<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BT chooses to route to an instance of L-Root in Belarus in Everything else</title>
    <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1984059#M36197</link>
    <description>&lt;DIV style="background: #EDF3F5; padding: 10px; margin-top: 20px; margin-right: 10px; border: 2px solid #CFD8DC; border-radius: 10px; box-shadow: 8px 8px 7px #676D70; font-size: 10pt;"&gt;&lt;BR /&gt;
&lt;P style="font-size: 10pt;"&gt;&lt;STRONG&gt;Moderators Note&lt;/STRONG&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P style="font-size: 10pt;"&gt;This topic has been moved from Broadband&amp;nbsp;to Everything Else&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Sun, 01 Sep 2024 16:53:21 GMT</pubDate>
    <dc:creator>dvorak</dc:creator>
    <dc:date>2024-09-01T16:53:21Z</dc:date>
    <item>
      <title>BT chooses to route to an instance of L-Root in Belarus</title>
      <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983888#M36193</link>
      <description>&lt;P&gt;I tried to raise the issue on the phone with Plusnet support but got a response saying we don't support domains. Hopefully there are people here who can raise this issue with BT NOC.&lt;/P&gt;&lt;P&gt;As you can see in the trace below BT selects to route to an instance of L-Root in Belarus. I believe it's a major security risk due to possible DNS manipulation from the owners of the instance.&lt;/P&gt;&lt;LI-CODE lang="python"&gt; mtr -4 -wzb -c4 l.root-servers.net
Start: 2024-08-30T16:51:32+0100
HOST: xxxxxxxx.xxx                                                   Loss%   Snt   Last   Avg  Best  Wrst StDev
  1. AS???    172.16.10.xx                                            0.0%     4    0.9   0.8   0.4   1.1   0.3
  2. AS???    &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@3681646702FDFD32BCA97E2E5F1BDDD5/images/emoticons/huh.gif" alt="Huh" title="Huh" /&gt;                                                    100.0     4    0.0   0.0   0.0   0.0   0.0
  3. AS6871   132.hiper04.sheff.dial.plus.net.uk (195.166.143.132)    0.0%     4    1.9   2.0   1.6   2.9   0.6
  4. AS2856   peer2-et-0-0-4.slough.ukcore.bt.net (109.159.252.118)   0.0%     4    3.2   9.9   2.7  30.5  13.8
  5. AS???    linx-224.retn.net (195.66.224.193)                      0.0%     4    5.5   5.7   3.3   9.6   2.8
  6. AS9002   ae5-9.rt.lim.waw.pl.retn.net (87.245.233.46)            0.0%     4   40.2  33.6  29.4  40.2   5.0
  7. AS9002   gw-as6697.retn.net (87.245.245.135)                     0.0%     4   34.2  34.7  34.2  35.1   0.4
  8. AS6697   ie2.net.belpak.by (93.85.80.241)                        0.0%     4   55.6  51.8  49.7  55.6   2.6
  9. AS6697   core2.net.belpak.by (93.85.80.53)                       0.0%     4   53.3  51.2  48.7  53.9   2.8
 10. AS6697   93.84.125.193                                           0.0%     4   48.8  49.2  48.8  49.5   0.3
 11. AS20144  l.root-servers.net (199.7.83.42)                        0.0%     4   46.2  46.3  46.2  46.4   0.1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 15:57:42 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983888#M36193</guid>
      <dc:creator>rocra</dc:creator>
      <dc:date>2024-08-30T15:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: BT chooses to route to an instance of L-Root in Belarus</title>
      <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983902#M36194</link>
      <description>&lt;P&gt;I'm not really sure what you are actually concerned about. Maybe this is no more than a 'conspiracy theory'?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There's currently 146 different instances around the world of the l.root-servers.net at 199.7.83.42 (there's a nice list of all the root server locations at&amp;nbsp;&lt;A href="https://root-servers.org/" target="_blank"&gt;https://root-servers.org/&lt;/A&gt; ), and your ISP and others will work out a (probably dynamic) route to get to the 'closest' instance... for whatever reason, we are being sent to Belarus. Although, to be honest, in 99.9% of cases, it's not "WE" who are using it. "WE" use maybe the plusnet DNS servers, and it's THEY who access the root servers. Only a small percentage do their own recursive DNS lookups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;l.root is run by ICANN (although they have no involvement in the routing to get to them). In reality, the server will be a secondary DNS server, being regularly updated from the primary, wherever that is. I would imagine that ICANN would soon spot if someone was screwing with one of their root servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, yes, I guess it's possible for ANYONE at the actual DNS server location OR on the data-path to 'poison' a DNS response, although, if I'm honest, I'd probably be more worried that any manipulation was being done in the UK than Belarus!!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, what other countries are you worried about?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 17:44:35 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983902#M36194</guid>
