Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

161–170 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#161
post #16

Earlier quoted context omitted.

Why would you do that though when there are perfectly fine internal address ranges available?

I suspect there are a decent number of network engineers who think it's funny to use DoD IPs for their internal network, especially given what their logging system will probably tell them by default. If you drive around with a WiFi stumbler running, you'll run into networks with names like "UTAH DATA CENTER" and "SIPRnet", etc for the same reason.

The main reason (I've done this at a bank previously) is when you need to ensure you don't overlap with other internal IP (RFC1918 was represented everywhere and routeable internally) and when you're trying to dodge 99% of your engineer's default Docker configs to reduce support request load.

In that case there's never any chance it'll be needed by people using the public internet there, and never any chance it'll be used suddenly by a deployed internal service somewhere else from an outside vendor.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#162

Earlier quoted context omitted.

Maybe DoD is trying to catch security flaws caused by traffic intended for their own internal networks accidentally reaching the public internet? Advertising those IPs publicly and logging all traffic could be a good way of detecting such bugs in DoD systems.

From the article: > What is clear, however, is the Global Resource Systems announcements directed a fire hose of Internet traffic toward the Defense Department addresses. Madory said his monitoring showed the broad movements of Internet traffic began immediately after the IP addresses were announced Jan. 20. > Madory said such large amounts of data could provide several benefits for those in a position to collect and…

> If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies

It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it.

It is not "rerouting a ton of traffic", the traffic was destined toward them in the first place.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#163

Some details about the ASN announcing the DoD prefixes: https://ipinfo.io/AS8003 It looks like they're not just announcing 11.0.0.0/8 but also a bunch of more specific routes, including 11.0.0.0/13 and 11.0.0.0/24 It looks like currently their only peer is Hurricane Electric: https://ipinfo.io/AS6939

One peer? Does that mean all that traffic is flowing through Hurricane Electric?

Yes, it does.

If you traceroute to any of the announced prefixes you'll see that you enter HE space (but as far as I know won't ever get a ping to the destination IP).

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#164

Earlier quoted context omitted.

From my personal experience: a cat died. A very non-important cat. It was the only thing of note in my report.

A random cat's death got to be top secret? Oh gawd...

Things are often classified because of how we know the cat died, not because the cat was special. Suppose you've recruited a foreign intelligence officer to work for you and he happens to mention the cat dying during a debriefing. You can't just declassify the unimportant bits because enough of them will tell you who said it.

It's the same problem as FAANG collecting mountains of "anonymous" metrics. Pretty soon, you can determine who the "anonymous" user is.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#165
post #162

Earlier quoted context omitted.

From the article: > What is clear, however, is the Global Resource Systems announcements directed a fire hose of Internet traffic toward the Defense Department addresses. Madory said his monitoring showed the broad movements of Internet traffic began immediately after the IP addresses were announced Jan. 20. > Madory said such large amounts of data could provide several benefits for those in a position to collect and…

> If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it. It is not "rerouting a ton of traffic", the traffic was destine…

You can debate semantics all you want, it doesn't change the reality of the situation and how the problem of IPv4 address exhaustion is very real and not just down to "incompetent network staff".

The DoD sitting on all that unused address space actively contributed to that problem and now it's exploiting band-aid fixes around it to once again play data kranken of the world under the guise of "We are just fighting APT!".

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#166

Earlier quoted context omitted.

Had Amazon won JEDI, a significant chunk of those IPs would exist on their infrastructure.

JEDI was a deal for internal cloud infrastructure. I don't think they would be utilizing public IP address ranges.

Good point, but, here's an anecdote to serve as a counterpoint:

When I was at a US three-letter department from 2013-2015, they did in fact use non-private IPs for their internal datacenter networks, and even for their office space LAN DHCP lease ranges. It blew my mind when I looked at my laptop and saw a public IP on it's ethernet interface. Watching the realization dawn on my InfoSec peers' faces there was amusing as well. IT personnel way up in the hierarchy blessed with institutional knowledge confirmed to me that using public IPs everywhere is one thing they did to justify sitting on that many public IPv4 addresses. They seemed confident that their firewalls and routing configurations were enough to protect their self-drawn boundary lines, and in many ways, they were right. It also made inter-agency connection agreements quite simple.

So the distinction of public vs. private may not actually matter quite as much in the context of IP ranges used on JEDI.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#167
post #103

Earlier quoted context omitted.

In our case, we were setting up VPN tunnels to a partner, who for some reason required that the addresses on our side should (appear to be) public IP addresses. So we couldn't use 10/8 or 192.168/16 in (that part of) our network. They didn't actually need the addresses to be routable from the public internet (that was the whole point of the VPN). I think the requirement was really a way of making sure they were uniqu…

There's also 172.16/12 :) But yeah I agree. If you're running a VPN for a large company it's kinda hard to avoid such conflicts. In my work we use 10.0.0.0/8 but of course some people use the same at home even though 192.168/16 is way more common. In general I find 172.16/12 the least common in the field.

I personally use a range towards the end of the 172.16/12 reservation for my home network for exactly this reason. Ever since I made the change five years ago I’ve never suffered any conflicts when running a VPN in or out.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#168
post #2

Paywall-free link: https://archive.is/tKOOA

Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.

Great point and totally off-topic, but I wonder if there is someone who reads the NY Times each and everyday in full.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#170
post #162

Earlier quoted context omitted.

> If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it. It is not "rerouting a ton of traffic", the traffic was destine…

You can debate semantics all you want, it doesn't change the reality of the situation and how the problem of IPv4 address exhaustion is very real and not just down to "incompetent network staff". The DoD sitting on all that unused address space actively contributed to that problem and now it's exploiting band-aid fixes around it to once again play data kranken of the world under the guise of "We are just fighting APT…

It’s pretty clear that the DoD realizes how close they were to being forced to sell all that IP space off and wouldn’t have even been able to say “we’re using it” as it wasn’t routed.
Post reply on HN