Re: FCC proposes $10 Million fine for spoofed robocalls

2019-12-19 Thread Christopher Morrow
How is it envisioned that this will work? I mean, I'm all for less spam calling... and ideally there would be some form of 'source address verification' on the PSTN/phone network... but in today's world that really just doesn't exist and the motivations to suppress fake sources are 'just as good' a

Re: FCC proposes $10 Million fine for spoofed robocalls

2019-12-19 Thread Christopher Morrow
> Plus if it didn't work well/too cumbersome/etc with email, it probably > won't be any better with voice. We have lots of experience with what > doesn't work for email. I sort of figured that the shaken/stir model that ( i happened to propose in their first meeting) of: "get the originator (han

Re: Google

2019-12-19 Thread Christopher Morrow
Didn't you all send a similar message last week? with zero details about destinations being 'attacaked'? and without any follow-up information when requested multiple times? On Thu, Dec 19, 2019 at 7:35 PM ahmed.dala...@hrins.net wrote: > > Sent. Thank you Damian! > > On Dec 20, 2019, at 1:21 AM

Re: FCC ... [REALLY new laws US passed today (19/12/2019)]

2019-12-19 Thread Christopher Morrow
On Thu, Dec 19, 2019 at 6:10 PM Fletcher Kittredge wrote: > > > Both TRACED and TRUE were passed by both houses today and are expected to be > signed by the current POTUS because of the bipartisan support. > > The Telephone Robocall Abuse Criminal Enforcement and Deterrence (TRACED) > Act (

Re: FCC proposes $10 Million fine for spoofed robocalls

2019-12-20 Thread Christopher Morrow
On Fri, Dec 20, 2019 at 1:40 PM Michael Thomas wrote: > > > On 12/19/19 9:14 PM, Christopher Morrow wrote: > >> Plus if it didn't work well/too cumbersome/etc with email, it probably > >> won't be any better with voice. We have lots of experience with what &g

Re: Thursday: Internet outage eastern Europe Iran and Turkey

2019-12-21 Thread Christopher Morrow
outages@ is that list I think? I do think the overall conversation about nation states disabling internet (which is not likely the case with Sean's original post?) is nanog-worthy. On Sat, Dec 21, 2019 at 7:41 PM Ross Tajvar wrote: > > I'm interested in these events. It might be worth making a se

Re: Thursday: Internet outage eastern Europe Iran and Turkey

2019-12-23 Thread Christopher Morrow
On Sat, Dec 21, 2019 at 11:53 PM Scott Weeks wrote: > > > > --- morrowc.li...@gmail.com wrote: > From: Christopher Morrow > > I do think the overall conversation about nation states > disabling internet (which is not likely the case with > Sean's

Holiday route leak

2019-12-27 Thread Christopher Morrow
howdy! If there are AS46844 folk listening around their eggnog ... it'd be nice if you would stop leaking prefixes: https://imgur.com/a/Js0YvP2 this from the current view at: https://bgp.he.net/AS15169#_graph6 I believe at least: 2620:0:1000::/40 was leaking around your noction filters. It

Re: Requesting /24 from ARIN

2019-12-28 Thread Christopher Morrow
I'm going to bet that: 1) the docs at ARIN talk about all you need to do to get this mission accomplished 2) questions to the hostmaster/registration-services-desk will also get all of these questions answered 3) taking up 10k+ people's time on what is solved with the above 2 things isn't rea

Re: Iran cuts 95% of Internet traffic

2019-12-29 Thread Christopher Morrow
On Sun, Dec 29, 2019 at 6:02 PM Keith Medcalf wrote: > > > Why would anyone with anything important to say use somethingmail.com > > Somethingmail.com is not e-mail. It is a Giggle Gaggle Google thing. huh what? ;; ANSWER SECTION: somethingmail.com. 86400 IN MX 10 mail.somethingmail.com. ;; AUT

Re: 5G roadblock: labor

2019-12-29 Thread Christopher Morrow
On Sun, Dec 29, 2019 at 5:50 PM Michael Thomas wrote: > > An interesting article on the road to 5G that they need to about double > the size of the workforce to roll it out. I expect that this affects > some of you directly. Huh, you mean since you have to deploy a tower/unit every ~100 meters to

Re: 5G roadblock: labor

2019-12-30 Thread Christopher Morrow
On Mon, Dec 30, 2019 at 4:11 PM Brian J. Murrell wrote: > > On Mon, 2019-12-30 at 09:50 -0500, Shane Ronan wrote: > > > > Also, keep in mind that 10 years ago, you didn't know you would want > > or > > need 25mbits to your phone, > > Who needs 25mbits to their phone? > this is the wrong argument

Re: 5G roadblock: labor

2019-12-30 Thread Christopher Morrow
On Mon, Dec 30, 2019 at 6:09 PM Michael Thomas wrote: > > > On 12/30/19 2:46 PM, Brandon Martin wrote: > > On 12/30/19 5:42 PM, Michael Thomas wrote: > >> Oh, I didn't know that. Seems like it's a relatively new thing. Seems > >> like they went to a lot of trouble to essentially do what voip does.

