Apple network traffic takes mysterious detour through Russia
- Reference: 1658948198
- News link: https://www.theregister.co.uk/2022/07/27/apple_networking_traffic_russia_bgp/
- Source link:
In a [1]write-up for MANRS (Mutually Agreed Norms for Routing Security), a public interest group that looks after internet routing, Internet Society senior internet technology manager Aftab Siddiqui said that Russia's Rostelecom started announcing routes for part of Apple's network on Tuesday, a practice referred to as BGP (Border Gateway Protocol) hijacking.
BGP is the glue that links multiple networks together to form the internet. Unfortunately, the protocol is too credulous. When an autonomous system (AS) – a group of networks managed by a single entity – announces routes for groups of IP addresses (IP prefixes) that it does not own, internet traffic will generally adapt to those routes if the rogue announcement isn't filtered out.
[2]
Some bad route announcements are accidental and a result of something like a configuration blunder, and some announcements are straight-up malicious.
[3]
[4]
For example, in 2018 cyberthieves used BGP hijacking [5]to meddle with Amazon's Route 53 DNS service and redirect internet traffic from a cryptocurrency website to a phishing site hosted in Russia.
The redirection of Apple's networking traffic began about 2125 UTC on Tuesday, according to Siddiqui, when Rostelecom’s AS12389 network began announcing 17.70.96.0/19, which is part of Apple's [6]17.0.0.0/8 block and is usually announced as part of the larger 17.0.0.0/9 block.
[7]After config error takes down Rogers, it promises to spend billions on reliability
[8]Cloudflare's outage was human error. There's a way to make tech divinely forgive
[9]Big Tech's private networks and protocols threaten the 'net, say internet registries
[10]Facebook rendered spineless by buggy audit code that missed catastrophic network config error
The routing change was [11]detected by BGPstream.com (Cisco Works), which identified the block as AS714 APPLE-ENGINEERING, US, and [12]by GRIP Internet Intel (GA Tech ). And it lasted just over 12 hours.
Apple did not respond to a request for comment and The Register is unaware of any public statement the company may have made about the hijacking of its network traffic.
[13]
"It is not clear which services were impacted by this incident," said Siddiqui. "Unless we get more details from Apple or other researchers, we can only guess."
Siddiqui said Rostelecom (AS12389) has been involved in [14]previous BGP hijackings , and emphasized that network operators implement effective route filtering based on reliable information to thwart these shenanigans.
The Register asked MANRS whether anyone there had heard anything from Apple since its post was published and a spokesperson replied, "We have not heard anything from Apple yet on this issue. The MANRS team is reaching out privately to learn more about the incident."
[15]
In 2020, Cloudflare created the website [16]Is BGP safe yet? while knowing full well that it is not. At the time this story was filed, the answer to that question was still, "No." ®
Get our [17]Tech Resources
[1] https://www.manrs.org/2022/07/for-12-hours-was-part-of-apple-engineerings-network-hijacked-by-russias-rostelecom/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YuG1gwPoKE4YvrXUmpyiIwAAAII&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuG1gwPoKE4YvrXUmpyiIwAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuG1gwPoKE4YvrXUmpyiIwAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2018/04/24/myetherwallet_dns_hijack/
[6] https://whois.arin.net/rest/net/NET-17-0-0-0-1
[7] https://www.theregister.com/2022/07/25/canadian_isp_rogers_outage/
[8] https://www.theregister.com/2022/06/27/cloudflares_outage_opinion_column/
[9] https://www.theregister.com/2021/12/09/study_on_the_internets_technical_success_factors/
[10] https://www.theregister.com/2021/10/06/facebook_outage_explained_in_detail/
[11] https://bgpstream.crosswork.cisco.com/event/293915
[12] https://grip.inetintel.cc.gatech.edu/events/submoas/submoas-1658870700-714=12389/17.70.96.0-19_17.0.0.0-9
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YuG1gwPoKE4YvrXUmpyiIwAAAII&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.manrs.org/2020/04/not-just-another-bgp-hijack/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YuG1gwPoKE4YvrXUmpyiIwAAAII&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://isbgpsafeyet.com/
[17] https://whitepapers.theregister.com/
Block sizes
"Rostelecom’s AS12389 network began announcing 17.70.96.0/19, which is part of Apple's 17.0.0.0/8 block and is usually announced as part of the larger 17.0.0.0/9 block."
A /9 block is *smaller* than a /8 block.
Re: Block sizes
/19 is smaller than /9. Probably Apple announces 17.0.0.0/9 separately.
It would be interesting to know what those addresses are usually used for.
Re: Block sizes
It would be interesting to know what those addresses are usually used for.
S'easy. Grab Nmap and have at it. Apple may object, but like most of big tech, if they have no respect for our security or privacy, turnabout is fair play.
This is why all traffic should be encrypted
Since fixing BGP seems to impossible as we've been dealing with these for at least 20 years.
Even stuff that seems innocuous should be encrypted. That way the only thing malicious actors can do is a DoS, rather than snooping or worse modifying traffic in transit.
I'm not sure if any of Apple's iPhone to HQ traffic etc. is in the clear, but I doubt it. If it was then, it surely isn't after this happened!
Yet IPv6 networks were built to rely on and assume both BGP and DNS work perfectly.
Hence our current conundrums. First why the {BLEEP} is anyone letting BGP advertisements out of Russia right now? Ask the TLAs for a map of their network edge and banish any advertisements for other ranges to /dev/null.
Second, it's been clear for a while that BGP is a shitshow, if we can't fix it, we should be declaring support for an alternative, not waving our arms around. Much like SSL and DNS, BGPs core problems are in it's design assumptions not it's core code. You can fix those without breaking existing routing, but if only some participants implement the changes you have this kind of thing as an ongoing problem. The big asns and tier 1 carriers need to start slapping everyone else on the wrist to get the heel draggers moving.
Carrot and stick perhaps? A new routing overlay where jumbo frames are supported but you have to run complaint secure DNS, non-blind trust BGP etc to join the party. I'd pay extra for it!