13/11/2018
Internet 'hijack' sees Google traffic misdirected through China and Russia in possible war-game experiment.
Large parts of the internet went down for more than an hour on Monday after a strange incident meant web traffic was rerouted through China and Russia.
Google said that its search engine, as well as apps like Spotify that rely on its services, stopped working because of the major mishap.
Researchers from the network-intelligence company ThousandEyes said the misdirected traffic was particularly concerning given the list of countries that sensitive data was passing through.
The incident "put valuable Google traffic in the hands of ISPs in countries with a long history of internet surveillance," ThousandEyes researcher Ameet Naik wrote in a blog post.
The traffic misdirection, known as a border gateway protocol (BGP) hijacking, lasted for around an hour and a half on Monday evening, ending at around 10.30pm GMT.
"[It] further underscores one of the fundamental weaknesses in the fabric of the internet," Mr Naik wrote. "Even corporations like Google with massive resources at their disposal are not immune from such BGP hijacks and leaks."
ThousandEyes executive Alex Henthorn-Iwane said it was the worst incident affecting Google traffic that his firm had ever seen. He also speculated that the hijacking may have been the result of "a war-game experiment."
The incident was particularly suspicious because internet traffic was being sent to the Chinese government’s internet provider, China Telecom, which has previously been accused of improperly routing traffic through China.
A report earlier this year by researchers at the US Naval War College and the Tel Aviv University found China Telecom has been hijacking internet traffic passing through the US and Canada on a regular basis.
"Conveniently, China Telecom has ten strategically placed, Chinese controlled internet ‘points of presence’4 (PoPs) across the internet backbone of North America," the report stated.
"Vast rewards can be reaped from the hijacking, diverting, and then copying of information-rich traffic going into or crossing the United States and Canada – often unnoticed and then delivered with only small delays."
Support free-thinking journalism and subscribe to Independent Minds
A Google spokesperson told The Independent: “We’re aware that a portion of internet traffic was affected by incorrect routing of IP addresses, and access to some Google services was impacted. The root cause of the issue was external to Google and there was no compromise of Google services.”
In an update to its Google Cloud Status Dashboard, Google said it was conducting an internal investigation in the hope of making "appropriate improvements" to help prevent a future recurrence of the issue.