This is a complete side point, but what does this sentence mean? > Created in 2015, the DDS operates a Silicon Valley-like office within the Pentagon.
The office has a deliberately different type of culture. Edit: more info at https://www.dds.mil/about
Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
51–60 of 257 posts
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#52Earlier quoted context omitted.
DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs for a 2 year tour of duty fixing pressing issues in DoD tech via pretty broad authority to sidestep A) the usual senior military slow-roll* in the way of these fixes B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech. DDS Hires a lot of motivated engineers who would be in civil service…
I don't know Brett super well so I can't speak to the rest of his background, but it's not correct that the Obama admin asked him to take over DDS. DDS's founding head was Chris Lynch, who served in that role until the middle of the Trump administration, when he left government service and that's when Brett got the job.
I saw him present on DDS and his backstory at BSidesLV a few years ago and did a bit of non-profit govttech chatter with the team there.
Correct, it was in the middle of the Trump Admin.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#53Earlier quoted context omitted.
Ohh, I think I see. So instead of (or in addition to) creating internal subnets inside 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, they set up subsets inside DoD's 11.0.0.0/8 etc., and it worked out because there were no external BGP announcements for those ranges. But now that there are, if they did not explicitly configure their border gateways to route those ranges inside their networks, the traffic may now lea…
Maybe DoD is trying to catch security flaws caused by traffic intended for their own internal networks accidentally reaching the public internet? Advertising those IPs publicly and logging all traffic could be a good way of detecting such bugs in DoD systems.
It sounds a bit weird they would have needed 170+M ips to get a good attack sample from the internet if the ip are contiguous, a few thousands would have sufficed. It sounds very weird to expect "China" to suddenly route Xi's dirty videos and why not Iran, Japan, everyone suddenly routing craps there, it's not very targetted and would cost quite a bit to read all the potential tcp packets that got lost by bad WAN vs LAN priority decisions in routers.
Also, it's one shot, so why now ? They would have just lost a huge weapon, if true, in a very public manner, for no particular visible threat, not precise target and at great cost possibly.
I'm okay to believe this was possibly just an inventory/activation exercise because someone noticed they owned stuff they can't use until they register them.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#54Earlier quoted context omitted.
DDS hires professional engineers at a special paygrade pegged to their civilian pay stubs for a 2 year tour of duty fixing pressing issues in DoD tech via pretty broad authority to sidestep A) the usual senior military slow-roll* in the way of these fixes B) the sh**y govt contractors who made the tech and usually get paid to fix their own bad tech. DDS Hires a lot of motivated engineers who would be in civil service…
This is quite interesting — glad I asked!
Some of the projects they talk about doing have huge value-adds to technically underserved groups like military families during mandatory base moves every few years. Those groups are totally dependent on following the system as designed (get your travel voucher here, your goods shipped here, etc) and much of it depends on single option, very janky govt, almost intranet-like, porfals. Iirc, one of their projects was fixing a portal was leaking SSNs like gangbusters. Normal times, that’s a 6 month -> 10 year process to work with the contractor. DDS did it fairly quickly.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#55"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems" I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?
If that were true, depending on path inforation, any botnet or other traffic destined to those networks would end up in this new AS8003 traffic sink, which would create a map of candidate CCP assets to target on the internet. You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracki…
You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing shit networking but not CCP-relevant things ?
And the amount of botnets we have in China that are to scam each other that even the CCP doesn't want ? :D
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#56Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#57Earlier quoted context omitted.
> running out of private address space Classic merger "solution". Company A uses 10/8 Company B uses 10/8, company A buys company B and orders new subsidiary B to renumber into 11/8 "All you have to do is change every first octet to 11"
or, you know, use NAT to do so :)
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#58Earlier quoted context omitted.
Lots of less clueful network operators worldwide have used the DoD /8 IP blocks internally, under the impression that they'll never show up in the global v4 routing table, essentially for the same purposes that people would use the 10/8 RFC1918 blocks.
Some of those less-cluefull operators include Juniper and Azure[1], Cisco[2][3], and probably many other companies. When Cloudflare put its 1.1.1.1 DNS server into use, it started receiving huge amounts of packets destined to unroutable addresses because the 1.0.0.0/8 space was (mostly?) unused. If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is…
E.g. https://www.defense.gov/Resources/Military-Departments/A-Z-L...
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#59Earlier quoted context omitted.
Thanks a lot, Appreciate. It is not I don't want to pay the washingtonpost.com. I just don't have time to read them.
It’s the principle for me. I won’t support any publication with obvious bias.
Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20
#60This is a complete side point, but what does this sentence mean? > Created in 2015, the DDS operates a Silicon Valley-like office within the Pentagon.
More money, I assume. The government does not want to raise all programmers’ pay, so instead of adjusting the pay schedules that apply to everyone, they make a special group that the normal pay schedules don’t apply to. I wonder if it came about because how much of a dumpster fire the first version of healthcare.gov was for the premier of the Affordable Care Act. That probably embarrassed a lot of people.
To your first point, it'd be more accurate to say that many government offices often don't hire any programmers, which can (among other issues) make it challenging for those offices to select strong contractors.