Shared posts

21 Nov 07:42

How Somebody Forced the World's Internet Traffic Through Belarus and Iceland

by Arik Hesseldahl

facebook_networkThis is a deeply technical, but potentially very troubling story. Imagine one day you’re using the Internet the same way you do every day. Reading the news, shopping, sending email, checking your bank and credit card balances. Maybe even doing some work for your employer.

Typically, but not always, the bits being sent from your computer, tablet or phone will flow from where you are to where they need to be via the most direct route available.

But what if they didn’t? What if someone slipped in between you and the various servers you’re connecting with and diverted your traffic elsewhere, funneling it through a choke-point of their choosing, so they could capture, copy and analyze it? Your data takes some extra — and imperceptible — milliseconds to get where it’s going and ultimately everything you’re doing online works just fine. But your traffic has been hijacked by parties unknown and you’re none the wiser that it has happened.

In network security circles, this is what’s known as a Man-In-The-Middle or MITM attack. And for years it has been understood to be possible in theory, but never seen in practice. That changed earlier this year when someone — it’s unclear who — diverted Internet traffic from some 150 cities around the world through networks in Belarus and Iceland.

The troubling disclosure came yesterday from the research company Renesys. The firm specializes in tracking the operational health of global Internet infrastructure. When Internet traffic goes down in one country or another, whether because of a natural disaster or political unrest, Renesys is usually among the first to see it.

The attack — and Renesys maintains that it was an attack — targeted large Internet carriers in every major city in the U.S. and numerous major cities in Europe and around the world. (See their map here.)

The first incident took place during most of the month of February, when Internet traffic was silently redirected through an Internet service provider called GlobalOneBel, based in the Belarusian capital, Minsk. The targets of these attacks included financial institutions, government agencies and network service providers.

Renesys tracked the attacks as they happened. Here’s how its CTO Jim Cowie described one:

Here’s an example of a trace from Guadalajara, Mexico, to Washington, D.C., that goes through Moscow and Minsk. Mexican provider Alestra hands it to PCCW for transit in Laredo, Texas. PCCW takes it to the Washington, D.C., metro area, where they would normally hand it to Qwest/Centurylink for delivery.

Instead, however, PCCW gives it to Level3 (previously Global Crossing), who is advertising a false Belarus route, having heard it from Russia’s TransTelecom, who heard it from their customer, Belarus Telecom. Level3 carries the traffic to London, where it delivers it to Transtelecom, who takes it to Moscow and on to Belarus. Beltelecom has a chance to examine the traffic, and then sends it back out on the “clean path” through Russian provider ReTN. ReTN delivers it to Frankfurt and hands it to NTT, who takes it to New York. Finally, NTT hands it off to Qwest/Centurylink in Washington D.C., and the traffic is delivered.

So if you were in Mexico, sending an email to someone in Washington, D.C., it got diverted in Virginia and sent to London, Moscow and Minsk before taking a return trip through Frankfurt, New York and ultimately to its intended destination. Renesys thinks the chances are pretty good it was read along the way.

It’s helpful at this point to understand something called Border Gateway Protocol. It’s one of those things that make the Internet work, but is a little hard to get your head around if you don’t live with it day by day.

Basically BGP is a method by which Internet service providers tell the world what other networks they’re connected to and how they themselves can be reached. Because the Internet is built for resiliency and reliability, there are usually multiple ways for traffic to get from one place to another, and those routes are published in something called the Global Routing Table.

Imagine the Internet is a long series of intersecting lines of people going in multiple directions, and you can only pass handwritten messages to three or four different people standing next to you, and each of them are in lines headed in different directions. BGP is sort of a way of announcing to the world where you’re located in that chain, which people you can reach, and which directions they’re heading.

But imagine what would happen if one of those three people you can reach lies to you about who they can reach. With no reason to question that information, you would probably pass a message on to them, unaware that it would be handed off to additional actors that that might just peek at it before they send it on its way.

That’s essentially what Renesys says has been happening here. These attacks occurred throughout February and into March. Then they stopped for awhile.

The attacks resumed in May, and almost right away the choke-point switched from Belarus to Iceland. For about five minutes — literally — traffic was routed through was an Icelandic ISP called Nyherji hf.

Then they stopped again — until July. This time, the venue was again in Iceland. Beginning on July 31, traffic from a large VOIP company — Renesys wouldn’t name it — was diverted through an Internet service provider called Opin Kerfi that oddly announced access to 597 different IP blocks versus its usual three.

The result caused routine Internet traffic to take some routes that were so indirect as to be absurd. For a brief time on Aug. 2, data traffic between two providers in Denver didn’t just flow across town as it normally would. Instead the bits went to Iceland first, with stops in London, Montreal, New York, Dallas and Kansas City along the way.

So who did it? It’s hard to say. I talked to Cowie last night and he didn’t seem to have much of an idea. “We can track whose infrastructure was used to carry out these attacks because they leave their footprints in the global routing table,” he said. “Tracing it back to who engineered this attack is another thing entirely.”

The targets of the attack have been notified. The motivation was likely a financial one.

This sort of attack should not happen, Renesys contends. But when it does, it leaves a permanent, indelible mark that is visible to those who know how to look for it. While sometimes these bad traffic routes are advertised in error and by accident — someone mistypes a digit in configuring networking equipment — when they are sustained and as wide-ranging as this, something bad is likely taking place, Cowie says, something that can and should be stopped.