Re: 5G roadblock: labor

2019-12-30 Thread Christopher Morrow
Oh good :) someone coaxed cameron out of the holiday keg :) On Mon, Dec 30, 2019 at 6:32 PM Ca By wrote: > > > > On Mon, Dec 30, 2019 at 2:41 PM Christopher Morrow > wrote: >> >> On Mon, Dec 30, 2019 at 4:11 PM Brian J. Murrell >> wrote: >> > >

Re: 5G roadblock: labor

2020-01-03 Thread Christopher Morrow
On Fri, Jan 3, 2020 at 4:37 AM Mark Tinka wrote: > > > > On 3/Jan/20 11:25, Saku Ytti wrote: > > > > > Yes markets differ, and this is not 4G/5G question, only thing 5G does > > is help markets which struggle to provide sufficient service in dense > > metro installations. > > Which brings us full

Re: 5G roadblock: labor

2020-01-03 Thread Christopher Morrow
On Fri, Jan 3, 2020 at 9:28 AM Mike Hammett wrote: > > Throughput is (mostly) a function of channel size, modulation, and signal to > noise ratio. > > Coverage is (mostly) a function of frequency, radiated power, obstacles, and > signal to noise ratio. > > > Other than in the bowels of large bui

Re: 5G roadblock: labor

2020-01-03 Thread Christopher Morrow
On Fri, Jan 3, 2020 at 2:21 PM Mike Hammett wrote: > > Right. I didn't want to spend too much of my time delving into any and all > situations where it'll vary. > ok, fair enough :) > I wonder how much the sub 1 GHz penetrates the buildings anyway if the > transmitter is at the street. > > > 5

Re: 5G roadblock: labor

2020-01-03 Thread Christopher Morrow
On Sat, Jan 4, 2020 at 12:26 AM Mark Tinka wrote: > > > > On 3/Jan/20 21:49, Christopher Morrow wrote: > > > the local folk have been pimping the idea that: "hey, just run a > > 4g/lte/g5 cell service inside your building/business, backhaul over > > cable-mo

Re: Cost Recovery Surcharge & Va Personal Property Tax Recovery for IP Transit

2020-01-06 Thread Christopher Morrow
On Mon, Jan 6, 2020 at 10:30 AM William Herrin wrote: > If it's not written in to your contract, it's a breach of contract. Either > way it's a deceitfully imposed surcharge, not a state tax. Virginia does not > tax the sale of services like transit and colo. More, the only personal > property

Re: Traffic forecasts

2016-04-18 Thread Christopher Morrow
doesn't dyn/renesys provide this as well? On Thu, Apr 14, 2016 at 9:01 AM, Tum Eh wrote: > Dear All, > > Do you use any source other than Telegeography in order to get country's > Internet bandwidth infos, or continent to continent capacities etc. > > BR, > Tum >

Re: [Non-DoD Source] Re: G root not responding on UDP?

2016-04-18 Thread Christopher Morrow
On Fri, Apr 15, 2016 at 5:23 PM, Cassell, James D CIV DISA IE (US) < james.d.cassell4@mail.mil> wrote: > Regarding yesterday's G-root outage: > > Like many outages, this one resulted from a series of unfortunate events. > These unfortunate events were operational errors; steps have been taken

Re: sub $500-750 CPE firewall for voip-centric application

2016-05-05 Thread Christopher Morrow
On Thu, May 5, 2016 at 8:27 PM, Jared Mauch wrote: > > > On May 5, 2016, at 4:52 PM, Javier J wrote: > > > > I'm a fan of the EdgeRouterLite3 > > > > > > I don't manage many small businesses networks anymore because we now do > > only 100% cloud and remote work but I started deploying them to al

Re: CALEA

2016-05-10 Thread Christopher Morrow
On Tue, May 10, 2016 at 4:00 PM, Josh Reynolds wrote: > This is a large list that includes many Tier 1 network operators, > government agencies, and Fortune 500 network operators > ​no one gets calea requests because prism gets all requests?​

Re: Comcast DNS Contact

2016-05-16 Thread Christopher Morrow
On Mon, May 16, 2016 at 12:35 PM, wrote: > > Can one of the Comcast DNS guru's contact me reference an issue with a .gov resolution? > > Robert ​out of curiosity, is the .gov problem related to dnssec perhaps?​

Re: IPv6 Residential Deployment Survey

2016-05-23 Thread Christopher Morrow
On Mon, May 23, 2016 at 9:34 AM, Bjørn Mork wrote: > Got as far as the second page, where I was met by the question > > "What technology is used for the customer link ? >Choose one of the following answers " > > Come on... One technology per ISP? In what world is that? > > ​isn't this one

Re: IPv6 Residential Deployment Survey

2016-05-23 Thread Christopher Morrow
On Mon, May 23, 2016 at 10:14 AM, Christopher Morrow < morrowc.li...@gmail.com> wrote: > > > On Mon, May 23, 2016 at 9:34 AM, Bjørn Mork wrote: > >> Got as far as the second page, where I was met by the question >> >> "What technology is used for th

