11 ms·
"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems" I don't think I've heard of
by pgn674 5y ago
"several Chinese companies use network numbering systems that resemble the U.S. military’s IP addresses in their internal systems"
I don't think I've heard of this before. What does it mean? Does China operate a disconnected BGP network? Or do they have some modified protocol, or what?
- woah 5y agoThese IP addresses were unused for a very long time, so using them on internal networks worked fine. Once the Floridian company in the article started announcing them, gateway routers on the Chinese internal networks may have started sending their traffic to Florida.
- pgn674 5y agoOhh, I think I see. So instead of (or in addition to) creating internal subnets inside 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16, they set up subsets inside DoD's 11.0.0.0/8 etc., and it worked out because there were no external BGP announcements for those ranges. But now that there are, if they did not explicitly configure their border gateways to route those ranges inside their networks, the traffic may now leak out to DoD's pilot effort.
- jasonhansel 5y agoMaybe DoD is trying to catch security flaws caused by traffic intended for their own internal networks accidentally reaching the public internet? Advertising those IPs publicly and logging all traffic could be a good way of detecting such bugs in DoD systems.
- dannyw 5y agoIt also explains the lack of public commentary.
- capableweb 5y agoNot sure. If the government is doing something large-scale in public (like construction projects [or maybe global IP routing]), they should communicate what is happening before doing it, in order to not phase people.
- ajross 5y agoRight, because if there's anything the Pentagon has been known for over the past seven decades or so it's clear publication and transparent disclosure of all its large scale classified projects so as not to phase the public.
- kelnos 5y agoEh, I wouldn't be surprised if an org like the Pentagon is secretive about things that aren't really necessary to be secrets. It's just kinda in their nature to be that way (kinda like Apple's default-secrecy about products and features). (Also, sorry to be That Guy, but this one always gets to me: in the sense you've used it, it's "faze", not "phase".)
- dunmalg 5y agoI used to work in intelligence. "Secrecy creep" has long been a serious problem inside DoD. How information get classified has largely been left up to low level federal bureaucrats, people my father used to angrily refer to as "big haired women from Mississippi". Basically, they are low level federal office drones, with minimal knowledge about the actual content of classified programs, who re left to determine how they are classified. They start with the core information of a project and classify it "Top Secret". Then they take all the peripheral information of that project and classify it TS as well, just to be safe, because it might overlap with the core info, but they have no clue because they're a GS-4 clerk from Boogerville with a high school diploma. Later as more content is generated in a program, stuff peripheral to the previous peripheral data, which realistically should be classified "Confidential" at most, it too gets classified as TS because of its proximity to the previously over-classified peripheral data. Lather-Rinse-Repeat for a few decades and you have huge swathes of widely known, utterly inconsequential information classified Secret or Top Secret.
- xwolfi 5y agoReading what the DOD said "officially" it appears that maybe they were just looking to see if these IP could be registered, simply. It sounds a bit weird they would have needed 170+M ips to get a good attack sample from the internet if the ip are contiguous, a few thousands would have sufficed. It sounds very weird to expect "China" to suddenly route Xi's dirty videos and why not Iran, Japan, everyone suddenly routing craps there, it's not very targetted and would cost quite a bit to read all the potential tcp packets that got lost by bad WAN vs LAN priority decisions in routers. Also, it's one shot, so why now ? They would have just lost a huge weapon, if true, in a very public manner, for no particular visible threat, not precise target and at great cost possibly. I'm okay to believe this was possibly just an inventory/activation exercise because someone noticed they owned stuff they can't use until they register them.
- freeflight 5y agoFrom the article: > What is clear, however, is the Global Resource Systems announcements directed a fire hose of Internet traffic toward the Defense Department addresses. Madory said his monitoring showed the broad movements of Internet traffic began immediately after the IP addresses were announced Jan. 20. > Madory said such large amounts of data could provide several benefits for those in a position to collect and analyze it for threat intelligence and other purposes. It's interesting how this is framed as something "defensive in nature", when it's yet another massive funnel for data being slurped up by a US government agency. If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies, I doubt anybody would believe a benign "Just checking our security!" explanation.
