Just a guy in Vermont trying to connect all the dots...
Author's posts
Jan 23
ENISA Report On Secure Routing And Network Resiliency
What is the state of our routing infrastructure and what can be done to make it more secure and resilient?
In July 2010, the European Network and Information Security Agency (ENISA) published a report on this topic called:
It begins with a paragraph that I think will resonate with most of us:
Reliable communications networks and services are now critical for public welfare and economic stability. Intentional attacks on the Internet, disruptions due to physical phenomena, software and hardware failures, and human mistakes all affect the proper functioning of public communications networks. Such disruptions reveal the increased dependence of our society on these networks and their services. A vital part of reliable communication networks is the routing infrastructure.
The report goes on at great length to report on the result of a survey of network operators within the European Union about the use of – or plans to use – secure routing technologies within their networks. The report is quite useful in the background that it first provides around routing security concerns and some of the proposed solutions. It then goes into a detailed analysis of the survey results.
While the data is now close to three years old (the interviews were in March/April 2010), many of the points are quite similar to more recent analyses. A key point I noticed was this:
Overall, the lack of available knowledge and skills in routing security is recognised as a major barrier hindering further improvements in routing security, as became clear both from the online survey and the interviews.
Addressing this point by helping promote more awareness and education around routing security / resiliency is a primary aspect of our new Routing section here on Deploy360!
Overall the report makes for good reading if you are looking to understand more about the topic or “routing resiliency / security.” There has been a good bit of progress made within some of the working groups mentioned since the time of the report, but the report still provides a solid foundation and background.
Jan 22
Slides: Early DNSSEC Deployment Observations from Ed Lewis
What have we seen in terms of DNSSEC deployment around the world? Are there general trends or themes we can understand? Can we dive a bit deeper into some of the algorithms used in DNSSEC signatures?
In an October 2012 presentation to NANOG 56, Ed Lewis of Neustar dug into all these questions and more. The slides make for interesting reading, particularly some of the details about which crypto algorithms were used and what key lengths were used. He also looked at the frequency of key changes, key rollover processes and included a whole section on NSEC/NSEC3 records.
All in all an interesting set of data and some good recommendations around guidance that is needed for the industry. Well worth your time to scan through the slide deck if you are interested in statistics around DNSSEC deployment.
Jan 21
10 Updated Internet-Drafts Related to IPv6 Security
Fernando Gont of SI6 Networks has been a VERY busy man lately! He and his colleagues and co-authors have recently updated a whole host of Internet-Drafts related to IPv6 security. In a post to the full-disclosure mailing list, Fernando provided his list that includes:
Network Reconnaissance in IPv6 Networks
Security Implications of IPv6 on IPv4 Networks
Virtual Private Network (VPN) traffic leakages in dual-stack
hosts/ networksSecurity Assessment of Neighbor Discovery (ND) for IPv6
DHCPv6-Shield: Protecting Against Rogue DHCPv6 Servers
Security Implications of IPv6 Fragmentation with IPv6
Neighbor DiscoverySecurity Implications of IPv6 options of Type 10xxxxxx
Security Implications of Predictable Fragment
Processing of IPv6 “atomic” fragments
Recommendations on filtering of IPv4 packets containing IPv4 options
Some of these are broader documents while some dive deep into specific issues or solutions. Altogether they do represent a great amount of work on IPv6 security issues, which is excellent and definitely needed as we continue to move to using more and more IPv6 in our networks.
Thanks to Fernando and the others involved in the work for getting these updated drafts out. If you have any comments on these drafts, I know that Fernando is always looking for feedback – his email address and contact info in Argentina can be found at the end of any of the drafts.
Jan 21
PowerDNS Releases Version 3.2 With Increased DNSSEC Support
Congratulations to Bert Hubert and the rest of the team at
PowerDNS for their release 3.2 last Thursday that, if you scroll down through the release announcement and changelog is pretty much mostly about improvements to their already strong DNSSEC support! The list of changes and improvements is rather impressive.
In speaking with Bert last week, he said the team there views DNSSEC as basically “done” now for the authoritative server end and is now moving to focus on what they can do to make DNSSEC easier for deployment in DNS resolvers. We’re looking forward to seeing what the team does there.