Re: IPv6 Residential Deployment Survey

2016-05-23 Thread Christopher Morrow
rvey … > > ​'don't offer' from the perspective of a client is really: "Did not get" i filled in the survey as a client of the ISP.​ > Saludos, > Jordi > > > -Mensaje original- > De: NANOG en nombre de Christopher Morrow < > morrowc.l

Re: CALEA

2016-05-31 Thread Christopher Morrow
"Encryption The number of state wiretaps in which encryption was encountered decreased from 41 in 2013 to 22 in 2014. In two of these wiretaps, officials were unable to decipher the plain text of the messages. Three federal wiretaps were reported as being encrypted in 2014, of which two could not

Re: IPv6 is better than ipv4

2016-06-02 Thread Christopher Morrow
On Thu, Jun 2, 2016 at 10:47 AM, Ca By wrote: > > https://blogs.akamai.com/2016/06/preparing-for-ipv6-only-mobile-networks-why-and-how.html > > Wherein akamai explains a detailed study showing ipv6 is "well > over 10%" faster than ipv4 on mobile, and they reference corroborating > studies from Li

Re: IPv6 is better than ipv4

2016-06-02 Thread Christopher Morrow
On Thu, Jun 2, 2016 at 12:23 PM, Daniel Corbe wrote: > Maybe we should let people believe that IPv6 is faster than IPv4 even if > objectively that isn’t true. Perhaps that will help speed along the > adoption process. ​do we REALLY think it's still just /marketing problem/ that keeps v6 deploy

Re: IPv6 is better than ipv4

2016-06-02 Thread Christopher Morrow
On Thu, Jun 2, 2016 at 12:55 PM, Ca By wrote: > > > On Thursday, June 2, 2016, Christopher Morrow > wrote: > >> >> On Thu, Jun 2, 2016 at 12:23 PM, Daniel Corbe >> wrote: >> >>> Maybe we should let people believe that IPv6 is faster than IPv4 e

Re: IPv6 is better than ipv4

2016-06-02 Thread Christopher Morrow
to matter... I mean, if you haven't gotten the message now: http://i.imgur.com/8vZOU0T.gif > > > > - > Mike Hammett > Intelligent Computing Solutions > http://www.ics-il.com > > Midwest-IX > http://www.midwest-ix.com > > - Original Message ---

Re: IPv6 is better than ipv4

2016-06-02 Thread Christopher Morrow
On Thu, Jun 2, 2016 at 3:37 PM, Jeff McAdams wrote: > On Thu, June 2, 2016 13:31, Christopher Morrow wrote: > > On Thu, Jun 2, 2016 at 1:17 PM, Mike Hammett wrote: > > >> Yes. > >> > > ​REALLY??? I mean REALLY? people that operate networks haven't haven&

Re: Netflix VPN detection - actual engineer needed

2016-06-05 Thread Christopher Morrow
On Sun, Jun 5, 2016 at 6:48 PM, Damian Menscher wrote: > I suggest you focus your efforts on bringing native IPv6 to the masses, not > criticizing service providers for defending themselves against abuse, just > because that abuse happens to be over a network (HE tunnel broker; Tor; > etc) you su

Re: Netflix VPN detection - actual engineer needed

2016-06-05 Thread Christopher Morrow
On Sun, Jun 5, 2016 at 8:15 PM, Laszlo Hanyecz wrote: > For P2P stuff it's a way to get around NAT - you can get inbound torrent > connections or host a shooting game match on your desktop behind the NAT > router. ​but to be fair, stun/ice/upnp has made all that work for 'years'...​

Re: Netflix VPN detection - actual engineer needed

2016-06-06 Thread Christopher Morrow
On Mon, Jun 6, 2016 at 3:30 PM, Aled Morris wrote: > Maybe HE's IPv6 tunnel packets could be flagged with a destination option > (extension header field) that records the end-user's IPv4 tunnel endpoint > so geolocation could be done in the "old fashioned" way on that address. > > Similar to the

Re: IPv6 is better than ipv4

2016-06-07 Thread Christopher Morrow
On Tue, Jun 7, 2016 at 7:51 AM, Mikael Abrahamsson wrote: > Slashdot, Github etc, still no IPv6 though. ​oddly github has ipv6 being announced from their ASN: AS​36459 | 2620:112:3000::/44 | GITHUB - GitHub, Inc., US

Re: Equinix IX Port Moves

2016-06-10 Thread Christopher Morrow
On Fri, Jun 10, 2016 at 10:00 AM, Mike Hammett wrote: > Who has moved an Equinix IX port? We're told that it's a full > cancellation, re-order, re IPs, re-peering, etc. > > Can anyone lend any input either way on that? > > ​there are 2 meanings (at least) to 'move', did you mean: 1) move port f

Re: intra-AS messaging for route leak prevention

2016-06-10 Thread Christopher Morrow
On Tue, Jun 7, 2016 at 2:35 AM, Mark Tinka wrote: > One thing we do to reduce opportunistically hazardous vectors is to not > learn customer paths via peers. > ​so I can't be a customer of you and a network you peer with? (I'm sure I got your meaning wrong)​