- ev1 5y ago> If China or Russia would suddenly reroute a ton of traffic from outside their countries, to their respective government agencies It is their IP space. It is entirely on your incompetent network staff if you are stealing IPs that are 1) not yours, 2) in use, 3) not in your country for internal use and on top of that, not rejecting external routes to it. It is not "rerouting a ton of traffic", the traffic was destined toward them in the first place.
- freeflight 5y agoYou can debate semantics all you want, it doesn't change the reality of the situation and how the problem of IPv4 address exhaustion is very real and not just down to "incompetent network staff". The DoD sitting on all that unused address space actively contributed to that problem and now it's exploiting band-aid fixes around it to once again play data kranken of the world under the guise of "We are just fighting APT!".
- bombcar 5y agoIt’s pretty clear that the DoD realizes how close they were to being forced to sell all that IP space off and wouldn’t have even been able to say “we’re using it” as it wasn’t routed.
- hujun 5y agoit is very unlikely to for a company like Alibaba not configuring their BGP right
- zeusk 5y agoHave you seen the talk about AI with Jack Ma and Elon? I wouldn't be surprised.
- Jach 5y agoFWIW Ma seems significantly smarter than he showed during that event when you look at translations of his Chinese (speaking or written). But in any case, even an incompetent CEO can still have competent IT.
- Havoc 5y agoWhy would you do that though when there are perfectly fine internal address ranges available?
- Godel_unicode 5y agoI suspect there are a decent number of network engineers who think it's funny to use DoD IPs for their internal network, especially given what their logging system will probably tell them by default. If you drive around with a WiFi stumbler running, you'll run into networks with names like "UTAH DATA CENTER" and "SIPRnet", etc for the same reason.
- imwillofficial 5y agoI always hated seeing “FBI Surveillance Van” Made me wanna climb out of my FBI Surveillance Van and have a word with them.
- leesalminen 5y agoHa! “Unmarked white van” is the WiFi name at my local dog daycare. I got a good laugh.
- dwarfsandstuff 5y agoMy wifi is called nsa_net
- Godel_unicode 5y agoThere are lots of examples of this type of "squat space" being used for largely internal addressing in addition to rfc 1918 space: https://teamarin.net/2015/11/23/to-squat-or-not-to-squat/ https://teamarin.net/2015/11/23/to-squat-or-not-to-squat/
- motohagiography 5y agoIf that were true, depending on path inforation, any botnet or other traffic destined to those networks would end up in this new AS8003 traffic sink, which would create a map of candidate CCP assets to target on the internet. You could do the same with any AS. I haven't looked into bgp spoofing since about '99, but it seems to have matured since then. The idea of using it as ephemeral canary/honeynet space for tracking botnet C&C traffic seems like a reasonable play.
- xwolfi 5y agoBut the internet is not just CCP vs Captain America. I mean my home network has random ips and a shit network admin, so I will also send crap data to the DOD, from Hong Kong. You imagine the work to figure out if my tcp heartbeats between my torrent server and my nginx proxy are CCP botnets or me misconfiguring my router ? From the same place kinda ? And you imagine the amount of people we are in China that are doing shit networking but not CCP-relevant things ? And the amount of botnets we have in China that are to scam each other that even the CCP doesn't want ? :D
- Forbo 5y agoI once had a client who decided to use an IP block that was registered to APNIC for their internal network. Made for quite the headache as I tried to track down why there was a ton of traffic supposedly going to China and Japan. -__-
- ufmace 5y agoYeah, that's why the stated explanation sounds weird. Suddenly advertise this never-used block, and you're just going to get a massive torrent of previously-internal traffic from bazillions of organizations all over the planet that used it for something internal and were slightly lazy and didn't set up their routing quite right. Probably 99.9% of it is of no use whatsoever to anyone outside that org. It's tough to imagine that anyone thought they'd get any useful information on any hostile CCP activity by doing this. I would also expect that any department doing hostile things on the net would be at least smart enough to not let any of their internal traffic leak out like that, no matter who they actually worked for.
- walrus01 5y agoLots of less clueful network operators worldwide have used the DoD /8 IP blocks internally, under the impression that they'll never show up in the global v4 routing table, essentially for the same purposes that people would use the 10/8 RFC1918 blocks.