      <dc:creator>paul_blitz</dc:creator>
      <dc:date>2024-08-30T17:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: BT chooses to route to an instance of L-Root in Belarus</title>
      <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983908#M36195</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/39167"&gt;@paul_blitz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;I'm not really sure what you are actually concerned about. Maybe this is no more than a 'conspiracy theory'?&lt;/P&gt;
&lt;P&gt;So, yes, I guess it's possible for ANYONE at the actual DNS server location OR on the data-path to 'poison' a DNS response, although, if I'm honest, I'd probably be more worried that any manipulation was being done in the UK than Belarus!!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So, what other countries are you worried about?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I'm not saying they're doing it. I'm saying it's a security risk. Belarus is known to use DNS spoofing in the past. &lt;A href="https://humanconstanta.org/en/state-provider-spoofs-dns-responses-for-users/" target="_blank"&gt;https://humanconstanta.org/en/state-provider-spoofs-dns-responses-for-users/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The route goes via Belpak which is state-owned.&lt;/P&gt;
&lt;P&gt;Overall the country is 25/100 on Freedom on the Net &lt;A href="https://freedomhouse.org/country/belarus/freedom-net/2023" target="_blank"&gt;https://freedomhouse.org/country/belarus/freedom-net/2023&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There were incidents where China leaked i-root instances in 2010 and k-root instances in 2021&lt;/P&gt;
&lt;P&gt;Do you have links or evidence to support you implying UK spoofs DNS requests?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 18:45:07 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983908#M36195</guid>
      <dc:creator>rocra</dc:creator>
      <dc:date>2024-08-30T18:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: BT chooses to route to an instance of L-Root in Belarus</title>
      <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983948#M36196</link>
      <description>&lt;P&gt;Thanks for the links, interesting reading.&lt;/P&gt;
&lt;P&gt;The 'attack' in that first article wasn't related to the root servers, or any other DNS servers, as it was a form of MITM, or in-transit attack, where certain specific sites (mainly Belarus) were 'spoofed'.... so the vast majority would have been untouched.... but the issue is,&amp;nbsp; of course, that they COULD have spoofed other sites too...&lt;/P&gt;
&lt;P&gt;Under the terms of 'conspiracy theory' we have to actually assume this could happen on ANY DNS lookup, caused by whoever has a suitable gripe! From a practical perspective, 99.99% of my DNS lookup will be happening here in the UK, thus my comment about the UK, and with it being a conspiracy theory, no proof is needed &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In real terms, given the sites that we are interested in, I suspect we remain pretty safe.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Aug 2024 10:09:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1983948#M36196</guid>
      <dc:creator>paul_blitz</dc:creator>
      <dc:date>2024-08-31T10:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: BT chooses to route to an instance of L-Root in Belarus</title>
      <link>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1984059#M36197</link>
      <description>&lt;DIV style="background: #EDF3F5; padding: 10px; margin-top: 20px; margin-right: 10px; border: 2px solid #CFD8DC; border-radius: 10px; box-shadow: 8px 8px 7px #676D70; font-size: 10pt;"&gt;&lt;BR /&gt;
&lt;P style="font-size: 10pt;"&gt;&lt;STRONG&gt;Moderators Note&lt;/STRONG&gt;&lt;/P&gt;
&lt;BR /&gt;
&lt;P style="font-size: 10pt;"&gt;This topic has been moved from Broadband&amp;nbsp;to Everything Else&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 01 Sep 2024 16:53:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Everything-else/BT-chooses-to-route-to-an-instance-of-L-Root-in-Belarus/m-p/1984059#M36197</guid>
      <dc:creator>dvorak</dc:creator>
      <dc:date>2024-09-01T16:53:21Z</dc:date>
    </item>
  </channel>
</rss>

