Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] Security group highlights - December 2018

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] Security group highlights - December 2018


Chronological Thread 
  • From: Brad Fleming <>
  • To:
  • Subject: Re: [Security-WG] Security group highlights - December 2018
  • Date: Mon, 7 Jan 2019 10:43:25 -0600
  • Ironport-phdr: 9a23:05icdhxIBrw18SjXCy+O+j09IxM/srCxBDY+r6Qd2ukVIJqq85mqBkHD//Il1AaPAd2Lraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze+/94HQbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDwULs6Wymt771zRRHolCgIOCM3/m/ZisJujq1VoxWvqgdww4LIZYGYLvp+cr/fcN4cWGFPXtxRVytEAo6kcoYPFfAOMvtFpIf9o1sBsx6+BQiqBOPg1zRFgWT50rA00+QlDw7G2Q0gH9QBsHnPr9X6LqESUfqrw6nO1znDae1Z2Svk5YXObxsvr/aMXbdqfsrQz0kiDx/FjlWOpoz/ITyV2eUNs3OH7+V+T+KjkXIoqwZrrjiyxccgkpXJh4wUylDY6SV23pw1KcekR058ZN6oCJ1QtiGfN4RsTcMuWX1nuCE/yrAApJW1fzAKxYw5yxPed/CKcY2F4hzgWemKPTt1gX1odbG+ihu99EWs1PHwW8yx3VpUsCZKjMHAum4M2hDP9MSKT/Vw8lug1DuK1A3c8f9ILlsxmKfaL5MswaI8m58NvknHHiL6hkD7gaySe0k6++Wl7uTqba/iq5OCMoJ0hB/yPbk0lcG5HO82KBIBX3KB9uS5zLDj/VP2QLFNjvAul6nWqpHaJcACqq6+Ag9Zz58v6hmhAzu4ztsUh3YHLFVCeBKIi4jmJUvCL+z/Dfe6m1iskTFryO7aPrD5HJnAL2TPnbXkcLZz6ENT0xY/wNVQ6p9XC7wML/f+VlHtuNHdCxI1LRK4zPj/BNV4zIweWGaPAqGDMKPVtF+F/vkgLPSCZI8Rpjn9Lvkl5/jhjXIiml8SZ6+p3YEJZ3C+BPhmJVuWYWb0jtcbDWgKphY+TPDtiFCaSj5ceWq9X78m5jE6FIKnDZ7PR46igLGa2Ce7H4ZWZnxdClySC3vodoOEW+sSZyKIJM9ujCAEWaa7R4A/yB6uqVyy970yNeff5zcZqYOmy9dd5uvPmAs0+CAuScmRzjKjVWZxy0kSTjN+8qRypE17xR/X26R2h/FdFNpcz/BAVB03M9jawvAsWIO6YR7IYtrcEAXued6hGzxkFt8=

I’m assuming RFC1918 IPs as the source, correct? Regardless of source or destination address I’m good with it. We shouldn’t be leaking that junk, if we are something is broken, and I don’t expect Internet2 or the greater community to deal with our failures. A publicly viewable counter on the firewall filter term could be useful; I could make one of our junior network team check the I2 counter every month to verify we don’t have an internal issue. I’d be fine if that instrumentation wasn’t added until later if I2 staff would like to move quickly on deploying filters but also want to gather more input from the community on exposing FW filter counters in this manner. 
--
Brad Fleming
Assistant Director for Technology
Kansas Research and Education Network

On Jan 7, 2019, at 10:13 AM, Adair Thaxton <> wrote:

I trust everyone had a nice break, and hasn't been driven up the wall by
bored children yet.  Our three-year-old reached the "why?" stage just in
time for break, so if you're still sane, I envy you!


- Internet2 is considering blocking all RFC1918 space at ingress links. 
We do not expect this to affect cloud tunnel traffic, or any legitimate
traffic.  However, we all know the pitfalls of that last statement,
especially on our networks!  We plan to start by logging RFC1918 traffic
only, and then move to blocking it.  We also plan to offer opt-outs for
customers who need them.  We would welcome your input on this, for our
benefit as well as for the benefit of other customers.


- Check your routing tables! 
https://twitter.com/InternetIntel/status/1080466509292621829


- Hat tip to researchers at the University of Maryland! 
https://www.theregister.co.uk/2019/01/03/recaptcha_voice_challenge/


- A lot of it, as it turns out. 
http://nymag.com/intelligencer/2018/12/how-much-of-the-internet-is-fake.html


Happy new year, everybody!

Adair

Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page