Re: intra-AS messaging for route leak prevention

2016-06-10 Thread Christopher Morrow
On Fri, Jun 10, 2016 at 1:05 PM, Mark Tinka wrote: > > > On 10/Jun/16 16:47, Christopher Morrow wrote: > > > > ​so I can't be a customer of you and a network you peer with? > > > You can, but we won't learn your paths via the peering session we would &

Re: Equinix IX Port Moves

2016-06-10 Thread Christopher Morrow
t; > Midwest-IX > http://www.midwest-ix.com > > - Original Message - > > From: "Christopher Morrow" > To: "Mike Hammett" > Cc: "NANOG" > Sent: Friday, June 10, 2016 9:46:17 AM > Subject: Re: Equinix IX Port Moves > > > &

Re: intra-AS messaging for route leak prevention

2016-06-10 Thread Christopher Morrow
On Fri, Jun 10, 2016 at 1:17 PM, Mark Tinka wrote: > > > On 10/Jun/16 19:08, Christopher Morrow wrote: > > > > ​oh, so I didn't misunderstand.. that makes 'backup isp' less useful, no?​ > > > > With regard to reaching our network, not true. You wo

Re: Enough about Netflix banning HE tunnels [really: IPv6 adoption]

2016-06-13 Thread Christopher Morrow
On Fri, Jun 10, 2016 at 4:21 PM, wrote: > On Fri, 10 Jun 2016 20:12:43 -, "STARNES, CURTIS" said: > > and the Chromebook content filtering is not IPv6 compatible either > > So what are you using for content filtering? A quick google search > indicates that there do exist filtering solutions t

Re: Timeouts Loading Major Websites

2016-06-21 Thread Christopher Morrow
"the internet is on fire" not as helpful a troublereport as one might want. please provide at least (so everyone else can verify/help/troubleshoot): 1) from location X 2) site Y with protocol Z (which resolves to a.b.c.d currently) 3) traceroute to siteY (address a.b.c.d) otherwise... "sur

Re: IPv4 Legacy assignment frustration

2016-06-21 Thread Christopher Morrow
how is this a problem with the RIR ? On Tue, Jun 21, 2016 at 11:01 PM, Suresh Ramasubramanian < ops.li...@gmail.com> wrote: > There is absolutely no budgeting for idiots. Beyond a long hard process > that is helped by internal escalations from affected people on a corporate > network - ideally

Re: Quick question regarding: Problematic IPv6 Multicast traffic within an IX.

2016-06-25 Thread Christopher Morrow
On Sat, Jun 25, 2016 at 6:29 AM, Bruce Simpson wrote: > On 24/06/16 18:31, joel jaeggli wrote: > >> you can filter multicast destination addresses by acl. >> >> NDP you kinda need since it replaces ARP >> >> RA's you can and should filter (icmp6 type 134) >> > > Data point, although the chances o

Re: IPv6 deployment excuses

2016-07-04 Thread Christopher Morrow
On Mon, Jul 4, 2016 at 12:28 PM, Matt Hoppes < mattli...@rivervalleyinternet.net> wrote: > Except the lady will eventually downsize. The college student will want > more and lease the space. > > Also, the 49,000 Sq ft office space that has been leased for 10 years and > never occupied will be take

Re: New ICANN registrant change process

2016-07-06 Thread Christopher Morrow
On Mon, Jul 4, 2016 at 3:03 PM, Jay Ashworth wrote: > Seems to me that the proper thing to be done would have been for > Registries to deauthorize registrars on the grounds of continuous streams > of complaints. > > On what metric? Pure volume? Percent of registrations? type of complaint by simi

Re: New ICANN registrant change process

2016-07-06 Thread Christopher Morrow
On Wed, Jul 6, 2016 at 2:53 PM, David Conrad wrote: > On Jul 6, 2016, at 7:23 AM, Christopher Morrow > wrote: > > On Mon, Jul 4, 2016 at 3:03 PM, Jay Ashworth wrote: > >> Seems to me that the proper thing to be done would have been for > >> Registries to deautho

Re: New ICANN registrant change process

2016-07-06 Thread Christopher Morrow
On Wed, Jul 6, 2016 at 4:04 PM, David Conrad wrote: > Depends on whether or not the Registry wants their TLD to be associated >> with spam/malware distribution/botnet C&C/phishing/pharming and be removed >> at resolvers via RPZ or similar. Ultimately, the Registries are responsible >> for the poo

Re: New ICANN registrant change process

2016-07-06 Thread Christopher Morrow
On Wed, Jul 6, 2016 at 10:17 PM, David Conrad wrote: > On Jul 6, 2016, at 10:41 AM, Christopher Morrow > wrote: > > Perhaps this all self-polices? > > I figure either it does or governments get involved and that most likely > ends in tears. > > I can't wait for

Re: Bitcoin mining reward halved

2016-07-09 Thread Christopher Morrow
On Sat, Jul 9, 2016 at 3:10 PM, Jimmy Hess wrote: > On Sat, Jul 9, 2016 at 2:04 PM, wrote: > > Hi, > > Blockchain-based replacement for RPKI involving encoding of > IP address registry registrations assigned to a Network operator's > specified Org ID wallet, And LOAs for propagating the an

Re: Google NOC Contact?

