NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Technology

Unfixed internet glitch could strand you offline

By Peter Svensson
AP·
11 May, 2010 12:27 AM8 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Is the internet so fragile that it could fall to bits over dicey routing data? Photo / Sandy Parkinson
Is the internet so fragile that it could fall to bits over dicey routing data? Photo / Sandy Parkinson

Is the internet so fragile that it could fall to bits over dicey routing data? Photo / Sandy Parkinson

NEW YORK - In 1998, a hacker told Congress that he could bring down the internet in 30 minutes by exploiting a certain flaw that sometimes caused online outages by misdirecting data. In 2003, the Bush administration concluded that fixing this flaw was in the nation's "vital interest."

Fast forward to 2010, and very little has happened to improve the situation. The flaw still causes outages every year. Although most of the outages are innocent and fixed quickly, the problem still could be exploited by a hacker to spy on data traffic or take down websites.

Meanwhile, our reliance on the internet has only increased. The next outage, accidental or malicious, could disrupt businesses, the government or anyone who needs the internet to run normally.

The outages are caused by the somewhat haphazard way that traffic is passed between companies that carry internet data. The outages are called "hijackings," even though most of them are not caused by criminals bent on destruction. Instead the outages are a problem borne out of the open nature of the internet, a quality that also has stimulated the net's dazzling growth.

"It's ugly when you look under the cover," says Earl Zmijewski, a general manager at Renesys, which tracks the performance of internet data routes. "It amazes me every day when I get into work and find it's working."

When you send an email, view a web page or do anything else online, the information you read and transmit is handed from one carrier of internet data to another, sometimes in a long chain.

When you log into Facebook, your data might be handed from your internet service provider to a company such as Level 3 Communications, which operates a global network of fiber-optic lines that carry internet data across long distances. It, in turn, might pass the data to a carrier that's connected directly to Facebook's server computers.

The crux of the problem is that each carrier along the way figures out how to route the data based only on what the surrounding carriers in the chain say, rather than by looking at the whole path.

It's as if a driver had to get from Philadelphia to Pittsburgh without a map, navigating solely by traffic signs he encountered along the way - but the signs weren't put up by a central authority. If a sign pointed in the wrong direction, that driver would get lost.

That's essentially what happens when an internet route gets hijacked. Because carriers pass information between themselves about where data should go - and this system has no secure, automatic means of verifying that the routing information is correct - data can be routed to some carrier that isn't expecting the information. The carrier doesn't know what to do with it, and usually just drops it. It falls into a "black hole."

On April 25, 1997, millions of people in North America lost access to the entire internet for about an hour. The hijacking was caused by an employee misprogramming a router, a computer that directs data traffic, at a small internet service provider.

A similar incident happened elsewhere the next year, and the one after that. Routing errors also blocked internet access in different parts of the world, often for millions of people, in 2001, 2004, 2005, 2006, 2008 and 2009.

Last month a Chinese internet service provider halted access from around the world to a vast number of sites, including Dell.com and CNN.com, for about 20 minutes.

In 2008, Pakistan Telecom tried to comply with a government order to prevent access to YouTube from the country and intentionally "black-holed" requests for YouTube videos from Pakistani internet users.

But it also accidentally told the international carrier upstream from it that "I'm the best route to YouTube, so send all YouTube traffic to me."

The upstream carrier accepted the routing message, and passed it along to other carriers across the world, which started sending all requests for YouTube videos to Pakistan Telecom. Soon, even internet users in the US were deprived of videos of singing cats and skateboarding dogs for a few hours.

In 2004, the flaw was put to malicious use when someone got a computer in Malaysia to tell internet service providers that it was part of Yahoo. A flood of spam was sent out, appearing to come from Yahoo.

"Hijacking is very much like identity theft. Someone in the world claims to be you," said Todd Underwood, who worked for Renesys during the Pakistan Telecom hijacking. He now works for Google, trying to prevent hijacking of its websites, which include YouTube.

In 2003, the Bush administration's Critical Infrastructure Protection Board assembled a "National Strategy to Secure Cyberspace" that concluded that it was vital to fix the routing system and make sure the "traffic signs" always point in the right direction.

But unlike internet bugs that get discovered and fixed relatively quickly, the routing system has been unreformed for more than a decade. And while there's some progress being made, there's little industry-wide momentum behind efforts to introduce a permanent remedy.

Data carriers regard the fallibility of the routing system as the price to be paid for the internet's open, flexible structure. The simplicity of the routing system makes it easy for service providers to connect, a quality that has probably helped the explosive growth of the internet.

That growth has also increased the risks exponentially. Fifteen years ago, maybe 8,000 people in the world had access to computers that use the Border Gateway Protocol, or BGP, which defines how carriers pass routing information to each other.

