Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

231–240 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#231

TampaBay times has a more detailed article w/ some details from netsec researchers. They're indicating a well-known spammer is behind the company. https://www.tampabay.com/news/military/2021/04/24/pentagon-m... This Sunbiz record has company principals and filings from 2007-2013 - inc names (not in TBT article) and another dropbox address, this one in Chicago http://search.sunbiz.org/Inquiry/corporationsearch/SearchR…

My reading of the Tampa Bay Times article is that the company name was copied from that of a supposedly defunct front for a spammer. The individual supposedly behind it has done DoD contracts before and has supposedly retired.

Both of these leads have a lot of "supposedly"s attached, but the one to the spam front is a lot more tenuous.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#232

TampaBay times has a more detailed article w/ some details from netsec researchers. They're indicating a well-known spammer is behind the company. https://www.tampabay.com/news/military/2021/04/24/pentagon-m... This Sunbiz record has company principals and filings from 2007-2013 - inc names (not in TBT article) and another dropbox address, this one in Chicago http://search.sunbiz.org/Inquiry/corporationsearch/SearchR…

My reading of the Tampa Bay Times article is that the company name was copied from that of a supposedly defunct front for a spammer. The individual supposedly behind it has done DoD contracts before and has supposedly retired. Both of these leads have a lot of "supposedly"s attached, but the one to the spam front is a lot more tenuous.

This is helpful. Thank you.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#233
post #115

Earlier quoted context omitted.

DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs for a 2 year tour of duty fixing pressing issues in DoD tech via pretty broad authority to sidestep A) the usual senior military slow-roll* in the way of these fixes B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech. DDS Hires a lot of motivated engineers who would be in civil service…

> DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs I wish USDS would do this as well; I feel like they'd attract a lot more talent. Although perhaps they want to attract exactly the kind of talent who would take a big pay cut out of a sense of service/duty. > Cool stuff and I’d work for them in a second For myself, while I recognize that military is a necessary evil in the wor…

I think it’s ok to have that self awareness about where your values line is, when it’s paired with understanding that you’re able to abstract away that public service to someone else who does it for you.

A ton of folks want to have a free lunch in that respect, especially in tech. God help them if Amazon wins the JEDI contract while they work there, but other nefarious work FAANGs get up to while employed at one is ok as long as it’s ~out of sight. Like the Dragonfly project at GOOG...

Similarly, there’s this issue of so much fundamental tech came out of huge DARPA grants, NIST work, and so on. It’s ok if you don’t want to be the one working with DARPA/DDS, but tech’s roots are so tied to them that it has to be ack’d.

The line of folks who “would be in the DoD but for X” is long, and it’s a comically reoccurring conversation for people who do DoD work. That conversation is much different if that awareness exists, though.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#234
post #176

Earlier quoted context omitted.

rpki[0], but that doesn't mean fake bgp announcements, considered bgp hijacking[1], don't happen[2]. Once every t1 drops invalid prefixes, then rpki will effectively mean no T1 can turn off the internet for other ASNs, but everyone signing their prefixes is required to mean nobody can fake announce an IP. It looks like the DOD's routes are indeed signed[3]. 0: https://isbgpsafeyet.com/ 1: https://www.thousandeyes.com…

The HE link doesnt mean they are signed. It just means the IRR records are correct. You would see a green key on the prefixes if they were signed (and correct) The prefixes are in the https://www.radb.net Somebody (as everybody can do this with radb) said to RADB that 8003 is the correct origin for these prefixes. Considering the DoD hasnt rained hell on the RADB, Id guess theyre good as well, but its not RPKI signed…

Ah, my bad. I looked around and now know what RPKI signed actually looks like on HE. https://bgp.he.net/ip/1.1.1.1

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#237

TampaBay times has a more detailed article w/ some details from netsec researchers. They're indicating a well-known spammer is behind the company. https://www.tampabay.com/news/military/2021/04/24/pentagon-m... This Sunbiz record has company principals and filings from 2007-2013 - inc names (not in TBT article) and another dropbox address, this one in Chicago http://search.sunbiz.org/Inquiry/corporationsearch/SearchR…

The CEO of ARIN has confirmed that the DoD has authorized this specific company to advertise these prefixes, so if there's any known spam or fraud involved, you might want to take that up with the federal contracting agency which issued the contract to this company.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#238

Earlier quoted context omitted.

If they're using them for internal networks, they'll (probably) work just like they did before. It's likely many folks are using these as like private RFC-1918 addresses.

If they are private, which they could be, I wonder why they are showing up in public on there... Also, ripe.net has ripe stats... Checked a few of the ranges and seen people other than the dod and these lads announcing the range...

Anyone can put an address in their DNS records, whether it's "theirs" or not. I have several records with 192.168.0.0/16 IPs. The DNS can be seen publicly but obviously they don't route. It's the same thing.

Other folks are definitely using those DoD addresses. For example, I see a bunch being announced by AS23352 / Server Central: https://bgp.he.net/AS23352#_prefixes

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#239

Earlier quoted context omitted.

why?

Its incompatible with IP v4, has a stupid addressing scheme, it requires new router hardware and software for isps to buy and nobody is using it because of all the aforementioned issues.

IPv6 is well over 20 years old. In fact, IPv6 is now older than the IPv4 Internet was when it went mainstream back in the mid 90's. There is really no excuse not to support it...

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#240
post #16

Earlier quoted context omitted.

Why would you do that though when there are perfectly fine internal address ranges available?

In my case I got a class C around about 1992 (back then that was the only way to get on the internet), at some point the ISP above my ISP claimed it as theirs without telling me .... I still use it internally why should I change?

Is it "directly assigned" to you in whois? I got mine around 1993.
Post reply on HN