2016-07-18 Thread Christopher Morrow
replying offlist (I'm sure I'm not the only one) On Mon, Jul 18, 2016 at 4:30 PM, Nick Olsen wrote: > Wondering if anyone from the Google NOC is on-list. > > Having issues reaching your authoritative name servers that appear to be > anycasted on Level3's network. > > Traffic to your name serve

Re: EVERYTHING about Booters (and CloudFlare)

2016-07-27 Thread Christopher Morrow
On Wed, Jul 27, 2016 at 10:58 AM, Paras Jha wrote: > I consistently did not even get replies This is a common 'complaint' point for abuse senders. I often wonder why. What is a reply supposed to do or tell you?

Re: EVERYTHING about Booters (and CloudFlare)

2016-07-27 Thread Christopher Morrow
On Thu, Jul 28, 2016 at 3:55 AM, Miles Fidelman wrote: > > > On 7/27/16 10:48 PM, Randy Bush wrote: > >> They just lost all respect from here. Would someone from USA please >>> report these guys to the feds? What they are doing is outright >>> criminal. >>> >> hyperbole. it is not criminal. you

Re: NFV Solution Evaluation Methodology

2016-08-02 Thread Christopher Morrow
On Tue, Aug 2, 2016 at 10:16 PM, Eric Kuhnke wrote: > But but but... cloud! THE CLOUD! Cloudy clouds fluffy white flying > through the air, you should move everything to the Cloud (tm). > > Sometimes people forget that *somebody* needs to run the bare metal and OSI > layer 1 things that physic

Re: NFV Solution Evaluation Methodology

2016-08-03 Thread Christopher Morrow
On Wed, Aug 3, 2016 at 8:20 AM, Ca By wrote: > > > On Wednesday, August 3, 2016, Randy Bush wrote: > >> > but, NFV isn't necessarily 'cloud'... It CAN BE taking purpose built >> > appliance garbage that can't scale in a cost effective manner and >> > replacing it with some software solution on '

Re: Host.us DDOS attack -and- related conversations

2016-08-03 Thread Christopher Morrow
On Wed, Aug 3, 2016 at 10:40 AM, James Bensley wrote: > How will > BCP save you then? Can everyone stop praising it like it was a some > magic bullet? > aren't you making a 'perfect is the enemy of good' argument here? 'seatbelts don't solve all car crash deaths, so let's just go mad-max!'

Re: Host.us DDOS attack -and- related conversations

2016-08-03 Thread Christopher Morrow
it's good that there aren't any easy solutions to this sort of problem... wait... that's wrong, there are. On Wed, Aug 3, 2016 at 12:04 PM, Robert Webb wrote: > Thanks for that link. My host is sitting in Atlanta and I believe that > Atlanta hosts their main infrastructure. > > I am seeing arou

Re: Host.us DDOS attack -and- related conversations

2016-08-04 Thread Christopher Morrow
"it's good that there aren't any easy solutions to this sort of problem..." On Thu, Aug 4, 2016 at 12:03 PM, Robert Webb wrote: > Looks like ATL01 is down again hard. > > Although, as someone else mentioned earlier, IPv6 seems to be just fine. > > Robert > > On Wed, Aug 3, 2016 at 12:40 PM, Phil

Re: CAIDA selected by FCC for internet performance measurement

2016-08-12 Thread Christopher Morrow
isn't this what KC presented like 3 nanogs ago? On Fri, Aug 12, 2016 at 4:41 PM, Scott Weeks wrote: > > > --- s...@donelan.com wrote: > From: Sean Donelan > > CAIDA has submitted to the FCC its initial proposal for > measuring internet interconnection point performance > metrics as part of the

Re: Looking for recommendations for a dedicated ping responder

2016-09-09 Thread Christopher Morrow
On Fri, Sep 9, 2016 at 4:17 PM, Jared Mauch wrote: > > > On Sep 9, 2016, at 4:08 PM, Dan White wrote: > > > > We're being caught up in some sort of peering dispute between Level 3 and > > Google (in the Dallas area), and we've fielded several calls from larger > > customers complaining of 40-50%

Re: "Defensive" BGP hijacking?

2016-09-14 Thread Christopher Morrow
On Wed, Sep 14, 2016 at 4:04 PM, Bryan Fields wrote: > On 9/14/16 3:09 AM, Scott Weeks wrote: > > > > Yes, RPKI. That's what I was waiting for. Now we can get to > > a real discussion > > Problem is, RPKI does not work for people with legacy blocks who will not > sign > a Legacy RSA. ARIN does

Re: "Defensive" BGP hijacking?

2016-09-18 Thread Christopher Morrow
On Fri, Sep 16, 2016 at 12:06 PM, Mel Beckman wrote: > > Preventing government manhandling needs to be a design goal. > Can you proffer some potential solutions or directions to look? At the end of the day the ISP or DNS operator or Enterprise is subject to local law enforcement action(s), so I

Re: "Defensive" BGP hijacking?

