2010/10/12

Dedicated Internet Access in Hong Kong in Year 1994

In clearing my drawers today, I found a quotation from Supernet sent to me in December 1994 about subscribing to its 256kbps Internet Dedicated Access.  The installation charge was HK$55,000 quoted as follows:

HKT DDS leased line installation – HK$4,000
Supernet Dedicated Installation fee – HK$10,000
Router installation – HK$41,000

As for the monthly recurrent cost, it was charged at HK$45,900 a month made up as follows:

HKT DDS leased line rental – HK$5,900
Supernet Dedicated monthly rental – HK$40,000

That was not the end of the story.  Supernet adopted a cap on monthly throughput of 8000 MB per month.  If the quota was exceeded, user would be charged HK$8 per MB.

It should be noted that in the early days of Internet, routers and switches, firewall and other networking equipment were not highly reliable and the committed availability of Supernet was just 99 %.  We all know that the Service Level Agreement used today always require the serving ISP to provide 99.9 or 99.95 % availability.

Looking back, I could not imagine how network administrators could have paid such high cost for Internet provisions and yet the services were not reliable. On top of that, how could they ensure that the maximum throughput was not exceeded.  Of course, having said that, network administrators today have easier jobs as they can ask ISPs to provide the best possible services without worrying the bandwidth usage.

2010/10/11

What the hell is Google on this planet !

What the hell is Google on this planet ! Google is testing intelligent cars that can drive by themselves.

The technolgies involved are video cameras, radar sensors and a laser range finder. I believe digital road maps are also required. Ultimately, the number of car accidents can be reduced.

When such cars are available in the market, I don’t need to learn driving and get a drive licence in order to use a car.

Google please keep up with the good work and give us more surprise in whatever new inventions.

2010/10/09

Nobel Peace Prize 2010

Though I can download or copy and paste the statement by the Noble Committee about the Nobel Peace Prize Award 2010 granted to Liu Xiaobo, I prefer to buy a newspaper and type the content word by word by myself and post it on my blog. This way, I am paying a tribute to the winner.  Here comes the statement:

The Nobel Peace Prize 2010

The Norwegian Nobel Committee has decided to award the Nobel Peace Prize for 2010 to Liu Xiaobo for his long and non-violent struggle for fundamental human rights in China.  The Norwegian Nobel Committee has long believed that there is a close connection between human rights and peace.  Such rights are a prerequisite for the “fraternity between nations” of which Alfred Nobel wrote in his will.

Over the past decades, China has achieved economic advances to which history can hardly show any equal.  The country now has the world’s second largest economy; hundreds of millions of people have been lifted out of poverty.  Scope of political participation has also broadened.

China’s new status must entail increased responsibility.  China is in breach of several international agreements to which it is a signatory, as well as of its own provisions concerning political rights.  Article 35 of China’s constitution lays down that “Citizens of the People’s Republic of China enjoy freedom of speech, of press, of assembly, of association, of procession and of demonstration”.  In practice, these freedoms have proved to be distinctly curtailed for China’s citizens.

For over two decades, Liu Xiaobo has been a strong spokesman for application of fundamental human rights in China.  He took part in the Tiananmen protests in 1989; he was a leading author behind Charter 08, the manifesto of such rights in China which was published on the 60th anniversary of the United Nations Universal Declaration of Human Rights, the 10th of December 2008.  The following year, Liu was sentenced to eleven years in prison and two years’ deprivation of political rights for “inciting subversion of state power”. Liu has consistently maintained that the sentence violates both China’s own constitution and fundamental human rights.

The campaign to establish universal human rights also in China ie being waged by many Chinese, both in China itself and abroad.  Through the severe punishment meted out to him, Liu has become the foremost symbol of this wide-ranging struggle for human rights in China.

Oslo, October 8, 2010/10/9

***** End *****

2010/10/08

In memory of John Lenon

Anybody still remember John Lenon was born on 9 October 1940. Google certainly do. Look at the Google logo on the left.

2010/10/01

SOA expiration time and DNSSEC signature period

My DNSSEC-signed zone bya.org.hk has SOA expiration timer set to one week (604800) which is not aligned with the published DNSSEC operational practices, RFC4614 bis. It is advisable to have SOA expiration timer between 1/3 and 1/4 size of the signature validity period (30 days = 2592000 seconds). If this is not handled properly, secondary nameserver could keep serving out of date RRSIGs. This can only happen when a primary nameserver is unreachable for AFXR update.

I have decided to set it to 720000 which is easy to remember.

2010/09/30

The Obama Administration issued another IPv6 directive

The Obama Administration has issued a directive requiring all US government agencies to upgrade their public-facing Web sites and services by 30 September, 2012 to operate on IPv6. Native IPv6 must be used as opposed to transition mechanisms.

Intutively, I have to ask myself what is the point of issuing such directive which is the second one in 5 years ? Back in 2005, the Bush
Administration established a deadline of June 2008 for all federal agencies to demonstrate IPv6 connectivity over their backbone networks. It seems clear to me that there is no penalty imposed on Federal agencies if they do not comply.

Would there be a third directive after the tenure of the Obama
Administration ? Only God knows !

2010/09/28

HKCERT web outage

In the current issue of HKCERT newsletter, HKCERT stated the incident of its web outage happened on 4 August.

The web server and the firewall were working normally.  However, the firewall could not connect to the Trust Source to verify incoming IP addresses and as a result, all visiting IP addresses were untrustworthy.  Thus, the firewall denied all access to the web server.

I applaud the gust of HKCERT in releasing the sensitive information and let all readers learn from the incident.  If the same happens in bank or any other public organizations, I doubt whether such details can be made known to the public.

