Comment by grommz
4 days ago
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
4 days ago
The US Department of War IP adresses baked into the firmware is the bigger story here. Note to self: never buy a Korean security product.
I do know of at least one company who has black-holed the entire DoD ip space and are using it for internal space, which is why I gave a speculation warning... it's really strange regardless.
I recently troubleshot an installation for someone where at some point in the past they'd picked 1.1.1.0/24 as their address range because "all that 192 stuff was silly and too complicated".
You know, I'm not sure I can explain how I feel about this properly without waving the shotgun around.
I had a gig for a contractor of some banks once. One of the banks was using 5.0.0.0/8 internally. I asked the guy if it doesn't lead to issues. All the time, he said. When they first came in, they just assigned each bank 1.0.0.0/8, 2.0.0.0/8, and so on. Number ten feels really lucky, he said.
2 replies →
LOL, they should have just used a 10.x space instead if they wanted slightly simpler numbers.
On the shotgun, or adjacent, I do tend to prefer ammo classes for my nets... 10.22.x.y, where x may be 1, 38, 45, etc. Allows for site to site vpn with friends/family a bit easier to remember.
1 reply →
Didn't AT&T do that and Cloudflare made them change it when they aquired that space?
7 replies →
Sounds like someones on the path to sovereign citizenship. I can't wait for our cyber-sovereign citizenships who deny various IP ranges coming from the government's domain naming system.
Yet another thing ipv6 solves. Yeah you can do the officially supported fdXX:XXXX:XXXX:... but you can also just pick something like 1::1 and it's unlikely to conflict with the current global range.
If you're gonna do that, though, it's better if you use fd00:... or one of the other assigned ranges so it's still in the standard range. OSes use this as a heuristic for source address selection.
65 replies →
Interesting -- seems like the side effect would be to basically prevent use by the DoD but not really anyone else. Bonus points if they sell a "government" version for higher cost
I also know of a company who does this. The reason in their case is they act as a network concentrator, bridging hundreds of client IP spaces, so this helps them avoid conflicts with their own space without having to NAT constantly. There is still a lot of NAT for the more common ranges.
If they converted to IPv6, they could easily have a globally unique address space. Real globally unique, not probabilistic.
4 replies →
This will trip up most SOC workflows in funny ways, and I like it.
IPs having a global distinction between public/private is a convention, but local routing can widely differ.
Same with the "China Cyberattacks" - the guys sitting on top of my outgoing fiber can simulate any IP address they want to me.
It’s only a convention in the sense that the IANA is a convention: https://www.iana.org/assignments/iana-ipv4-special-registry/...
192.0.0.0/24, 10/8, 172.16/12, and various other subslices of 192/8 are reserved for local use and are not publicly routable.
Yeah I wanted to do that at previous company. Got talked out of it, but it's nice have all those ips available.
I don't remember which but one of the major US cellular networks was using the DoDs 7.0.0.0/8 internally. It was never an issue since the DoD kept that /8 offline but the IPs would show up in traceroutes. I had to tell many people to ignore it.
I used to work somewhere that did that. Several of us in Eng pointed out that it was likely impossible to sell anything to DoD personnel since the reply would route internally. But I don't know if it was _fixed_, was still an issue when I left.
there's a couple subnets I (ab)use in the DOD IP space for my home network knowing they'd never put them on the open internet. it's also fun to throw logging for a loop if someone digs.
22.0.0.0/8 - it's basically free real estate!
the entirety of 10/8 and 172.16/12 and 192.168/16 wasn't large enough for your house?
4 replies →
I have seen ISP doing CGNAT on DOD IP space.
The CGNAT space (100.64.0.0/10) is also free real estate for container virtual/overlay networks when you don't want to (or can't, thanks to IT) use the RFC-1918 subnets.
I also do this, except 7.0.0.0/8 instead. Its great for not conflicting with hotel wifi dhcp.
> Note to self: never buy a Korean security product.
The Canadian Navy very recently made a major choice and agreed with you
https://www.google.com/search?client=firefox-b-d&q=hanwha+oc...
The DoWD owns such a large chunk of the IP space, it can very easily be a coincidence
That they used a public IP as an internal IP? That’s simply a mistake.
It's how Internet was supposed to work. NAT was a forced mistake, as well as the whole concept of "public" and "internal" address spaces.
Or Korean IoT products. The ones I was working on had insane approach to security.
can you elaborate on that approach?
As if domestic products aren't a hot mess of security issues and sloppy engineering. Lol
> Department of War
n.b., it's the Department of Defense, just like the Kennedy Center doesn't have Trump's name attached, and the large body of water by Texas is the Gulf of Mexico.
100% correct
DoW is a nickname if anything. I'm surprised Hegseth hasn't requested 'Secretary' get nick-named to something more masculine sounding.
just buy stuff you can put your own firmware/os on because it's either just the worst security in the world (aka anything not from china) or, well... china.
and while i currently don't hate china as much as i do US rn (because canadian; sorry) i can also say -- due to being an aforementioned leaflandian -- that due to very personal experience i have zero faith in anything from china that has the ability to connect to any type of network :')
And so yeah at this point if I can't at the very least get a whatever-wrt firmware (preferably a proper linux distro nowadays; not to say the *-wrt firmwares aren't a real OS but, y'know) on the device i just avoid them entirely since, well... it's all i can do at this point because even if there were baked in hardware-based backdoors i as an individual can't do much more than that.
That sounds horrible. I got an old PI4, would it make for a decent router, if at all possible?
It's not quite ideal hardware due to only having a single NIC, but you can slap a USB NIC on it and make it work, if that's what's handy.
Old thin clients are typically in the same hardware class, and probably cheaper by the time you add the exploding MSRP of a Pi, and a PSU, and a case and heatsink, and maybe some storage that doesn't suck ass. But if you already own the Pi, yeah, go for it.
Note to self: never buy any Korean hardware or software product.
/S
Note to self, never buy any hardware product, move to a yurt in the woods, start an alpaca ranch, write a manifesto
Oldie, bur relevant.
Tech enthusiasts: My entire house is smart.
Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don’t recognize