2016-09-19 Thread Christopher Morrow
(caution! I don't really think arin is evil!) On Mon, Sep 19, 2016 at 1:16 PM, John Curran wrote: > On Sep 14, 2016, at 4:59 PM, Christopher Morrow > wrote: > > > > On Wed, Sep 14, 2016 at 4:04 PM, Bryan Fields > wrote: > > > >> On 9/14/16 3:09 AM,

Re: "Defensive" BGP hijacking?

2016-09-20 Thread Christopher Morrow
On Tue, Sep 20, 2016 at 8:05 AM, John Curran wrote: > On Sep 19, 2016, at 11:58 PM, Christopher Morrow > wrote: > > > > (caution! I don't really think arin is evil!) > > Nor do I… (but I will remind folks that organizations evolve based on > participa

Re: Krebs on Security booted off Akamai network after DDoS attack proves pricey

2016-09-23 Thread Christopher Morrow
On Fri, Sep 23, 2016 at 9:24 PM, Jon Lewis wrote: > On Fri, 23 Sep 2016, Patrick W. Gilmore wrote: > > Is CloudFlare able to filter Layer 7 these days? I was under the >> impression CloudFlare was not able to do that. >> >> There have been a lot of rumors about this attack. Some say reflection, >

Re: Krebs on Security booted off Akamai network after DDoS attack proves pricey

2016-09-23 Thread Christopher Morrow
On Fri, Sep 23, 2016 at 10:13 PM, Jon Lewis wrote: > On Fri, 23 Sep 2016, Christopher Morrow wrote: > > On Fri, Sep 23, 2016 at 9:24 PM, Jon Lewis wrote: >> >> On Fri, 23 Sep 2016, Patrick W. Gilmore wrote: >>> >>> Is CloudFlare able to fil

Re: Krebs on Security booted off Akamai network after DDoS attack proves pricey

2016-09-24 Thread Christopher Morrow
On Sat, Sep 24, 2016 at 12:28 PM, Bill Woodcock wrote: > > > On Sep 24, 2016, at 7:47 AM, John Levine wrote: > > > >>> Well...by anycast, I meant BGP anycast, spreading the "target" > >>> geographically to a dozen or more well connected/peered origins. At > that > >>> point, your ~600G DDoS mig

Re: Krebs on Security booted off Akamai network after DDoS attack proves pricey

2016-09-24 Thread Christopher Morrow
On Sat, Sep 24, 2016 at 2:43 PM, Niels Bakker wrote: > * morrowc.li...@gmail.com (Christopher Morrow) [Sat 24 Sep 2016, 18:55 > CEST]: > >> boy, it'd sure be nice if there were some 'science' and 'measurement' >> behind such statements. >> Di

Re: Krebs on Security booted off Akamai network after DDoS attack proves pricey

2016-09-26 Thread Christopher Morrow
On Mon, Sep 26, 2016 at 7:49 PM, Mark Andrews wrote: > > Giving them real time access to the anomalous traffic log feed for > their residence would also help. They or the specialist they bring > in will be able to use that to trace back the problem. > > wouldn't this work better as a standard bi

Re: Questions re: VPN protocols globally

2016-10-05 Thread Christopher Morrow
On Tue, Oct 4, 2016 at 11:15 PM, Eric Germann wrote: > I’ve been charged with building a global VPN as an overlay on top of a > certain 3 letter company who also sells lots of stuff. > > you say 'vpn' do you mean 'mpls vpn' or 'ipsec vpn over intertubes' ? > We’re looking at > > US East > US We

Re: AS47860 - 93.175.240.0/20 - Wiskey Tango Foxtrot

2016-10-05 Thread Christopher Morrow
On Wed, Oct 5, 2016 at 7:55 PM, Ronald F. Guilmette wrote: > > > > P.S. This crap appears to be be brought to us courtesy of AS29632, > NetAssist, LLC: > > http://new.netassist.ua/ > > So anyway, where are the grownups? > clearly whomever provides transit to 29632... probably worth hunting

Re: Should abuse mailboxes have quotas?

2016-10-27 Thread Christopher Morrow
On Thu, Oct 27, 2016 at 11:03 AM, Stephen Satchell wrote: > > I'm tired of blatantly uncaring administrations. > it's also totally possible that in some cases the mailbox for abuse@ got moved behind some orgs other mail systems... This happened numerous times at $PREVIOUS_EMPLOYER. When moving

Re: Should abuse mailboxes have quotas?

2016-10-27 Thread Christopher Morrow
On Thu, Oct 27, 2016 at 2:35 PM, Dan Hollis wrote: > On Thu, 27 Oct 2016, Christopher Morrow wrote: > >> On Thu, Oct 27, 2016 at 11:03 AM, Stephen Satchell >> wrote: >> >>> I'm tired of blatantly uncaring administrations. >>> >> it'

Re: Large BGP Communities beacon in the wild

2016-10-27 Thread Christopher Morrow
On Thu, Oct 27, 2016 at 5:28 PM, James Bensley wrote: > > > Name and shame, it is not acceptable! > > read the IDR thread(1), the vendors in question actually self reported. I don't think 'shame' here is quite appropriate, but certainly owen's note about: "Hey, pls don't do this again" with the a

Re: Death of WHOIS, Film at 11

2016-10-30 Thread Christopher Morrow
On Sat, Oct 29, 2016 at 11:05 PM, Ronald F. Guilmette wrote: > > known inaccurante answers > I'm betting that the operators of the named whois servers believe the information is as accurate as they can provide, right?

