21 ms·
China Telecom's Internet Traffic Misdirection
- commandlinefan 8y agoI'm continually amazed at how insecure almost every aspect of internet routing is - it mostly boils down to a sort of "gentlemen's agreement" that everybody will follow the rules.
- toomuchtodo 8y agoInternet routing (BGP), SMTP, and DNS (not inclusive, just off the top of my head) were developed during the very beginnings of the internet, without much thought into today's use and scale. Today you'd do better, with hindsight being 20/20.
- Mtinie 8y agoThat's certainly true. But now that we have the benefit of hindsight, isn't the only reasonable option to start to take the steps to correct the obvious problems?
- toomuchtodo 8y agoYes, with a "but" the size of celestial bodies: it's a herculean effort. Witness how long IPv6 has taken to obtain traction (and the lack of any traction on DNSSEC, and the resulting DNS over HTTP shims). These are improvements that occur over years, if not decades and require substantial human and financial resources to deliver on.
- Mtinie 8y agoNo doubt. I didn't mean to trivialize the effort required to address the existing issues with scaling and securing the global Internet.
- 0x8BADF00D 8y agoWhy do you think IPv6 never took off? Do you think the format of addresses was less human readable, and therefore that’s what led to its slow adoption? What if the address was instead displayed as a mapping using a data format like JSON?
- toomuchtodo 8y agoNetworks found ways to reduce IPv4 usage, or support dual stack early on when necessary. Turns out every internet endpoint doesn't need to be directly addressable, and most Internet use cases are one to many (CDNs to eyeballs). https://www.nonog.net/wp-content/uploads/2017/06/Altibox-An-IPv6-Story-NONOG-2017-01-min.pdf https://www.nonog.net/wp-content/uploads/2017/06/Altibox-An-... https://www.networkworld.com/article/3254575/lan-wan/what-is-ipv6-and-why-aren-t-we-there-yet.html https://www.networkworld.com/article/3254575/lan-wan/what-is...
- q3k 8y agoBecause it takes effort and CAPEX to deploy it and most ISP are for-profit entities.
- tptacek 8y agoThe "DNS over HTTP shims" are not the result of DNSSEC taking too long to be adopted, but rather the fact that DNSSEC doesn't provide the protection that DoH does. People have a lot of weird ideas about what DNSSEC does; in particular: it doesn't encrypt queries.
- topspin 8y agoOne of the best steps is modern protocols. China - or whomever - can collect all the QUIC packets they want and it won't tell them much. The incentive for these games goes way down when all you get is some connection metadata and cryptographic line noise.
- throwaway2048 8y agoNot if you control CAs. Cert pinning only works in a limited amount of cases, and certificate transparency only works with CAs who have agreed to implement them (Which is not the vast majority).
- jopsen 8y agoCT will take time, I wouldn't be surprised if it catches on and becomes are requirement further down the line.. But sure, it won't happen overnight.. just saying gaps are closing :)
- tialaramex 8y agoFinishing the entire Certificate Transparency system will take time, but the elements that exist today already work fine. Install Google's Chrome browser. The browser checks for SCTs (the proof that the certificate was logged) and will reject new certificates that don't include such proof. It has been doing this since April. Try this URL: https://invalid-expected-sct.badssl.com/ https://invalid-expected-sct.badssl.com/ If you visit that in Chrome it gives you a full page interstitial warning it's bogus and if you click past the page is labelled "Not Secure". In other popular browsers it works fine, because it has a perfectly nice certificate but the Bad SSL site is deliberately not presenting the SCTs for it. [[ It's hard to do this by accident, most places that give lay folk a certificate will assume your goal is to have your certificate accepted, so they will log a "pre-certificate" for you and bake the SCTs inside the certificate they give you and you can't remove those ]] But yes, fully completing Certificate Transparency will be more work, we need a Gossip system so that monitors can consult each other to detect a split horizon, and mechanisms for clients to show summaries of what they know to determine if there are conflicts. What we have now is like if you have a house you've half-built, there is no roof over two rooms, and no electricity, and the floor is bare dirt. But, it's still a house, and in a rain storm it's better to be inside that unfinished house than out in the cold and wet. The people outside in the rain don't think "That guy's house doesn't have triple-glazed windows" they think "Lucky bastard isn't out in the rain like me".
- cwkoss 8y agoDo you know of any interesting alternative protocols proposed recently?
- thrower123 8y agoAt this point I'm inclined to think you'd be more likely to get bogged down for decades bikeshedding behind proposals in a standards consortium that has no actual power to enforce them, and the results would be a horrific mishmash with terminal second-system syndrome...
- cm2187 8y agoA "gentlemen's agreement" that was designed to sustain a nuclear strike...
