nanog mailing list archives

RE: 600,000 routers bricked


From: Robert Jacobs <rjacobs () pslightwave com>
Date: Mon, 3 Jun 2024 18:22:42 +0000

If you do a bit more digging the ISP is not Lumen ... It is a well known ISP and I recall reading about this outage 
when it happened.  I don’t know if indeed this was a botched attempt to gather a bot network or like some said an 
intentional act to get attention.



Robert Jacobs | Data Center Manager
Direct: 832-615-7742
Main: 832-615-8000
Fax: 713-510-1650
5959 Corporate Dr. Suite 3300; Houston, TX 77036
A Certified Woman-Owned Business
24x7x365 Customer Support: 832-615-8000 | support () pslightwave com

​This electronic message contains information from PS Lightwave which may be privileged and confidential. The 
information is intended to be for the use of individual(s) or entity named above. If you are not the intended 
recipient, any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have 
received this electronic message in error, please notify me by telephone or e-mail immediately.
-----Original Message-----
From: NANOG <nanog-bounces+rjacobs=pslightwave.com () nanog org> On Behalf Of Christopher Morrow
Sent: Monday, June 3, 2024 1:04 PM
To: Matt Erculiani <merculiani () gmail com>
Cc: NANOG <nanog () nanog org>
Subject: Re: 600,000 routers bricked

CAUTION: External Email. Do not click links or open attachments unless you recognize the sender and know the content is 
safe.


On Mon, Jun 3, 2024 at 1:40 PM Matt Erculiani <merculiani () gmail com> wrote:

It's important to note though that if you quietly (or even publicly) patch 600k devices to fix a bug, nobody cares. 
Plus, doing so is still a crime: it's 600k instances of accessing a computer system without permission. It's also 
far, FAR easier to write a stream of 0s to the bootloader than it is to decompile and debug bad firmware.


Lumen USED TO HAVE a walled-garden they dropped people into when their links/network ran amok.. at least in 
legacy-qwest/century-link consumer connectivity situations.
maybe that's gone now?
maybe the part of the affected network for this incident didn't have that capability?

Current thread: