Facebook Traffic Routed Through China

A number of Facebook users may have made a detour to China recently on their way to connect with friends.

Some of the network traffic heading to Facebook’s servers in Palo Alto, California was re-routed to first pass through Chinese and Korean servers, according to Barrett Lyon, a network security expert who flagged the incident on 22 March. Lyon suggested in a blog post that it was probably an accident.

‘Internet not a trusted network’

“This happens all the time – the Internet is just not a trusted network,” Lyon said.

Image from Algy3289 on on Wikimedia

A similar incident surfaced almost exactly a year ago on 8 April, 2010, when a Chinese ISP incorrectly published a set of BGP (Border Gateway Protocol) instructions that could have potentially affected 37,000 networks. The incident lasted only 18 minutes, and China Telecom, the country’s largest ISP, denied trying to hijack Internet traffic. Experts speculated it was an accident because of how quickly it was fixed.

Lyon’s analysis was for AT&T customers only. As customers browsed through Facebook, the network traffic first went to Chinanet, one of the largest ISPs in China, and then to SK Broadband in South Korea, before reaching Facebook’s ISP, Lyon said. Usually, traffic from these customers would have gone over the AT&T network directly to Facebook’s network provider.

Lyon used the trace-route tool to discover which network providers the traffic hopped through on its way to Facebook. It’s unclear how long this routing was in place, or whether it affected other ISPs.

While this kind of re-routing can happen “all the time” as network operators can easily make mistakes working with BGP and routing tables, Lyon was still concerned about the incident in light of China’s censorship activities.

“I prefer to know that when I am on AT&T’s network, going to US-located sites, my packets are not accidentally leaving the country and being subject to another nation’s policies.”

China aggressively censors the Internet and activists have worried about the government snooping on their citizens’ online activities. As the government exercises tremendous control over the ISPs, the government can see personal information, intercept email and view online activity.

“What could have happened with your data?” Lyon wrote. “Most likely absolutely nothing.”

Lyon said that “it’s possible” Facebook data, such as session ID information, personal data, messages, photos, chat conversations, and relationship information to “friends” could have been revealed, but noted it was only speculation at this time.

Encryption optional

Users who have already enabled HTTPS on their Facebook accounts can breathe a little easily, as their information would have been encrypted during this side jaunt through China. The Secure Sockets Layer means Chinanet could see there was traffic going to Facebook, but would not be able to see the contents of the traffic. Lyon criticised Facebook for rolling this feature out as an optional one, instead of enabling it for all users by default.

Twitter also recently rolled out HTTPS, but it’s also optional. Google uses it by default for its mail.

High-profile sites should also not be allowed to route to non-authenticated networks, he said.

Facebook or AT&T should have notified customers of the problem, Lyon said. Facebook did not respond to requests for comment.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Share
Published by
Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

14 hours ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

15 hours ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

16 hours ago

VW, Rivian Launch Joint Venture, As Investment Rises To $5.8 Billion

Volkswagen and Rivian officially launch their joint venture, as German car giant ups investment to…

17 hours ago

AMD Axes 4 Percent Of Staff, Amid AI Chip Focus

Merry Christmas staff. AMD hands marching orders to 1,000 employees in the led up to…

20 hours ago

Tesla Recalls 2,431 Cybertrucks Over Propulsion Issue

Recall number six in 2024 for Tesla Cybertruck, and this time the fault cannot be…

21 hours ago