there are perfectly fine internal address ranges available?

In the case of a managed service provider I worked for, using non-announced gov/mil space allowed us to inject routes for monitoring purposes into the MPLS vrfs of our customers so we could poll the routers without using our own public space.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#113

Some details about the ASN announcing the DoD prefixes: https://ipinfo.io/AS8003 It looks like they're not just announcing 11.0.0.0/8 but also a bunch of more specific routes, including 11.0.0.0/13 and 11.0.0.0/24 It looks like currently their only peer is Hurricane Electric: https://ipinfo.io/AS6939

One peer? Does that mean all that traffic is flowing through Hurricane Electric?

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#114
post #43

Earlier quoted context omitted.

It also explains the lack of public commentary.

Not sure. If the government is doing something large-scale in public (like construction projects [or maybe global IP routing]), they should communicate what is happening before doing it, in order to not phase people.

Eh, I wouldn't be surprised if an org like the Pentagon is secretive about things that aren't really necessary to be secrets. It's just kinda in their nature to be that way (kinda like Apple's default-secrecy about products and features).

(Also, sorry to be That Guy, but this one always gets to me: in the sense you've used it, it's "faze", not "phase".)

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#115
post #35

This is a complete side point, but what does this sentence mean? > Created in 2015, the DDS operates a Silicon Valley-like office within the Pentagon.

DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs for a 2 year tour of duty fixing pressing issues in DoD tech via pretty broad authority to sidestep A) the usual senior military slow-roll* in the way of these fixes B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech. DDS Hires a lot of motivated engineers who would be in civil service…

> DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs

I wish USDS would do this as well; I feel like they'd attract a lot more talent. Although perhaps they want to attract exactly the kind of talent who would take a big pay cut out of a sense of service/duty.

> Cool stuff and I’d work for them in a second

For myself, while I recognize that military is a necessary evil in the world we live in, and I have a ton of respect for the people who put themselves in harm's way, working for an org with a .mil address would be against my values. I'm so torn, though, since (e.g.) the Internet itself came out of the DoD. It's a hard pill to swallow for me sometimes that a lot of essential civilian tech was originally developed by or for the military.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#116
post #102

Earlier quoted context omitted.

Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.

https://github.com/iamadamdev/bypass-paywalls-chrome also really works well on the desktop. Unfortunately I haven't found a way to get it working on Firefox on mobile (the chrome repo also contains the FF one now ;) ). Thanks for the archive link. PS I understand that websites need to monetise.. But getting a subscription to read one linked article per month or so is just not going to happen. The sites I use a lot I…

You need Firefox 68 ( fennec 68.11.0 ) to use extensions from the open internet. Mozilla axed general extension support in later versions of their android browser.

I just keep it around next to my regular browser for the occasional paywall.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#119
post #39
post #35

This is a complete side point, but what does this sentence mean? > Created in 2015, the DDS operates a Silicon Valley-like office within the Pentagon.

The office has a deliberately different type of culture. Edit: more info at https://www.dds.mil/about

This page suggests a really interesting way of organising things: https://www.dds.mil/team

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#120
post #114

Earlier quoted context omitted.

Not sure. If the government is doing something large-scale in public (like construction projects [or maybe global IP routing]), they should communicate what is happening before doing it, in order to not phase people.

Eh, I wouldn't be surprised if an org like the Pentagon is secretive about things that aren't really necessary to be secrets. It's just kinda in their nature to be that way (kinda like Apple's default-secrecy about products and features). (Also, sorry to be That Guy, but this one always gets to me: in the sense you've used it, it's "faze", not "phase".)

I used to work in intelligence. "Secrecy creep" has long been a serious problem inside DoD. How information get classified has largely been left up to low level federal bureaucrats, people my father used to angrily refer to as "big haired women from Mississippi". Basically, they are low level federal office drones, with minimal knowledge about the actual content of classified programs, who re left to determine how they are classified. They start with the core information of a project and classify it "Top Secret". Then they take all the peripheral information of that project and classify it TS as well, just to be safe, because it might overlap with the core info, but they have no clue because they're a GS-4 clerk from Boogerville with a high school diploma. Later as more content is generated in a program, stuff peripheral to the previous peripheral data, which realistically should be classified "Confidential" at most, it too gets classified as TS because of its proximity to the previously over-classified peripheral data. Lather-Rinse-Repeat for a few decades and you have huge swathes of widely known, utterly inconsequential information classified Secret or Top Secret.
Post reply on HN