Re: Another day, another illicit SQUAT - WebNX (AS18450) 103.11.67.0/24

2016-10-31 Thread Christopher Morrow
On Fri, Oct 28, 2016 at 7:36 PM, Ronald F. Guilmette wrote: > In my own defense, I didn't see the ARIN allocation because I have a > normative process that I use for looking up IP addresses. It's > hierarchical, and I always start with whatver whois.iana.org has to > say. And it says that that

Re: NEVERMIND! (was: Seeking Google reverse DNS delegation contact)

2016-11-13 Thread Christopher Morrow
So... actually someone did tell arin to aim these at ns1/2google.com... I'll go ask arin to 'fix the glitch'. thanks! -chris (sometimes people do this, I have no idea why... perhaps they just like broken ptrs?) On Thu, Nov 10, 2016 at 10:05 PM, Ronald F. Guilmette wrote: > > > My profuse apolog

Re: NEVERMIND! (was: Seeking Google reverse DNS delegation contact)

2016-11-16 Thread Christopher Morrow
On Sun, Nov 13, 2016 at 3:57 PM, Christopher Morrow wrote: > So... actually someone did tell arin to aim these at ns1/2google.com... > I'll go ask arin to 'fix the glitch'. > > the glitch got fixed, shortly after this message, but not by my/our doing... hrm.. I see

Re: Forwarding issues related to MACs starting with a 4 or a 6 (Was: [c-nsp] Wierd MPLS/VPLS issue)

2016-12-02 Thread Christopher Morrow
On Fri, Dec 2, 2016 at 9:32 AM, Job Snijders wrote: > > Dear Vendors, take this issue more serious. Realise that for operators > these issues are _extremely_ hard to debug, this is an expensive time > sink. Some of these issues are only visible under very specific, rare > circumstances, much like

Re:

2016-12-02 Thread Christopher Morrow
On Fri, Dec 2, 2016 at 6:08 AM, Rich Kulawiec wrote: > > We are busy trying to support a domain name system that is two to > three orders of magnitude larger (as measured by domains) than it > should be or needs to be. > > that statement seems ... hard to prove. also, what does it matter the size

Re: Forwarding issues related to MACs starting with a 4 or a 6 (Was: [c-nsp] Wierd MPLS/VPLS issue)

2016-12-02 Thread Christopher Morrow
On Fri, Dec 2, 2016 at 11:02 AM, Simon Lockhart wrote: > On Fri Dec 02, 2016 at 10:29:56AM -0500, Christopher Morrow wrote: > > you'd think standard testing of traffic through the asic path somewhere > > between 'let's design an asic!' and 'here's yo

Re: Forwarding issues related to MACs starting with a 4 or a 6 (Was: [c-nsp] Wierd MPLS/VPLS issue)

2016-12-02 Thread Christopher Morrow
On Fri, Dec 2, 2016 at 11:07 AM, Christopher Morrow wrote: > > > On Fri, Dec 2, 2016 at 11:02 AM, Simon Lockhart wrote: > >> On Fri Dec 02, 2016 at 10:29:56AM -0500, Christopher Morrow wrote: >> >> 2^(8*9216) is quite a lot of different packets to test through th

Re: BCP38 and Red Hat

2016-12-15 Thread Christopher Morrow
On Thu, Dec 15, 2016 at 9:48 AM, Stephen Satchell wrote: > https://bugzilla.redhat.com/show_bug.cgi?id=1370963 > > Just a reminder that I have a feature request outstanding with Red Hat > to add support for BCP38, as well as measures for certain protocol-based > amplification reflection attacks.

Re: Benefits (and Detriments) of Standardizing Network Equipment in a Global Organization

2016-12-28 Thread Christopher Morrow
On Wed, Dec 28, 2016 at 1:39 PM, Chris Grundemann wrote: > On Tue, Dec 27, 2016 at 3:10 PM, Leo Bicknell wrote: > > > 2 Vendor > > > > Can be implemented multiple ways, for instance 1 vendor per site > > alternating sites, or gear deployed in pairs with one from each vendor > > up and down the s

Re: SoCal FIOS outage(?) / static IP readdressing

2017-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2017 at 8:37 AM, Jared Mauch wrote: > > > On Jan 4, 2017, at 7:54 AM, Baldur Norddahl > wrote: > > > > I solved this issue by making my own ISP. > > I’ve been thinking of the same in my underserved area. Labor is $5/foot > here and despite friends and colleagues telling me to mov

Re: SoCal FIOS outage(?) / static IP readdressing

2017-01-04 Thread Christopher Morrow
On Wed, Jan 4, 2017 at 4:53 PM, Paul B. Henson wrote: > > From: Christopher Morrow > > Sent: Wednesday, January 04, 2017 8:42 AM > > > > and think about it, you could get ipv6 on your network... the OP still > > doesn't have that native on his fios I bet. &g

Re: OmanTel hijacking of IP space

2017-01-11 Thread Christopher Morrow
On Wed, Jan 11, 2017 at 10:50 AM, Jared Mauch wrote: > 206.125.164.0 thanks to everyone who's (not) filtering. You're making the internet a little (less) better each time this happens.. What year is it?

