rysiek ✅ is a user on mastodon.social. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.
rysiek ✅ @rysiek

Holy cow:
bgpmon.net/popular-destination

"Early this morning (UTC) our systems detected a suspicious event where many prefixes for high profile destinations were being announced by an unused Russian Autonomous System.

Starting at 04:43 (UTC) 80 prefixes normally announced by organizations such Google, Apple, Facebook, Microsoft, Twitch, NTT Communications and Riot Games were now detected in the global BGP routing tables with an Origin AS of 39523 (DV-LINK-AS), out of Russia. "

· Web · 29 · 14

@rysiek shit, this really looks like a MitM attempt...

@Wolf480pl between this and Russia preparing "they're own Internet", the whole net thing is royally fscked.

@rysiek - Was having a discussion just last week with a fellow tester on hijacking BGP and how it often CAN'T be scoped in a test (as it can easily affect multiple entities outside of a targeted client). Annnnd, this pops up.

A lot of the core protocols of the net aren't secure by design. They're designed to be resilient, but not secure.

@tinker they're also designed in a time and context where security was not a priority.

That's what happens when security assumptions change.

( ͡° ͜ʖ ͡°)

@rysiek Crikey! That sounds like the opening to a William Gibson novel. I expect to come across the phrase "Operation Screaming Fist" any time now.

@kevinbeynon I never got into reading Gibson. Should I?

@rysiek Definitely. As well as his Neuromancer-related work, I'd also highly recommend his later trilogies. Pattern Recognition and it's two following books are excellent.