Meanwhile, if you are a PowerDNS user, the new release will give you even more DNSSEC power… time to upgrade!
Jan 21
FIR #687 – 1/21/13 – For Immediate Release
Jan 18
Report: Routing Resiliency Measurements – Where We Are And What Needs To Be Done
What are the actual frequency of routing security incidents? And what are the operational and economic impacts of such security incidents?
We all know that “routing security” incidents happen, but it’s hard to get a grasp on exactly what the situation is. To that end, our colleagues in the Internet Society Standards and Technology team organized a “Routing Resiliency Measurements Workshop” in November 2012 to bring together participants from network operators, research labs, universities and vendors to explore what we can measure now – and what we need to do to start collecting more accurate measurements. The team has now published a report:
and our colleague Andrei Robachevsky has published some observations about the workshop. As Andrei notes, the point of the workshop was to address three main questions:
- What level of attack has there been in the past – to what extent do security incidents happen, but go unnoticed, or get dealt with inside a single network, possibly introducing collateral damage?
- Are the number and impact of service disruptions and malicious activity stable, increasing, or decreasing?
- Can we understand why, and track it collectively?
The report goes into some detail on what was discussed in the workshop and some of the approaches that were outlined. As Andrei relays in his post, the workshop didn’t magically produce answers to all these questions… but it did lay the foundation for where more work needs to occur.
As we open up the new topic area of Routing Resiliency / Security here on Deploy360, we intend to bring you more information from workshops such as these… and ultimately more of the solutions and best operational practices that can lead to a more resilient and secure Internet.
Jan 18
cPanel To Add IPv6 Support in 2013
Good news for the many people out there using cPanel to configure their hosted website… IPv6 support is coming this year. In a post titled “IPv6 Implementation Update” they state:
Much like Y2K, this issue requires a proactive solution rather than a reactive response. That is why cPanel has been working diligently on research and analysis to incorporate IPv6 support into our products. In 2013 we will begin to deliver features that support IPv6.
As some of you may already know, IPv6 is much more than just a change in the addressing scheme. However, given the urgency of supporting IPv6 addressing, we will first focus on allowing you to manage manually assigned IPv6 addresses at least as well as you can currently manage IPv4 addresses in cPanel & WHM. We also look forward to supporting IPv6 addresses on NSD, MyDNS and BIND (for DNS functionality), Apache (for website functionality), cPanel & WHM and its related services, and the various mail services we support. Additional services will be made IPv6-capable as deemed fit. The level of support cPanel will provide for IPv6 will provide functionality needed for serving web content.
Given the large usage of cPanel among web hosting providers it is great to see that this support for IPv6 will be added to the software. The cPanel article encouraged people to join in the IPv6-related discussion happening in the Feature Requests area of their website. It’s interesting to read there already the comments of people who have not implemented cPanel (or have chosen different hosting providers who don’t use cPanel) because of its lack of IPv6 support.
Jan 17
Facebook Rolls Out Free Voice Calls In The US On iOS – A Quick Walkthrough And A Big, Huge Caveat
Voice calling through Facebook has the potential to be hugely disruptive... rather than calling on your phone over your regular phone connection - or even rather than using Skype, you can just call from directly within Facebook. This is the kind of "Over-The-Top (OTT)" app that gives telco operators a fit... goodbye, telco voice minutes!
Plus, it's using some HD voice codec so the sound quality is outstanding.
And since the folks at Facebook want you to live your life inside of their very pretty walls, this just provides yet one more reason for you to stay within those walls.
BUT... there's a big huge caveat that I'll get to in a moment.
A Quick Walkthrough
First, though, let's look at how it works. When you go into the Messenger app and open a chat with a friend (in this case, Jim Courtney), all you have to do is click the "i" button in the upper right:
After you do that you will get a window that I showed at the beginning of an article where you have a "Free Call" button.
