4 ms·
(More) direct link to the publication: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Sicherheit/SiSyPHus/Workpackage4_Telemetry.pdf https://www.bsi.
by heybrendan 8y ago
(More) direct link to the publication: https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Sicherheit/SiSyPHus/Workpackage4_Telemetry.pdf https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Cyber-Si...
Page 31 of the report was of primary interest--hosts hard-coded in diagtrack.dll:
geo.settings-win.data.microsoft.com.akadns.net
db5-eap.settings-win.data.microsoft.com.akadns.net
settings-win.data.microsoft.com
db5.settings-win.data.microsoft.com.akadns.net
asimov-win.settings.data.microsoft.com.akadns.net
db5.vortex.data.microsoft.com.akadns.net
v10-win.vortex.data.microsft.com.akadns.net
geo.vortex.data.microsoft.com.akadns.net
v10.vortex-win.data.microsft.com
us.vortex-win.data.microsft.com
eu.vortex-win.data.microsft.com
vortex-win-sandbox.data.microsoft.com
alpha.telemetry.microsft.com
oca.telemetry.microsft.com
At this point, I would recommend choosing to treat the {akadns.net, microsoft.com, microsft.com} TLDs with general distrust. Also in the report:
40.77.226.249
40.77.226.250
13.92.194.212
52.178.38.151
52.229.39.152
52.183.114.173
13.78.232.226
For convenience, I've enumerated the corresponding CIDRs:
13.104.0.0/14
13.64.0.0/11
13.96.0.0/13
40.112.0.0/13
40.120.0.0/14
40.124.0.0/16
40.125.0.0/17
40.74.0.0/15
40.76.0.0/14
40.80.0.0/12
40.96.0.0/12
52.145.0.0/16
52.146.0.0/15
52.148.0.0/14
52.152.0.0/13
52.160.0.0/11
52.224.0.0/11
I'm not sure how to react to the observation of the usage of "microsft.com". I'll admit my instinct is to perceive this as, at worst, a rather clandestine attempt at circumventing basic DNS black-holing techniques--in which case, well played MSFT.
Now if you'll excuse me, I have some firewall policies to update.
- jlgaddis 8y agoIf you put in a block for *.akadns.net you will very likely experience quite a bit of collateral damage. A lot of large, popular companies use Akamai. Likewise, Ii you drop all traffic from and to those CIDR ranges, well, I hope you don't use any services or sites that are hosted on Azure.
- heybrendan 8y agoExcellent point, and I'm well aware. Vigilance (and a proactive security posture) are the price of privacy--and I suspect nothing of actual value will be lost. It's preferable (to me) to blacklist /everything/ and deal with any future connectivity issues on a case-by-case basis.
- imhoguy 8y ago> akadns.net That is Akamai CDN TLD. Blocking that at this level may break a lot of sites/services. https://security.stackexchange.com/questions/9663/what-is-the-akamai-name-server-i-see-at-some-big-companies https://security.stackexchange.com/questions/9663/what-is-th...
- quietbritishjim 8y agoSorry for the nitpick, but things like .com and .uk are TLDs (top-level domains). Something like microsft.com is simply a domain.
- forapurpose 8y agoIt's more complicated than that. Is co.uk simply a domain?
- quietbritishjim 8y agoYes. Even .uk is a domain - that's why it can be called a top-level domain.