Re: IPv6-enabled multi-factor providers (not DUO)

2017-02-02 Thread Christopher Morrow
On Thu, Feb 2, 2017 at 11:32 AM, David Sotnick wrote: > Hi NANOG, > > (Apologies if this is slightly off-topic; there are a lot of IPv6-advocates > here who might have some insights). > > At my day job, we use Duo Security for MFA. It works well, with the caveats > that it's cloud-based and heavi

Re: backbones filtering unsanctioned sites

2017-02-10 Thread Christopher Morrow
On Fri, Feb 10, 2017 at 6:47 AM, Robert McKay wrote: > On 2017-02-10 04:18, Ken Chase wrote: > >> https://torrentfreak.com/internet-backbone-provider-cogent- >> blocks-pirate-bay-and-other-pirate-sites-170209/ >> >> /kc >> > > Strange indeed.. but they forgot to ban it on IPv6 - maybe they're try

Re: backbones filtering unsanctioned sites

2017-02-10 Thread Christopher Morrow
On Fri, Feb 10, 2017 at 1:39 PM, Mike Hammett wrote: > Have we determined that this is intentional vs. some screw up? > > if you look at the cogent LG it's pretty clear that the announce reachability for the /20 that includes the tpb /32.. and that the /32 is particularly routed elsewhere, and th

Re: backbones filtering unsanctioned sites

2017-02-10 Thread Christopher Morrow
his. > > I bet an answer from cogent here is: "you can always TE around 174" that's hard for end-users, but the direct customer can certainly do this... and yea, sucks :( > /kc > > > On Fri, Feb 10, 2017 at 03:03:11PM -0500, Christopher Morrow said: >

Re: backbones filtering unsanctioned sites

2017-02-10 Thread Christopher Morrow
On Fri, Feb 10, 2017 at 2:08 PM, Ken Chase wrote: > >"Abuse cannot not provide you a list of websites that may be > encountering > >reduced visibility via Cogent" > > They could, if they kept a list of forward lookups they had done to get IPs > i think you mean passive-dns .. which is a thin

Re: backbones filtering unsanctioned sites

2017-02-10 Thread Christopher Morrow
On Fri, Feb 10, 2017 at 5:30 PM, Ken Chase wrote: > If its not just cogent then we have an even larger issue -- that > theres asymetric application of rulings. So we should just assume > that if we can't get to something via cogent then all backbones > within the same jurisdiction(*) should or wi

Re: YouTube streaming failures

2017-02-12 Thread Christopher Morrow
verizon wired, comcast (on a mobile device) both work in IAD's area. On Sun, Feb 12, 2017 at 8:53 PM, Patrick W. Gilmore wrote: > I cannot stream on AppleTV or iPhone. Works on my laptop. > > Comcast, Massachusetts. > > -- > TTFN, > patrick > > > On Feb 12, 2017, at 8:08 PM, Brett A Mansfield <

Re: backbones filtering unsanctioned sites

2017-02-13 Thread Christopher Morrow
On Mon, Feb 13, 2017 at 4:53 PM, Jean-Francois Mezei < jfmezei_na...@vaxination.ca> wrote: > > > Cogent seems to have been very very silent on the issue. > > why would they say anything at all? it's blatantly clear what's happened, right? "lea order to block access" no explanation necessary. >

Re: Web/Streaming issues

2017-02-14 Thread Christopher Morrow
On Mon, Feb 13, 2017 at 1:49 PM, Art Stephens wrote: > Been getting complaints from customers about web services such Netflix, > Youtube, Facebook and Snapchat either slow to load or not loading at all > and yet speed tests seem to be ok. > > speed tests aren't necessarily related at all with (at

Re: Comcast and DGA like behavior

2018-04-25 Thread Christopher Morrow
On Wed, Apr 25, 2018 at 11:28 AM, J. Oquendo wrote: > Anyone else seeing DGA (1) like behavior for Comcast based > customers? If so, is there any information on it? Seeing a > lot of traffic to bogus domains all synonymous with their > networks. > don't they have a anti-botnet-automagic-walled-ga

Re: Curiosity about AS3356 L3/CenturyLink network resiliency (in general)

2018-05-20 Thread Christopher Morrow
On Sun, May 20, 2018 at 12:33 PM Rubens Kuhl wrote: > > CenturyLink bought Level 3, which bought Global Crossing, which bought > Impsat; this makes every market unique, for the good and bad of it. > > What I have as a customer feeling is that Global Crossing was the most > quality-minded of the 4,

<    1   2   3   4   5   6   7   8   9   10   >