When you press that, you begin a call experience very similar to any other call on your iPhone. First you are connecting to the other person and then you are in the actual call:
There is apparently the standard accept and decline buttons. (I neglected to have Jim call me back to get a screenshot.) While you are in the call you have a button to hang up, a speakerphone button and a microphone mute button. The last button is very nice in that it lets you remain in the call while using other features of your iPhone. In these two screenshots you can see that I could access our Messenger chat and also go back to my main iPhone screen to launch other applications. I can always tap the bar at the top to return to Messenger and the controls to our voice conversation:
The voice quality during the conversation was outstanding. It was crystal clear and rich enough that we knew it was some kind of HD voice codec being used.
All in all it was an excellent experience.
The Big, Huge Caveat
So what's the problem? Well... the reality is that right now trying to find someone to call is a struggle!
Going down through my contacts in the Messenger app was an exercise in futility. Person after person after person had the "Free Call" button greyed out:
Here's the fundamental problem:
You must be running the MESSENGER app on your iPhone!
It doesn't matter if you are running the Facebook application on your iPhone... you must be running Messenger.
And bizarrely there is no linkage between the two applications. If I am over in the Facebook application and go into a chat with Jim Courtney, notice that I have only the ability to "View Timeline":
And of course you must have an iPhone or iPad. If you have an Android device or some other device you are out of luck right now.
So the only people you can use this with are other people running Messenger on iOS.
Presumably Facebook is assuming people will just keep Messenger running... but I know that I, for one, try to limit the number of apps I keep running on my iPhone for battery life reasons.
More fundamentally, I never have used the Messenger app for chatting with other friends in Facebook. The Facebook app already provides the ability to chat... so why would I use the Messenger app? (And I know Facebook focuses on the speed that you can get to sending messages... but that's not critical for me.)
Potential For Disruption?
Now if Facebook gets their act together and makes this more intuitive and ubiquitous, the potential is there for more serious disruption. If it can be integrated into the main Facebook app... and can work for Android as well as iOS... and can work for people outside the US and Canada... THEN we might see more people shifting voice calls over into Facebook's voice service.
The potential is certainly huge, given Facebook's massive size.
Until then... it's an interesting option to have available... but I just don't see many people using it.
What About The Technology Behind It?
My other natural question was to wonder what they are using for the technology behind their voice service. As The Verge pointed out, Facebook and Skype have had a partnership to deliver video calling within Facebook's website. Could this be another component of that partnership? Is it a partnership with another VoIP provider? Is it something homegrown?
For now, I haven't seen any details that help explain that, but I'll certainly be watching to see what we can learn.
UPDATE: A tweet from Aswath Rao pointed me to a TechCrunch article from earlier this month when Facebook rolled out free voice calling in Canada that indicates that the technology is NOT from Skype. Separately I asked a Skype representative if Skype was involved in today's rollout and received the simple answer of "no".
If you found this post interesting or useful, please consider either:
- following me on Twitter;
- adding me to a circle on Google+;
- subscribing to my email newsletter; or
- subscribing to the RSS feed
Jan 16
Playing Google’s Zamboni Game/Doodle… Over IPv6!
Okay, maybe it’s a small thing, but I have to admit that when I wound up on Google’s home page today to try out their “Zamboni doodle” celebrating the 112th birthday of Frank Zamboni, I don’t know which I found cooler… the game itself, or the fact that I was getting to it entirely over IPv6:
(Address bar IPv6 info courtesy of the IPvFoo extension for Google Chrome.)
Just another moment when I’m glad that Google’s websites are accessible via IPv6! As a web developer, too, I had to know: is this Zamboni game done entirely in JavaScript? A StackExchange answer says that it is, which is fascinating.
P.S. And yes, that was as high as I let my score go… the Zamboni looks like it could be an enormous time-suck, and I do have some writing that needs to be done!
Jan 16
Are You A Redditor? Subscribe To The IPv6 Subreddit
Are you are redditor? Is Reddit one of your main sources of information, news and links? If so, have you checked out the IPv6 “subreddit”? It is at:
and currently has close to 4,000 readers subscribed to it. I’ve found it a useful place for both finding new links and stories and also for some interesting discussions related to those stories. If you’re a reddit user, do check it out!
P.S. And if you’re not a reddit user, there are many other places where IPv6 is discussed on other services.

