7 ms·
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
by grommz 2mo ago
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
- hhh 2mo agoI do know of at least one company who has black-holed the entire DoD ip space and are using it for internal space, which is why I gave a speculation warning... it's really strange regardless.
- kotaKat 2mo agothere's a couple subnets I (ab)use in the DOD IP space for my home network knowing they'd never put them on the open internet. it's also fun to throw logging for a loop if someone digs. 22.0.0.0/8 - it's basically free real estate!
- cryptonym 2mo agoI have seen ISP doing CGNAT on DOD IP space.
- walrus01 2mo agothe entirety of 10/8 and 172.16/12 and 192.168/16 wasn't large enough for your house?
- kotaKat 2mo agoi deal with a lot of nerds that are all interconnected with one another and nobody can agree on a common subnet for their houses when we all decide to exchange routes internally. ;)
- myself248 2mo agoI deal with a lot of nerds, but starting in about 2008 we all segmented up the 10.x space and each of us has a /16, with each site we manage having typically a /24 or /22, so nobody overlaps. We can light up tunnels between each other and never have a collision. We have a little internal registry on a private wiki, and it's been serving us well for... oh dear, almost two decades now. Crucially, we set aside the common 10.1 and 10.10 ranges as nonroutable, so any devices that default into those have to be dealt with before they can live on the wider network. Newcomers get handed a block and have to renumber, or NAT into it, or whatever, but they cannot emit bogons. At a small scale (first-name basis), this works.
- ErroneousBosh 2mo agoI work for a large organisation that has various blocks scattered around 10./8, some with highish values for the second octet and some with lowish values, so say 10.129.0.x/24 and 10.3.0.x/24 to pick just two out of a couple of thousand. But one of our vendor networks uses 10.32.x.x/32 for various radio gateways, and the radios themselves all locally expose (this is where I give away too big a clue as to what I do) 10.0.0.101 as a management address that emits important link status data. So you can imagine what a godawful bùrach everyone's routing tables are.
- xoa 2mo ago>the entirety of 10/8 and 172.16/12 and 192.168/16 wasn't large enough for your house? Just to chime in agreeing with sibling comments, the issue is when it's not about just your house and you're deep into self-hosted stuff with a lot of different properties and businesses other people's houses all sharing resources. Without a lot of coordination and consideration, which in practice doesn't really happen easily given the adhoc nature such things tend to organically develop out of, and all the random stuff that wants specific addresses at least for setup, it actually gets pretty easy to run into collisions. Allocations typically are definitely inefficient in many respects but also made sense in the context they were first done and of course can be a certain amount of effort to change. In an ideal world I sorta feel like "IPv6" should have been more along the lines of <12 octet prefix>:<IPv4>, everyone gets a prefix or set of prefixes that they actually own and are consistent worldwide, or at least only change when geographic location changes, and then can just have the entire 32-bit IPv4 space for LAN however they want. Then you only have to care about prefix between LANs and it could all be extremely automated, internally you only need to use something that looks like IPv4 with the network hardware transparently able to handle prefixes for WAN. Backwards compatibility story would be a lot more straight forward too. Oh well. @kotaKat: that's a great idea and I don't know why I forgot I played with that like 15 years ago. Really handy as a backup space that almost certainly won't collide with any commercial hardware at least.
- webstrand 2mo agoI also do this, except 7.0.0.0/8 instead. Its great for not conflicting with hotel wifi dhcp.
- bityard 2mo agoThe CGNAT space (100.64.0.0/10) is also free real estate for container virtual/overlay networks when you don't want to (or can't, thanks to IT) use the RFC-1918 subnets.
- bflesch 2mo agoThis will trip up most SOC workflows in funny ways, and I like it. IPs having a global distinction between public/private is a convention, but local routing can widely differ. Same with the "China Cyberattacks" - the guys sitting on top of my outgoing fiber can simulate any IP address they want to me.
- freeone3000 2mo agoIt’s only a convention in the sense that the IANA is a convention: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml https://www.iana.org/assignments/iana-ipv4-special-registry/... 192.0.0.0/24, 10/8, 172.16/12, and various other subslices of 192/8 are reserved for local use and are not publicly routable.
- ErroneousBosh 2mo agoI recently troubleshot an installation for someone where at some point in the past they'd picked 1.1.1.0/24 as their address range because "all that 192 stuff was silly and too complicated". You know, I'm not sure I can explain how I feel about this properly without waving the shotgun around.
- inigyou 2mo agoYet another thing ipv6 solves. Yeah you can do the officially supported fdXX:XXXX:XXXX:... but you can also just pick something like 1::1 and it's unlikely to conflict with the current global range. If you're gonna do that, though, it's better if you use fd00:... or one of the other assigned ranges so it's still in the standard range. OSes use this as a heuristic for source address selection.
- kowbell 2mo ago"all that 192 stuff was silly and too complicated... but this fd00: stuff is easy peasy!"
