Russian-Controlled Telecom Hijacks Traffic For Mastercard, Visa, And 22 Other Services (arstechnica.com)
An anonymous reader quotes the security editor at Ars Technica:
On Wednesday, large chunks of network traffic belonging to MasterCard, Visa, and more than two dozen other financial services companies were briefly routed through a Russian government-controlled telecom under unexplained circumstances that renew lingering questions about the trust and reliability of some of the most sensitive Internet communications.
Anomalies in the border gateway protocol -- which routes large-scale amounts of traffic among Internet backbones, ISPs, and other large networks -- are common and usually the result of human error. While it's possible Wednesday's five- to seven-minute hijack of 36 large network blocks may also have been inadvertent, the high concentration of technology and financial services companies affected made the incident "curious" to engineers at network monitoring service BGPmon. What's more, the way some of the affected networks were redirected indicated their underlying prefixes had been manually inserted into BGP tables, most likely by someone at Rostelecom, the Russian government-controlled telecom that improperly announced ownership of the blocks.
Anomalies in the border gateway protocol -- which routes large-scale amounts of traffic among Internet backbones, ISPs, and other large networks -- are common and usually the result of human error. While it's possible Wednesday's five- to seven-minute hijack of 36 large network blocks may also have been inadvertent, the high concentration of technology and financial services companies affected made the incident "curious" to engineers at network monitoring service BGPmon. What's more, the way some of the affected networks were redirected indicated their underlying prefixes had been manually inserted into BGP tables, most likely by someone at Rostelecom, the Russian government-controlled telecom that improperly announced ownership of the blocks.
I'm sure all the relevant important traffic for these sites was and is at least TLS encrypted, right? Right?
And it's not as if that espionage on banks isn't a totally normal thing:
https://www.wired.com/2017/04/...
http://www.spiegel.de/internat...
http://www.reuters.com/article...
Not just a few banks or lowly consumer creditcard companies, but SWIFT itself, the system that all banks use to transfer money around the globe. Not just traffic but actual inside data.
Not to mention a ton of routers inside various banks all over the middle east.
I wonder what the headline would have been if it were US entities doing the same thing; with no fact checking by main stream media.
Think about all the lies we've been fed on all this time...
Is it also coincidence that 4 out of 30 are French?
We got election in France with Le Pen with very close ties to Russia.
Did not Clinton lose thanks to Russian hackers that broke into her email?
in addition to all other spying on the world, but of course we're not allowed to talk about that. If something like this happens, most likely accidentaly, then all the shit-outlets on the Internet are quick to blow it up and point fingers.
Papers Please Comrade Data... before the data left Russian borders.
by TheSpoom (715771) Uncaring Linux user here. I have nothing to add to this but please continue. *munches popcorn*
These children are in dire need of parental supervision. Put them behind a responsible operator who makes sure they can't do it again.
Likely explanation:
- rostelcom is running a collection network spying on these netblocks.
- They use BGP within the collection network to limit what's collected and avoid DoSing themselves. BGP is a good protocol for custom stuff because it's simple to write and debug an endpoint, and it interoperates well.
- Misconfiguration leaked collection net prefixes onto the public Internet.
If that's true, the collection is ongoing.
No news here: NSA is collecting the same and more of both these networks and Russian financial networks. Go back to sleep, sheeple.
"Russian-Controlled Telecom Hijacks Traffic For Mastercard, Visa, And 22 Other Services."
Well that's just fucking splendid.
Just cruising through this digital world at 33 1/3 rpm...
Seriously? Anybody still doubts that every government that can, monitors, fucks with, tries to identify the source of anything they don't like?
5 to 7 minutes sounds like the reboot time of a major router when the admin didn't understand the redundancy features.
MasterCard is connected to my local peering exchange via their DDoS protection provider. There is no way that route would go via Russia unless the DDoS provider globally dropped all their other routes. Some of the listed companies also have a large global peering presence as well.
... to see if they could, and maybe get some sample data to see what they'd be dealing with before they start the full attack?
There's lots of these, e.g. you'll see VneshEconomBank used to bailout Putin projects and host spies in its offices abroad.
e.g. A Russian agent was caught and prosecuted in its New York office:
https://www.rawstory.com/2017/03/revealed-jared-kushner-met-with-head-of-russian-bank-that-hosted-spy-ring-busted-by-preet-bharara/
They really are a rogue nation at this point, ISIS kill a few people, but Russian *invades* allied countries, actively tries to take them over, it's government hackers constantly attacking our systems, its government propaganda constantly spreading astroturf.
Poland's Baltic port is cut off by strip of land. To sail to it, they need to go through a Russian controlled gate in the Russian enclave of Kaliningrad.
Russia sets special conditions on the use of the gate, e.g. military ships need special permission/inspection.
Polish government is making its own gate, since the Russian fleet has been threatening Baltic states. It wants to strengthen its NATO facilities.
So what's Russia been up to? Propaganda, astroturf, but not phrased in terms of "Russian government disapproves", more phrased in terms of "the people of poland disapprove"... i.e. Russian media claiming to be the true voice of the Polish people.
When we put sanctions on Russia, it took away the carrot and left the stick. No reason for Putin to hold back. So now Putin is facing protests, and he's attacking other nations to keep power. Not just Ukraine (miltary), not just Hungary (politically) , Germany (hacking and propaganda), not just Baltic states (agent provocateurs on the ground and cyber), not just the USA (hacking, astroturf, monied influence)....
Russia is practically at war with us at this point.
Any evidence? Can you cite an article mentioning this US hacking of border gateway protocol ? No?
And how are we not allowed to talk about it? By what mechanism does the US stop us talking about it? No?
And you got 2 mod points? What nationality are those mod points?
Really fuck you, you Russian skum troll. Hijacking networks is never allowed, and its not by accident that you transmit specific false routings.
No fixes for BGP hijacks, no mandatory ingress/egress filtering for ISPs, all the major browser manufacturers refusing to implement DANE. Don't attribute to malice what you can attribute to incompetence I guess ... extreme fucking incompetence.
Build a new internet already, so we can let the old internet rot.
This unverified news basically says that encrypted internet traffic from some banks was temporarily rerouted through "other" servers. So what? Start worrying, details to follow, they said.
Can someone please explain to me why Russia was ever connected to the freaking internet? It's a DOD project!
Snooping upon Russian businessmen would be nothing new to NSA/CIA brothers.
Nah - your mom just has a "spacious" pussy.
I am willing to bet $10 there'll be a dozen Trump conspiracy theorists raising hell over this. HE DID IT! and shit like that.
You fucking wankers could be more pathetic, but I'm at a loss as to how....