2010/09/22

DNSSEC Visualization

Some friends asked me the URL of the website to visualize DNSSEC chain of trust in a graphical manner. The URL is at http://dnsviz.net/


I have a picture below of verifying the chain of trust for the domain isoc.org. This tool is invaluable for troubleshooting and understanding DNSSEC chain of trust.

2010/09/21

ftp loop to test network throughput

I have crafted a script in Windows to test network throughput and performance.  Basically, it is a ftp loop in conjunction with wget.  To quit the loop, just press CTRL-C.

@echo off
:loop
echo Hi! This is a ftp loop!
wget ftp://username:password@server.net/test.wmv
del *.wmv* -y
goto loop

2010/09/19

Big John problem

I have not seen such advice in public toilets in Hong Kong but I have to admit that there is the Big John problem everywhere.















It has nothing to do with the size of Big John.  Rather the problem is related to the thrust and firing angle of Big John.

2010/09/15

WiFi on steroids

Just when we think there can hardly be further development on WiFi, then comes "WiFi on Steroids". The use of white space in TV band can boost coverage and better building penetration.

By the way, traditional WiFi in the 2.4 GHz band is sick in the sense that it has a poor coverage and insufficient building penetration. I therefore like the name "Wifi on steroids".

2010/09/08

IPv6 global routing infrastructure

I just received a newsletter from Hurricane Electric and note that of the 35684 autonomous networks in the world running BGP, the number of IPv6 networks is increased to 2487. In other words, IPv6 now makes up 7 % of the global routing infrastructure.

IPv4 and IPv6 will co-exist for an ultra long time. It might take 30 - 40 years for the global routing infrastructure to become 100 % IPv6. By that time, I will be sleeping forever.

2010/09/06

司馬文大比數勝出

南區選民投票精采呀,司馬文大比數勝出,建制派候選人一敗塗地。

以投票率計算,司馬文取得 59 %,力保泛民以往六成支持率。

泛民繼續努力呀!

2010/09/01

保護根域

DNSSEC 實行後,為了保護根域 (root zone),共有14位當家,7位謢法,分散保管加密鑰及隨時啟動後備鑰。當家和謢法個個德高望重,武功高強,現在缺小了一位武林盟主,應該是 Rod Beckstorm,我是否在談武俠小說呀!

2010/08/31

/64 block in IPv6 router links

I note that some ISPs and organizations are not using /64 block in IPv6 router link or IPv6 peering.

Unlike IPv4 which normally has a subnet mask of /30 in router link for reserving the available IPv4 addresses , there is no need to make the subnet mask as /126 in IPv6. Just use /64 will be good enough and this is the default in a basic network segment. Put it another way, this is not a waste IPv6 addresses but an industry norm.warrenkwok

2010/08/29

Can IPv6 resolve cache-poisoning

Lately, I have been thinking about whether IPv6 can help to prevent cache poisoning.

A resolver running IPv4 can have one source IPv4 address to use whereas one riding on IPv6 can have up to 2^64 addresses to use within a basic network segment. Each time, the IPv6-enabled resolver sends out a query, a random IPv6 address within the assigned prefix should be selected. This way, the chance of cache poisoning will be a factor 16 bit transaction ID, 16 bit random port number plus 64 bit source IPv6 address. That says, the chance of poisoning is 1 in 2^96 which is not a problem at all.

However, the reality is that not all authoritative name servers are IPv6-enabled. If the Internet world had implemented IPv6 much earlier, cache poisoning should have been resolved and DNSSEC would not be necessary.

2010/08/26

DNSSEC resolvers weakness

I notice there is a weakness in DNSSEC-aware resolvers which is the root public key.  If hackers can disrupt the pre-stored root trust anchor, the resolvers can not resolve any domain due to chain of trust not  established.  But is that a big deal.

No, not at all.  ISPs are required to supply 2 or more resolvers to clients.  Even one resolver breaks down, the other will serve immediately.  The chance of hackers damage two resolvers at the same time is quite limited.

2010/08/23

Pre-published rollover of zone signing keys

I have turned to the use of pre-published rollover of zone signing key in order to manage DNSSEC in one of my administered zones. I need to draw a diagram to remind about the timing sequences and what keys to sign and publish. Here it is.










The above process must be done by cron job and shell script for automation.

2010/08/22

Root and TLDs shall not sign child's NS glue records

I have been wondering if root zone and TLDs are required to sign the NS glue records for their child zone since these TLDs are required to sign the DS records of their child zones. The answer is negative. Current release of DNSSEC specifications do not require such signing as TLDs are not authoritative for their child zone glue records. Whatever submitted will be accepted and stored without question. Just give a live example. If I get abc.com and the glue reccords say ns1.abc.com is at 1.2.3.4. Verisign, the operator of .com TLD will never ask me to prove this information.

Sounds pretty reasonable. Will there be any risk due to no signing of NS glue records for child zones. Hackers will know after some time.

2010/08/19

Start time of RRSIG fall behind 9 hours from the system clock after zone signing

I was wondering why the start time of RRSIG fell behind 9 hours from the system clock when zone signing was completed. On careful lookup of dnssec-signzone, it was stated that RRSIG should have a start time of UTC-1 hour in order to allow clock skew. It also made sense that RRSIG should be time-stamped with UTC. Since the time zone of Hong Kong is UTC +8, after adding one hour for clock skew, all RRSIG generated will be 9 hours behind the system clock.

This triggers me to think about another issue. If you have a nameserver that performs DNSSEC zone signing, it is better to change the clock to UTC instead of the local time. It will help to track RRSIG start and expiry more easily.