Earlier quoted context omitted.
I used to work in intelligence. "Secrecy creep" has long been a serious problem inside DoD. How information get classified has largely been left up to low level federal bureaucrats, people my father used to angrily refer to as "big haired women from Mississippi". Basically, they are low level federal office drones, with minimal knowledge about the actual content of classified programs, who re left to determine how th…
Don't answer this if it isn't legal to answer, but do you have any examples you can share? I can entirely picture the process, and completely believe that it happens, but I don't have a mental image of what the end result looks like.
Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
141–150 of 257 posts
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#142Interesting, seems an effort to find out who was abusing ranges that were exclusively allowed or disallowed based on the ranges. Malware that tries to look like something else that uses a state level IP range to evade blocking, or check for blocks.[1]
>I interpret this to mean that the objectives of this effort are twofold. First, to announce this address space to scare off any would-be squatters, and secondly, to collect a massive amount of background internet traffic for threat intelligence.
>On the first point, there is a vast world of fraudulent BGP routing out there. As I’ve documented over the years, various types of bad actors use unrouted address space to bypass blocklists in order to send spam and other types of malicious traffic.
Cloudflare example shows how much traffic some of these ranges that are included/excluded have when turned on.
>On the second, there is a lot of background noise that can be scooped up when announcing large ranges of IPv4 address space. A recent example is Cloudflare’s announcement of 1.1.1.0/24 and 1.0.0.0/24 in 2018.
>For decades, internet routing operated with a widespread assumption that ASes didn’t route these prefixes on the internet (perhaps because they were canonical examples from networking textbooks). According to their blog post soon after the launch, Cloudflare received “~10Gbps of unsolicited background traffic” on their interfaces.
>And that was just for 512 IPv4 addresses! Of course, those addresses were very special, but it stands to reason that 175 million IPv4 addresses will attract orders of magnitude more traffic. More misconfigured devices and networks that mistakenly assumed that all of this DoD address space would never see the light of day.
Looks like a new cybersecurity policy/process started on inauguration day. Probably a defensive or offensive measure to combat the supply chain attacks that may well have used those ranges in evading blocking.
Why use a front company? As a honeypot.
If other scammers are using spoofing the ranges then another company does it, that doesn't raise alarm in the other entities abusing the same trick. If you announce it as DoD then it may scare off the others.
In any good investigation, you want to shroud the data/intel collection. Using a front company, or series of levels of fronts, is the way you have to go about it.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#143Earlier quoted context omitted.
That isn't really how it works anymore. It's possible (and standard) to push any political agenda without ever stating an opinion directly. It's all about which specific facts you choose to report and which you choose to ignore. It's very easy to select and report only facts that make group A look good, or only facts that make them look bad. In that way, 2 news sources can give people the opposite opinion without any…
And furthermore, public sentiment (and therefore elections) are decided by what the main sources of media determine is the most important news. Example: Cops have shot a thousand people a year for several years in a row (maybe a decade). About 300 of those each year have been black, which is a disproportionate amount by some measures. However, it is nowhere near the biggest problem in our country even for black peopl…
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#144Earlier quoted context omitted.
Outsourcing to private companies also (somehow) appeases the "small government" folks, even when it costs more/works worse.
Somehow? Money the spent is money in the economy, not in the government. It’s pretty easy to understand, I think.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#145Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#146Earlier quoted context omitted.
Who are the people associated with that company? I’d like to further investigate them.
You can look up the company name on Florida's Division of Corporations: http://search.sunbiz.org/Inquiry/CorporationSearch/ByName The Delaware company is registered there as a an "outside of the state of Florida" entity operating in Florida. Some actual people names are listed. I'm fairly confident it's the same company, as the Plantation, FL address is there.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#147Earlier quoted context omitted.
In our case, we were setting up VPN tunnels to a partner, who for some reason required that the addresses on our side should (appear to be) public IP addresses. So we couldn't use 10/8 or 192.168/16 in (that part of) our network. They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were uniqu…
There's also 172.16/12 :) But yeah I agree. If you're running a VPN for a large company it's kinda hard to avoid such conflicts. In my work we use 10.0.0.0/8 but of course some people use the same at home even though 192.168/16 is way more common. In general I find 172.16/12 the least common in the field.
It just looks nicer to me which shows the power of Apple and how easily I am influenced.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#148I want to reply to the following dead comment [1] > Aah, the wapo, that's Bezos, isn't it? It actually doesn't seem that unreasonable to me that a company as large as Amazon sees vast, unused resources held by the government. They publish an article as a sort of "wink wink, nudge nudge" to see if they can get it put up for auction. In fact, I'd be shocked if someone at Amazon or another company hasn't tried to ask th…
Had Amazon won JEDI, a significant chunk of those IPs would exist on their infrastructure.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#149Earlier quoted context omitted.
DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs for a 2 year tour of duty fixing pressing issues in DoD tech via pretty broad authority to sidestep A) the usual senior military slow-roll* in the way of these fixes B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech. DDS Hires a lot of motivated engineers who would be in civil service…
> DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs I wish USDS would do this as well; I feel like they'd attract a lot more talent. Although perhaps they want to attract exactly the kind of talent who would take a big pay cut out of a sense of service/duty. > Cool stuff and I’d work for them in a second For myself, while I recognize that military is a necessary evil in the wor…
It’s the whole those who seek power are least suited to it schtick.
I understand your reluctance and you of course make your own life choices but something to consider.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#150Earlier quoted context omitted.
These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.
Ohh, I think I see. So instead of (or in addition to) creating internal subnets inside 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, they set up subsets inside DoD's 11.0.0.0/8 etc., and it worked out because there were no external BGP announcements for those ranges. But now that there are, if they did not explicitly configure their border gateways to route those ranges inside their networks, the traffic may now lea…