- iso1631 2mo ago192.168.0.0/24 -> fd00:0::/64 192.168.1.0/24 -> fd00:1::/64 192.168.2.0/24 -> fd00:2::/64 192.168.240.0/24 -> fd00:240::/64 It's not a great idea, but its no harder. No need to mess around with setting up DHCP, remembering if your router is top or bottom of the subnet, and if you want 500 devices on a single subnet that's no problem. Now if you still need ipv4 then yes, ipv6 is stupid as you have double the pain for none of the gain, but if you are ip6 only then its far easier.
- SV_BubbleTime 2mo agoI doubt any endpoints are entirely ipv6. So it seems like it helps ISPs and large networks router… but they never had problems with address space running out at the high levels and almost all likely need to support v4 anyhow. I think it’s been long enough to be honest that ipv6 was a spectacular failure by complicating an already complicated system into something no one actually asked for. No human said “hey, networking sucks. Please make it much harder at my level!!”.
- accrual 2mo agoI also know of a company who does this. The reason in their case is they act as a network concentrator, bridging hundreds of client IP spaces, so this helps them avoid conflicts with their own space without having to NAT constantly. There is still a lot of NAT for the more common ranges.
- inigyou 2mo agoIf they converted to IPv6, they could easily have a globally unique address space. Real globally unique, not probabilistic.
- oasisbob 2mo agoThe fact that the network concentrator co uses DoD v4 address space to avoid conflicts implies that their clients are bringing v4 addresses, so IPv6 is utterly irrelevant in this situation.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- inigyou 2mo agoIt's common for a network to address its own devices with v6 while carrying v4 traffic either natively or by tunneling. Saves v4 space.
- anonymars 2mo agoInteresting -- seems like the side effect would be to basically prevent use by the DoD but not really anyone else. Bonus points if they sell a "government" version for higher cost
- makr17 2mo agoI used to work somewhere that did that. Several of us in Eng pointed out that it was likely impossible to sell anything to DoD personnel since the reply would route internally. But I don't know if it was _fixed_, was still an issue when I left.
- ec109685 2mo agoYeah I wanted to do that at previous company. Got talked out of it, but it's nice have all those ips available.
- Arrowmaster 2mo agoI don't remember which but one of the major US cellular networks was using the DoDs 7.0.0.0/8 internally. It was never an issue since the DoD kept that /8 offline but the IPs would show up in traceroutes. I had to tell many people to ignore it.
- walrus01 2mo ago> Note to self: never buy a Korean security product. The Canadian Navy very recently made a major choice and agreed with you https://www.google.com/search?client=firefox-b-d&q=hanwha+ocean+submarines+canada https://www.google.com/search?client=firefox-b-d&q=hanwha+oc...
- dev_l1x_be 2mo agoOr Korean IoT products. The ones I was working on had insane approach to security.
- salvador-odil 2mo agocan you elaborate on that approach?
- kingleopold 2mo agoNote to self: never buy any Korean hardware or software product. /S
- walrus01 2mo agoNote to self, never buy any hardware product, move to a yurt in the woods, start an alpaca ranch, write a manifesto
- zrobotics 2mo agoOldie, bur relevant. Tech enthusiasts: My entire house is smart. Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don’t recognize
- lardosaurusrex 2mo agojust buy stuff you can put your own firmware/os on because it's either just the worst security in the world (aka anything not from china) or, well... china. and while i currently don't hate china as much as i do US rn (because canadian; sorry) i can also say -- due to being an aforementioned leaflandian -- that due to very personal experience i have zero faith in anything from china that has the ability to connect to any type of network :') And so yeah at this point if I can't at the very least get a whatever-wrt firmware (preferably a proper linux distro nowadays; not to say the *-wrt firmwares aren't a real OS but, y'know) on the device i just avoid them entirely since, well... it's all i can do at this point because even if there were baked in hardware-based backdoors i as an individual can't do much more than that.
- prox 2mo agoThat sounds horrible. I got an old PI4, would it make for a decent router, if at all possible?
- myself248 2mo agoIt's not quite ideal hardware due to only having a single NIC, but you can slap a USB NIC on it and make it work, if that's what's handy. Old thin clients are typically in the same hardware class, and probably cheaper by the time you add the exploding MSRP of a Pi, and a PSU, and a case and heatsink, and maybe some storage that doesn't suck ass. But if you already own the Pi, yeah, go for it.
- RajT88 2mo agoAs if domestic products aren't a hot mess of security issues and sloppy engineering. Lol
- KPGv2 2mo ago> Department of War n.b., it's the Department of Defense, just like the Kennedy Center doesn't have Trump's name attached, and the large body of water by Texas is the Gulf of Mexico.
- BLKNSLVR 2mo ago100% correct DoW is a nickname if anything. I'm surprised Hegseth hasn't requested 'Secretary' get nick-named to something more masculine sounding.
- edwinjm 2mo agoThe DoWD owns such a large chunk of the IP space, it can very easily be a coincidence