Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Man, you really got lucky they didn’t throw you in jail. Anything related to national defense is pretty scary. Do you think you might get some kind of reward for exposing this vulnerability?
  • The NCSC does give out challenge coins for particularly good reports. I feel like if you get one of those, that will be 10 euros well spent.
  • It's funny how such holes can remain for years, and no one notices until someone stumbles upon them. It's interesting that no serious organization wanted to address the issue until it was discovered that the military was involved.

    It's a shame the author wasn't rewarded but at least the story can now be told over a beer.

  • Their homepage, https://lina.sh/, reminds me of the early days of the internet. Are webrings back in fashion? Or is this just a group of old school folks keeping the nostalgia alive?
    by bcx
  • I enjoyed reading this much more than anything I read here recently. In particular I like how it absolutely shows that somethings just… fall through the cracks!
    by dkga
  • It is a shame they did not actually set up a SIP server and see if any of those requests turned into actual call terminations.

    There is another schema called TRIP [1] - telephony routing over ip that uses a number format "1234*1455" designed to be entered on a standard phone keypad. When I registered my ITAD (internet telephony administrative domain, the RHS of a TRIP number) I was lucky enough to get one that matches my local dialling code!

    https://tripresurgence.org/trip/history/ [1]

  • It's a shame that ENUM didn't really go anywhere, but I suppose ultimately many stakeholders consider the phone network being administratively separate from the Internet a feature, not a bug, even though it's now largely an overlay network on top of the Internet itself in its modern form (NGN).

    As far as I remember, the Austrian telco regulator was particularly SIP-forward in the early 2000s, and there was a prefix dedicated exclusively to ENUM-based services back in the day.

    Unlike its sibling VoIP prefix, which was terminated the "usual PSTN way" by operators that would then bridge to SIP or whatever internally, the idea of the "ENUM first" prefix was that you'd register a number with some registrar and then make it resolve to your SIP client (via a proxy/service provider or directly to any publicly reachable IP address). Reachability from the PSTN was provided via gateways that would translate from circuit switched voice to SIP/RTP, so effectively you could really be reachable for incoming calls independently of any telco.

    Unfortunately, as far as I remember both the VoIP and the ENUM prefix ended up being prohibitively expensive to call from many plans (they were billed at higher rates than both landlines and cellphones from many carriers and not included in any flat rate plans).

    Still, together with native SIP and Wi-Fi support in many early smartphones at the time, it felt like standards-based Internet telephony was just around the corner, which of course didn't quite play out, and we ended up with the fragmented OTT landscape of today instead that only uses phone numbers as user identifiers, with a per-service privately managed directory instead of a DNS-based one.

    by lxgr
  • > It never really took off though, and even back in its early days it saw barely any use. Over the years it just deteriorated further, and today it's basically completely dead.

    It's actually not completely dead... It's just (almost) completely non-public.

    You can subscribe to services to get number porting information where the interface is basically e164.arpa/ENUM queries to a private nameserver over a VPN. I don't know the details, the cost was high enough that it didn't make sense for my employer to pursue it.

Explore Birbla archives

I accidentally logged phone calls to military bases · Birbla