Live data from Hacker News

Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

washingtonpost.com

61–70 of 257 posts

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#61
post #55

Earlier quoted context omitted.

If that were true, depending on path inforation, any botnet or other traffic destined to those networks would end up in this new AS8003 traffic sink, which would create a map of candidate CCP assets to target on the internet. You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracki…

But the internet is not just CCP vs Captain America. I mean my home network has random ips and a shit network admin, so I will also send crap data to the DOD, from Hong Kong. You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing…

I once had a client who decided to use an IP block that was registered to APNIC for their internal network. Made for quite the headache as I tried to track down why there was a ton of traffic supposedly going to China and Japan. -__-

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#62
post #50
post #44

Earlier quoted context omitted.

> running out of private address space Classic merger "solution". Company A uses 10/8 Company B uses 10/8, company A buys company B and orders new subsidiary B to renumber into 11/8 "All you have to do is change every first octet to 11"

or, you know, use NAT to do so :)

how would nat help in this case?

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#63
post #27
post #20

Still seems a bit odd to me. It doesn't explain why "GLOBAL RESOURCE SYSTEMS, LLC" is involved. Poking around, the individuals associated with that aren't government employees. The company was formed 9/8/2020 in Delaware.

If I were to guess, because private companies aren't subject to FOIA requests. It's a little trick the gov't has been doing for some time now to avoid legitimate, legal scrutiny by the public.

Outsourcing to private companies also (somehow) appeases the "small government" folks, even when it costs more/works worse.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#64

Earlier quoted context omitted.

Lots of less clueful network operators worldwide have used the DoD /8 IP blocks internally, under the impression that they'll never show up in the global v4 routing table, essentially for the same purposes that people would use the 10/8 RFC1918 blocks.

Some of those less-cluefull operators include Juniper and Azure[1], Cisco[2][3], and probably many other companies. When Cloudflare put its 1.1.1.1 DNS server into use, it started receiving huge amounts of packets destined to unroutable addresses because the 1.0.0.0/8 space was (mostly?) unused. If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is…

Juniper and Cisco are equipment vendors, not ISPs. If the DOD /8s are used in some documentation examples, that's a whole other thing.

If network operators are taking the theoretical network blocks provided in training examples and attempting to copy and paste them into real world use, that is a whole other problem with training and education. And lack of oversight by senior people who should know better at their company.

1/8 is also a whole other thing because it's a legitimately announced block controlled by, as I recall, APNIC. If it's in some peoples' 20 year old bogon folded that's their problem, not apnic's.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#65
Some details about the ASN announcing the DoD prefixes: https://ipinfo.io/AS8003

It looks like they're not just announcing 11.0.0.0/8 but also a bunch of more specific routes, including 11.0.0.0/13 and 11.0.0.0/24

It looks like currently their only peer is Hurricane Electric: https://ipinfo.io/AS6939

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#66
post #36

Earlier quoted context omitted.

I've tried subscribing to a few news sources, including WaPo, but I can't handle the political agendas (right, left, or any of it). I've had better luck with subscription based aggregators, but nothing exciting enough to want to plug one in particular. Always looking for new options to try.

Yeah all the news sources my parents sub’d to in the early 00s and I sort of figured I’d sub to as well once ready are aggravatingly narrative driven. I’m not sure if I never noticed that, or if it’s a new media approach, but I don’t need “baseball + narrative injection” articles in my life. I’m actually fairly bummed out about this, I go to Reuters now.

News coverage has always been narrative driven to some extent, but previously that was more in selectivity of coverage. The quality of reporting has been in a long slow decline due to a mix of sagging finances and low-no quality control competition. The 'Action News' TV format significantly degraded things, and then blogs and specifically conservative-targeted media drove adoption of the narrative approach.

This revealing interview gives an interesting perspective on the media business around the turn of the century. Note that this is a pdf archive copy saved to draw attention to a particular segment, and I'd urge you ignore that and rad the whole thing. I can't link to the original as it vanished some time ago, and this archive predates the establishment of the internet archive. Thus the presentation is biased (sorry) but it's the only complete copy of the interview I know of. https://zfacts.com/zfacts.com/metaPage/lib/Weekly_Standard_M...

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#68
post #58

Earlier quoted context omitted.

Some of those less-cluefull operators include Juniper and Azure[1], Cisco[2][3], and probably many other companies. When Cloudflare put its 1.1.1.1 DNS server into use, it started receiving huge amounts of packets destined to unroutable addresses because the 1.0.0.0/8 space was (mostly?) unused. If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is…

What IPs does the DoD actually host defense-related services on? E.g. https://www.defense.gov/Resources/Military-Departments/A-Z-L...

NIPR and SIPR don't talk to the global routing tables for v4 and v6. Generally if a DOD person needs to access commercial internet resources for things, it'll be through a separate commercial network purpose LAN, or through something like an rdp session to a Citrix thin client to do that.

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#69
post #50

Earlier quoted context omitted.

or, you know, use NAT to do so :)

how would nat help in this case?

If they're not actually using the whole /8 (highly likely), you can setup a 1:1 NAT. basically from network b, if you want to talk to network a, you find out the address in 11/8 that corresponds to the 10/8 address and vice versa. You can use split horizon dns to make it mostly transparent.

Every networking problem in the world can be solved with more NAT or more encapsulation :)

Re: Millions of the Pentagon’s dormant IP addresses sprang to life on January 20

#70
post #7

"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems" I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?

Not just Chinese companies. I know of one FAANG company that used internal IP addresses in the 11.0.0.0/8 space (in addition to, not instead of, RFC 1918 space).
Post reply on HN