Now, Danny McPherson, chief security officer at Arbor Networks, believes that with the growth of internet access across the world and the attendant increase in the number of carriers, that figure is probably closer to a million people.

Peiter Zatko, a member of the "hacker think tank" called the L0pht, told Congress in 1998 that he could use the BGP vulnerability to bring down the internet in half an hour.

In recent years, Zatko - who now works for the Pentagon's Defence Advanced Research Projects Agency - has said the exploit would still work. However, it would likely take a few hours rather than 30 minutes, partly because a greater number of internet carriers would need to be hit.

Plenty of solutions have been proposed in the internet engineering community, going back as far as 1995. The US government has supported these efforts, spurred in part by the Bush administration's 2003 strategy statement. That has resulted in some trials of new technology, but adoption by data carriers still appears distant. And the federal government doesn't have any direct authority to force changes.

One reason is that the weaknesses in the system are in the routing between carriers. It doesn't help if one carrier introduces a new system - every one it connects with has to make the change as well.

"It's kind of everybody's problem, because it impacts the stability of the internet, but at the same time it's nobody's problem because nobody owns it," says Doug Maughan, who deals with the issue at the Department of Homeland Security.

The big internet carriers seem willing to accept the status quo. Spokesmen at AT&T and Verizon Communications, two of the largest, world-spanning carriers of internet traffic, said they were unable to find anyone at their companies who could discuss the issue of routing reform.

Pieter Poll, the chief technology officer at Qwest Communications International Inc., says that he would support some simple mechanisms to validate data routes, but he argues that fundamental reform isn't necessary. Hijackings are typically corrected quickly enough that they don't pose a major threat, he argues.

One fix being tested would stop short of making the routing system fully secure but would at least verify part of it. Yet this system also worries carriers because they would have to work through a central database.

"My fear is that innovation on the internet would slow down if there's a need to go through a central authority," Poll says. "I see little appetite for that in the industry."

Jeffrey Hunker, a former senior director for critical infrastructure in the Clinton administration, says he's not surprised that little has happened on the issue since 2003. He doesn't expect much to happen in the next seven years, either.

"The only thing that's going to drive adoption is a major incident, which we haven't had yet," he says. "But there's plenty of evidence out there that a major incident would be possible."

In the meantime, network administrators deal with hijacking an old-fashioned way: calling their counterparts close to where the hijacking is happening to get them to manually change data routes.

Because emails may not arrive if a route has been hijacked, the phone is a more reliable option, says Tom Daly, chief technical officer of Dynamic Network Services, which provides web hosting and other internet services.

"You make some phone calls and hope and pray," Daly says. "That's about it."

- AP

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Technology

Premium
Business|personal finance

Surge in new vehicle sales: Industry insiders explain three factors behind spike

04 Jul 05:00 AM
Premium
World

No one likes meetings. They’re sending their AI note-takers instead

03 Jul 07:00 PM
Premium
Business

Cloudflare introduces default blocking of AI data scrapers

03 Jul 02:59 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.
Recommended for you
The nearly fatal gas exposure case that rocked Greymouth
New Zealand

The nearly fatal gas exposure case that rocked Greymouth

04 Jul 06:03 AM
'It's all safe mum': Murder accused allegedly took $85k hidden in mother's dressing gown
Crime

'It's all safe mum': Murder accused allegedly took $85k hidden in mother's dressing gown

04 Jul 06:00 AM
Four prolific shoplifters charged with stealing groceries worth $17,000
New Zealand

Four prolific shoplifters charged with stealing groceries worth $17,000

04 Jul 05:58 AM
'You can’t hide': Police seize GBL, cannabis, pills in Waikato online drug bust
Crime

'You can’t hide': Police seize GBL, cannabis, pills in Waikato online drug bust

04 Jul 05:05 AM
Philip Polkinghorne: Real estate sign vandalised with 'Killer'
Auckland

Philip Polkinghorne: Real estate sign vandalised with 'Killer'

04 Jul 05:00 AM

Latest from Technology

Premium
Surge in new vehicle sales: Industry insiders explain three factors behind spike

Surge in new vehicle sales: Industry insiders explain three factors behind spike

04 Jul 05:00 AM

Tesla and BYD fight it out in a resurgent EV market.

Premium
No one likes meetings. They’re sending their AI note-takers instead

No one likes meetings. They’re sending their AI note-takers instead

03 Jul 07:00 PM
Premium
Cloudflare introduces default blocking of AI data scrapers

Cloudflare introduces default blocking of AI data scrapers

03 Jul 02:59 AM
NZ taxpayer-funded $29m satellite likely lost in space

NZ taxpayer-funded $29m satellite likely lost in space

01 Jul 10:26 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP
search by queryly Advanced Search