Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

21–30 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#21
post #14
post #8

Earlier quoted context omitted.

These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.

Ohh, I think I see. So instead of (or in addition to) creating internal subnets inside 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, they set up subsets inside DoD's 11.0.0.0/8 etc., and it worked out because there were no external BGP announcements for those ranges. But now that there are, if they did not explicitly configure their border gateways to route those ranges inside their networks, the traffic may now lea…

Maybe DoD is trying to catch security flaws caused by traffic intended for their own internal networks accidentally reaching the public internet? Advertising those IPs publicly and logging all traffic could be a good way of detecting such bugs in DoD systems.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#22
post #16
post #8

Earlier quoted context omitted.

These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.

Why would you do that though when there are perfectly fine internal address ranges available?

I suspect there are a decent number of network engineers who think it's funny to use DoD IPs for their internal network, especially given what their logging system will probably tell them by default.

If you drive around with a WiFi stumbler running, you'll run into networks with names like "UTAH DATA CENTER" and "SIPRnet", etc for the same reason.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#23
post #16
post #8

Earlier quoted context omitted.

These IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.

Why would you do that though when there are perfectly fine internal address ranges available?

Two things that come to mind are running out of private address space (a /8 isn't that large), or wanting address space that doesn't clash with other private networks (e.g. to ensure a VPN doesn't overlap with home networks). There's probably more reasons.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#24
post #20

Still seems a bit odd to me. It doesn't explain why "GLOBAL RESOURCE SYSTEMS, LLC" is involved. Poking around, the individuals associated with that aren't government employees. The company was formed 9/8/2020 in Delaware.

Means nothing. Companies can be a front for a government.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#26
post #7

"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems" I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?

Way back when, I was working at a startup with little clue what I was doing. Long story short, I setup a VPN network to connect 600 devices through 8 wifi routers to a VPC. I used 11.0.0.0/8 because I didn't want to bother sorting through the conflicts with 10.x, 192.168.x, and 172.x which were all used at various places throughout the chain (e.g. the routers on 192, some upstream services on 10.x and 172.)

All I had to do to make it work, IIRC, was add an ip routing rule to prioritize our internal routing for traffic on 11.0.0.0/8 instead of sending it over the default interface.

This solution worked fine, but it broke in weird ways and I remember one time I did arp -a on one of the Amazon boxes and saw some DoD registered addresses, which was a little alarming, but I just chalked it up to my not understanding the details.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#27
post #20

Still seems a bit odd to me. It doesn't explain why "GLOBAL RESOURCE SYSTEMS, LLC" is involved. Poking around, the individuals associated with that aren't government employees. The company was formed 9/8/2020 in Delaware.

If I were to guess, because private companies aren't subject to FOIA requests. It's a little trick the gov't has been doing for some time now to avoid legitimate, legal scrutiny by the public.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#28
post #24
post #20

Still seems a bit odd to me. It doesn't explain why "GLOBAL RESOURCE SYSTEMS, LLC" is involved. Poking around, the individuals associated with that aren't government employees. The company was formed 9/8/2020 in Delaware.

Means nothing. Companies can be a front for a government.

Well, yes, but I'm interested in "for what purpose, in this specific case".

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#29
post #27
post #20

Still seems a bit odd to me. It doesn't explain why "GLOBAL RESOURCE SYSTEMS, LLC" is involved. Poking around, the individuals associated with that aren't government employees. The company was formed 9/8/2020 in Delaware.

If I were to guess, because private companies aren't subject to FOIA requests. It's a little trick the gov't has been doing for some time now to avoid legitimate, legal scrutiny by the public.

[deleted]

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#30
post #6

I want to reply to the following dead comment [1] > Aah, the wapo, that's Bezos, isn't it? It actually doesn't seem that unreasonable to me that a company as large as Amazon sees vast, unused resources held by the government. They publish an article as a sort of "wink wink, nudge nudge" to see if they can get it put up for auction. In fact, I'd be shocked if someone at Amazon or another company hasn't tried to ask th…

Had Amazon won JEDI, a significant chunk of those IPs would exist on their infrastructure.
Post reply on HN