“If you’re watching, this sort of attack is instantly visible to those people who monitor BGP,” Cowie said. “But no one is looking.”

While it’s a fair bet that some kind of crime was at least attempted if not committed in carrying out these attacks, the legal jurisdictions will be kind of tricky to sort out. The attackers could be anywhere in the world and might have used ISPs in Belarus and Iceland without their knowledge. With possible victims in a variety of countries, prosecution of a crime — if one was indeed committed — would likely be difficult.

But there is a way to stop this from happening again. Cowie said the really big Internet service providers — the ones who resell their traffic to smaller regional and national providers — should be watching for when smaller players advertise false routes. “If big ISPs monitored their customers and filtered their traffic when they advertise these false routes, this would be over. This kind of attack could not occur. … In each one of these attacks there was someone, usually a very large ISP, who failed to filter.”

“Our motivation is to shed some light on this,” he said. “We really want people to start raising their game a bit and start watching out for this.”

12 Nov 15:39

Take Bill Gates's Favourite Course For Free

If you ask Bill Gates about his most favourite course that he ever studied, it's something called Big History. It originated in a university in Sydney, Australia, and is divided into 8 separate modules which "help to blur the boundaries between history and science".

Gates liked the course so much that he's now funding it so that anyone can take it for free, online. The 8 modules should each take around an hour to complete, and you can study entirely in your own time and at your own pace.


http://www.techsupportalert.com/content/take-bill-gatess-favourite-course-free.htm
22 Oct 14:14

Help Save Your Eyesight With This Clever Windows Program

If you're at at your PC or laptop right now, you're probably looking at a screen that's set quite bright. Probably with a blue tinge, and a colour temperature of around 6000K (if you're into such things). Such settings are great during the day, as they match natural sunny daylight. But as the day fades to dusk, and the colour of the natural light fades to a more yellow hue, your PC screen stays the same. Which can irritate your eyes, hinder your ability to relax at night, and generally affect your mood.

Which is where a really neat piece of software comes in. It's called F.Lux and, in a nutshell, it changes the colour of your PC screen automatically in line with the time of day. As I write this, for example, it's 8pm where I live, and dark outside, so my screen is rather yellow and reminiscent of incandescent lighting. Tomorrow morning it'll be back to sunlight shades again.

I discovered this program a couple of days ago when a friend of mine posted on Twitter that this software had, literally, saved his eyesight. That's a recommendation if ever I heard one. - Robert Schifreen, Hot Finds Editor.


http://www.techsupportalert.com/content/help-save-your-eyesight-clever-windows-program.htm
27 Aug 11:03

Websites hosten bij Google Drive

by Willem Karssenberg
Ik weet dat het al een tijdje kan, maar in deze screencast wil ik toch even laten zien hoe makkelijk het is en wat de mogelijkheden zijn van het tonen van HTML bestanden via Google Drive.

De instructie die Google zelf geeft betreft het tonen van één HTML bestand, maar ik laat zien dat je een hele map met alle bestanden daarin kunt aanbieden.

Je begint met het maken van een nieuwe map in Google Drive waarbij je bij: delen kiest voor: Openbaar op het web. Iedereen kan daarmee de bestanden in die map zien. Zorg ervoor dat het startbestand de naam index.html heeft en deze zal automatisch getoond worden wanneer de url van de map gebruikt wordt. Vervolgens kun je ook submappen aanmaken met daarin plaatjes, javascript- en stylesheetbestanden.

Maar het mooiste komt nog!

De url die Google Drive voor je aanmaakt is namelijk onmogelijk lang en niet te onthouden, laat staan te communiceren. Gelukkig biedt Gdriv.es uitkomst! Kopieer de folder ID uit de adresbalk bij Google Drive en geef die door aan Gdrives. Verzin een alias voor je website en Gdrives maakt een mooie url voor je.
Zo heb ik de dobbelstenen routine uit de screencast als url gegeven: http://gdriv.es/dobbelen



Bekijk de screencast bij Youtube.
14 Jun 13:59

Seagate Introduces NAS HDD: WD Red Gets a Competitor

by Ganesh T S

Consumers looking to fill their SOHO / consumer NAS units with hard drives haven't had too many choices. Western Digital recognized early on that the dwindling HDD sales in the PC arena had to be made up for in the fast growing NAS segment. Towards this, they introduced the WD Red series (in 1TB, 2TB and 3TB capacities) last July. Today, Seagate is responding with their aptly named NAS HDD lineup. Just like the WD Red, these HDDs are targeted towards 1- to 5-bay NAS units. WD terms their firmware secret sauce as NASWare and Seagate's is NASWorks. NASWorks supports customized error recovery controls (TLER in other words), power management and vibration tolerance.

TLER helps to ensure that drives don't get dropped from the NAS and send the array into a rebuild phase. Seagate also claims that the firmware has an optimal balance for sequential and random performance.

Seagate does have a lead over WD in the capacity department. While the WD Red currently tops out at 3TB, Seagate's NAS HDD comes in 2 TB, 3 TB and 4 TB flavors. Seagate hasn't provided any information on the number of platters or spindle speed. Power consumption numbers are available, though. Average operating power is 4.3W for the 2TB  model and 4.8W for the 3 TB and 4 TB ones.

Pricing is set at $126, $168 and $229 for the 2TB, 3TB and 4TB models respectively.

Update: Seagate has released an extensive product manual here. The 3TB and 4TB models have four platters each, while the 2TB model has two. The drives have a 3-year warranty.