Networks
Routing, naming, certificates and segmentation. The plumbing attackers move through.
57 sketches
DDoSSomething finite runs out
DNSThe sign, not the building
DNS tunnellingEveryone waves it through
NACThe question moved, not the answer
TLSOne of you shows a name
VPNsIt protects the road, not the ends
Wi-Fi evil twinsTwo signs, one name
Air gapsThe gap only stops the wire
Certificate validationPrivate, with whoever turned up
East-west trafficOne gate in, none between
FirewallsIt checks the ticket, not the errand
Lateral movementSideways, on borrowed trust
Man-in-the-middleBoth ends think the line is direct
MicrosegmentationA door between every pair
Network monitoringThe envelope, not the letter
Remote accessA room at a time, every time
SegmentationHow far the fall goes
'VPN means secure'The tunnel ends first
'air gaps cannot be hacked'The wire stops
DNS is a directory, not proof of safetyIt only answers where
DNSSEC signs answers but does not hide themA sealed postcard
Encrypted DNS protects the resolver path, not the destinationCovered to the desk, open to the door
Registrar compromise can outrank server securityIt all hangs from one fitting
Registrar locks add friction to domain theftThe pin that makes them stop
Dangling DNS can point to somebody else's resourceYour plate, their locker
Subdomain takeover begins with abandoned ownershipNobody minding the stall
Split-horizon DNS gives different users different mapsTwo maps of the same building
CAA narrows who may issue certificatesThe name names its signers
Certificate transparency makes issuance observableEvery certificate leaves a receipt
BGP announces reachability, not truthA claim, not a proof
BGP hijacking can redirect traffic before applications see itThe points move under the train
Route leaks can be accidental and disruptiveThe whole motorway down a side lane
RPKI validates route origins, not the whole pathOnly the first pair of hands is signed for
More specific Internet routes usually winThe narrower claim takes it
Anycast sends one address to multiple placesOne address, many doorsteps
Route filtering is Internet hygieneWe all drink from the same main
Internet paths can change without applications changingSame two ends, different wires
Control-plane attacks can break data-plane assumptionsThe train is fine. The points moved
TLS encrypts a connection, not endpoint intentionsA sealed pipe to a stranger
Certificates bind keys to names through trust chainsHeld together by a chain of seals
Certificate expiry creates operational pressureEvery one of them runs out
Private-key compromise survives a valid certificateThe certificate is fine
HSTS removes the insecure choice after a browser has learned the policy, while preload can protect the first visit tooThe turning that stops existing
OCSP stapling moves status evidence closerThe proof comes stapled on
Mutual TLS authenticates both endsBoth of you show papers
TLS termination moves the trust boundaryThe seal ends here, not there
Certificate pinning trades flexibility for tighter expectationsA slot cut for one shape
PKI can fail operationally while cryptography is soundThe maths was never the problem
Segmentation limits paths, not compromise itselfBulkheads, not armour
Every firewall allow rule creates a permitted pathEvery rule is a hole
Flat networks turn local trust into broad reachabilityOne floor, no walls
Microsegmentation moves boundaries closer to workloadsMove the fence inwards
Management paths can bypass segmentationOver the checkpoint
Default deny makes new paths deliberateNothing moves until a lever is pulled
Network zones should reflect trust and functionZones follow the job
Segmentation needs tested failure behaviourPull the plug and watch
Encrypted traffic still needs network policySealed, and still checked