- DoctorOetker 8y agoI didn't know that, was this the motivation of the current design? is there a source to back this up?
- toomuchtodo 8y agohttps://www.wired.com/2012/09/what-do-the-h-bomb-and-the-internet-have-in-common-paul-baran/ https://www.wired.com/2012/09/what-do-the-h-bomb-and-the-int...
- TeMPOraL 8y agoThe two aren't at odds. Packet routing was designed to survive sudden and severe loss of network paths, but it still assumes that participants on the network are cooperative players.
- throwaway2048 8y agoBGP was designed far after that era of ARPANET
- StudentStuff 8y agoSuch is the nature of BGP. Something like SPF (eg: an authorized AS list for an IP block) and DMARC (reporting about who tried to broadcast what IP block and was rejected) would be great, perhaps even have the latter component convey attack info so ISPs could deal with infected clients automatically. Basic security mechanisms when it comes to large ISP networks are a pipe dream though, instead we get vendors pushing extremely vulnerable Juniper gear cause its reasonably priced, meanwhile these boxes have new root exploits found multiple times a year. None of the vendors give a crap about security, Cisco pays it some lip service (to win gov't contracts) but charges a premium for basic features.
- jopsen 8y agoI'm amazed telecoms let's this happen, routing massive amounts of traffic the wrong way, must cause a lot of latency, right?
- felix_nagaand 8y agoSure, but how many users care about 20ms to their local data farm versus 70 cross country and maybe 200 to China?
- cronix 8y agoRight, they generally say "my phone is getting slow, time to upgrade"
- jgrahamc 8y agoAnd that agreement is trying to be enforced using PKI: https://blog.cloudflare.com/rpki/ https://blog.cloudflare.com/rpki/
- e40 8y agoI'd like to point out that government used to run by agreements that were like that, and look what has happened in that domain. I say this as a warning what the internet could become.
- dangerlibrary 8y agoYour analogy is confusing. I have no idea if you are talking about international, national, or local agreements. I also have no idea what your opinions are. Your comment simultaneously contains almost no information is super off topic.
- magicbuzz 8y agoAnd state actors are proving themselves to not be gentlemen at all.
- jmartrican 8y agoThis is so stupid that we keep doing business with the Communist Party of China.
- StudentStuff 8y agoIts not as though our domestic technology vendors care about security. JunOS is constantly having new vulnerabilities found, and Cisco ain't much better, but charges a premium price as they are viewed as the market leader and pay some lip service to security.
- olliej 8y agoOr the government of Australia which has laws allowing similar...
- consumer451 8y agoI just don’t understand why the telecom agreements are not reciprocal. If no foreign nation is allowed to put a POP in China, then why is China allowed to put POP’s all around the world?
- localguy 8y ago"Loading..." the page doesn't work without JavaScript enabled for no reason.
- cronix 8y agoOther links: https://dyn.com/blog/china-telecoms-internet-traffic-misdirection/ https://dyn.com/blog/china-telecoms-internet-traffic-misdire... http://www.circleid.com/posts/20181105_china_telecom_accused_of_misdirecting_internet_traffic/ http://www.circleid.com/posts/20181105_china_telecom_accused...
- DevoidSimo 8y agoIt's using ajax to fetch the actual article. Seems a bit strange since it's static
- jachee 8y agoImagine that: Oracle doing something more complex than necessary. /s
- burtonator2011 8y agoThis is one of the reasons TLS/SSL and crypto is so amazingly important. Go ahead, monkey around with BGP, since I have the public key of the recipient of my packets I can detect this and block any type of misdirection.
- maltalex 8y ago> Go ahead, monkey around with BGP, since I have the public key of the recipient of my packets I can detect this and block any type of misdirection. And how did you get that public key? An attacker could pretty easily obtain a valid Let's Encrypt certificate using a BGP hijack. Also, the CA system is in bad shape - CAs have been hacked and certificates were leaked. Not to mention that some of the CAs your browser trusts are not entirely trustworthy or are located in untrustworthy countries. Oh, and from time to time there are attacks against TLS itself (e.g. https://drownattack.com/ https://drownattack.com/)
- dcbadacd 8y agoWe should definitely talk more about those CAs and should totally have a way to force only certain CAs should be able to give out certs for a domain. Oh wait, it's called HPKP and it's being removed D:
- jopsen 8y agoExpect-Ct anyone? Then we can delist compromised CAs, yay :) (Sure, it'll take time, but gaps seems to be closing on so many layers)
- olliej 8y agoHPKP was a bad standard - there’s no way it could be used safely at scale. There are just too many ways to accidentally screw up, and that’s before you start dealing with actual attackers. CT allows you to detect misissuance - theoretically you could have a monitor service that watched all the logs for changes to your domains. Longer term something (no opinion stated on exactly what) needs to be done to rectify the trust model for BGP and DNS
- resters 8y agoCombine this with exploits into one or more broadly trusted certificate authorities (which surely exist) and it's pretty amazing how much data China would have been able to obtain. Every time I bring up the following point someone chimes in that it's a bad idea, but I still fail to understand why it's not easy to pick which CAs I want to trust by picking a list of entities/people I trust and then adopting their recommendations for which CAs to trust. This would be a few clicks of UI to let me be intelligently paranoid while maintaining only a layperson's understanding of why (say) Bruce Schneier decides to trust some and not others.
- freeflight 8y agoSounds a bit like how ad-block plus handles the blocking based on lists to which you subscribe, just with certificate white/blacklists?
- aaaaaaaaaab 8y agoThat’s basically PGP.
- cwkoss 8y agoDistributed trust and vouching systems are going to be the next big thing.
- jopsen 8y agoI personally think certificate transparency and Expect-Ct headers will do far more to detect China-in-the-middle. Nothing is more embarrassing than getting caught with your fingers in the cookie jar. Besides I trust CAs will be de-listed if proven compromised.
- tinus_hn 8y agoChina would only be annoyed if you made it out to be a bad thing. Everybody knows that, like the US, they snoop up any information they can get their hands on. Which makes it even more likely they didn’t do an active attack because there’s more chance of being caught if you don’t care.
- 8y ago
- walrus01 8y agoIf BGP4 were designed today, it would look very different.
- martinald 8y agoSomewhat offtopic but which tool shows you the AS number + info alongside the traceroute in the screenshot?
- jwbensley 8y agoI would guess that the author copied the results into a table and prettified them and added in details like location. At the top of the screenshot it says "traceroute from London to ..." - no traceroute program knows where it is in the world! Also the locations of each hop in traceroute NY > Chicago > Ashburn etc., no traceroute program will know where in the world those IPs are. I suspect the author has guestimated based on the reverse DNS record for the IPs and latency. Traceroute does have the ability to show you the ASNs in a path but that is based on a WHOIS lookup of the IPs that it's discovering. So it could be wrong by assuming the IP address of each hop was announce by the ASN that owns it.
- agentphil 8y agothousandeyes.com, a network intelligence platform, gives you all that information in one place.
- deleted 8y ago[deleted]
- gcb0 8y agolol. typical anachronistic oracle. their blog fails fail to render on 2 out of 3 browsers I tested. What is this? 1995?
- praneshp 8y agoCan I ask what browsers? If you've disabled Javascript, I'd argue that's the anachronism.
- gcb0 8y agofirefox mobile with uBlock origin. Edit: ha! ironically, Oracle site about china spying on you won't load the content unless you allow google analytics code to run. If google analytic code fail, the rest of their code also fails.
- pinusc 8y agoI can read the article just fine on Firefox for Android with uBlock origin. It also loads with no problems through my pi-hole, which blocks Google Analytics.
- deleted 8y ago[deleted]
- cauldron 8y agoCT and Chinese ISPs have been hijacking user traffic for decades, profiting off of it by selling traffic dump to data exploiting companies, insert ads in webpages, steal social media tokens (for follower boosting and ads retweeting). I've found China Unicom openly hawking their data mining products. https://imgur.com/a/uNxA50K https://imgur.com/a/uNxA50K
- mehrdadn 8y agoTangent, but are traceroutes spoofable (barring timing differences), or would they break too many other things to be practical? I'm wondering if anyone might do that to hide their tracks.
- nrki 8y agoYes. You can set your reverse DNS to whatever you want if you own the IP blocks. See also: https://news.ycombinator.com/item?id=5192656 https://news.ycombinator.com/item?id=5192656
- furkitolki 8y agoAccording to traceroute, I wonder what makes United States safe and China not. Both not safe.
- ggm 8y agoHanlon's razor has been raised on NANOG.
- zozbot123 8y agoHow about just globally blocking AS4134 and AS9318?
- baybal2 8y agoYou will be surprised how many companies already doing so
- mirimir 8y agoOK, so I'm sitting here, posting to HN in Firefox. And if I like, I can open a terminal and run something like: traceroute news.ycombinator.com | grep -f chinese-ipv4 -f chinese-hosts And indeed, there could be a Firefox extension that did that, right? So at least, users would know.
- jwbensley 8y agoIts difficult for the "average user" (define as you please) to know what what path should look like though. Lots of ISPs will have private peerings to others ISPs/content providers/carriers etc. which aren't publically listed anywhere.
- mirimir 8y agoI'm not suggesting that the (say) Firefox extension would show the path. It would just show whether the path included devices in whatever country. In this case, China. Users wouldn't need to know details. There are many sources of geolocation data that the extension could draw upon.