- jeroenhd 5y agoSome of those less-cluefull operators include Juniper and Azure[1], Cisco[2][3], and probably many other companies. When Cloudflare put its 1.1.1.1 DNS server into use, it started receiving huge amounts of packets destined to unroutable addresses because the 1.0.0.0/8 space was (mostly?) unused. If you configure your routers correctly, none of these IP addresses should resolve, anyway. If something in your network is intentionally dialing the department of defence, you probably have some kind of problem at hand. In theory this might become a huge problem, but in practice it probably won't. [1]: https://www.juniper.net/documentation/en_US/vmx/information-products/pathway-pages/getting-started/vmx-gsg-azure.pdf https://www.juniper.net/documentation/en_US/vmx/information-... [2]: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/LTRDCN-2100-LG.pdf https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf... [3]: https://security.stackexchange.com/questions/157682/why-does-my-charter-cable-modem-have-a-static-arp-entry-tied-to-a-department-of https://security.stackexchange.com/questions/157682/why-does...
- ethbr0 5y agoWhat IPs does the DoD actually host defense-related services on? E.g. https://www.defense.gov/Resources/Military-Departments/A-Z-List/ https://www.defense.gov/Resources/Military-Departments/A-Z-L...
- walrus01 5y agoNIPR and SIPR don't talk to the global routing tables for v4 and v6. Generally if a DOD person needs to access commercial internet resources for things, it'll be through a separate commercial network purpose LAN, or through something like an rdp session to a Citrix thin client to do that.
- photon-torpedo 5y agoIf I remember correctly, one of the large Chinese supercomputers (ex #1 in the TOP500) uses the 11.0.0.0 address space for its internal network.
- TechBro8615 5y agoWay back when, I was working at a startup with little clue what I was doing. Long story short, I setup a VPN network to connect 600 devices through 8 wifi routers to a VPC. I used 11.0.0.0/8 because I didn't want to bother sorting through the conflicts with 10.x, 192.168.x, and 172.x which were all used at various places throughout the chain (e.g. the routers on 192, some upstream services on 10.x and 172.) All I had to do to make it work, IIRC, was add an ip routing rule to prioritize our internal routing for traffic on 11.0.0.0/8 instead of sending it over the default interface. This solution worked fine, but it broke in weird ways and I remember one time I did arp -a on one of the Amazon boxes and saw some DoD registered addresses, which was a little alarming, but I just chalked it up to my not understanding the details.
- twic 5y agoI did the same with 51/8 back when that was owned by the UK Department of Work and Pensions but not publicly routable.
- nanliu 5y agoAlibaba for example use DoD address ranges for their management servers running Alicloud services. They assumed since nothing in their cloud platform would connect to those addresses they can use these them to alleviate IPv4 shortage. In Alicloud, the customer have the right to use any RFC1918 addresses, so they had to be creative since they didn’t have sufficient IPv4 addresses.
- sterlind 5y agobut if they're not filtering BGP announcements for those ranges (however unlikely), and the GFW isn't blocking traffic out to those addresses (even more unlikely), and the internal metrics were high (super unlikely), I guess it'd slurp out all the traffic? maybe this was a weird smash-and-grab.
- Aperocky 5y agoYou'd be surprised, but GFW is a blacklist not a whitelist, as such the blocked domains and/or IPs are a very small subset of all public addresses out there.
- fred256 5y agoNot just Chinese companies. I know of one FAANG company that used internal IP addresses in the 11.0.0.0/8 space (in addition to, not instead of, RFC 1918 space).
- walrus01 5y agoEvery time I've seen this it's because of inefficient and wasteful use of 10/8 internally. Like, not every tiny site or thing needs a /24. Once the wasteful use becomes entrenched as a practice, it would be very labor intensive and time-consuming to go on a renumbering plan. As compared to the effort to just use 11/8. And then ultimately because of refusal to get over the technical hurdle of using IPv6 for internal management.
- knorker 5y agoBut have you seen inside of FAANG?
- snowwrestler 5y agoWell I would hope it’s not Apple since they already own all of 17.0.0.0... one of only 7 private companies that own their own /8, as far as I know.
- globular-toast 5y agoWhy don't they use IPv6? Is there still a lot of hardware out there that doesn't support it? It seems perfect if it's internal only.