Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Doug Madory

@dougmadory@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Internet analysis at Kentik

382 Followers
73 Following
32 Posts
Joined February 02, 2023
LinkedIn:
https://www.linkedin.com/in/dougmadory/
Blog posts:
https://www.kentik.com/blog/author/doug-madory/
Wikipedia:
https://en.wikipedia.org/wiki/Doug_Madory
Twitter:
https://twitter.com/DougMadory
Open post
Doug Madory @dougmadory@infosec.exchange
· 2mo ago
At 06:05 UTC on Jul-27, DDoS mitigation service Voxility (AS3223) leaked over 30k BGP prefixes to its transit provider Lumen (AS3356) for up to 40 minutes causing traffic to affected prefixes to be disrupted or misdirected. Same thing happened last year: https://www.kentik.com/blog/beyond-their-intended-scope-ddos-mitigation-leak/
Kentik

Beyond Their Intended Scope: DDoS Mitigation Leak | Kentik Blog

6
1
4
2
Open post
Doug Madory @dougmadory@infosec.exchange
· 5mo ago

Iran’s Internet Blackout: Peering into The World’s Worst Internet Shutdown

Some are calling it Digital Apartheid. Our latest post uses traffic data to show how expanded whitelisting is reshaping internet access in Iran.

https://www.kentik.com/blog/irans-internet-blackout-peering-into-the-worlds-worst-internet-shutdown/

kentik.com
6
0
4
1
Open post
Doug Madory @dougmadory@infosec.exchange
· 7mo ago

On Feb-4, Starlink disabled terminals in Russian-occupied parts of Ukraine that weren't on Ukrainian Ministry of Defense's approved list.

We saw a 75% drop in Starlink traffic to Ukraine as a result. 🤯

https://www.politico.com/news/2026/02/25/elon-musk-russian-army-starlink-00793742

politico.com
6
2
2
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 5mo ago

Internet shutdown in Iran is in its 46th day.👀

While only a fraction of normal traffic levels, the volume of whitelisted traffic has been slowly growing in the past month as the IR govt expands its program of selectively authorizing access to certain individuals and companies.

4
0
3
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 7mo ago

BGP routes belonging to the network of the Islamic Republic of Iran Broadcasting (AS42586) were completely down between ~17:00 UTC on Mar-1 and ~10:00 UTC on Mar-2.

Pings (blue line) was already down due to the shutdown. The BGP outage (green line) might be indicative of technical failure (fiber cut, power outage) or cyberattack.

See @IODA@mastodon.social view:
https://ioda.inetintel.cc.gatech.edu/asn/42586?from=1771874802&until=1772479602&view=view1

https://themedialine.org/top-stories/broadcast-disruptions-spread-after-strikes-and-satellite-hijacking-of-iranian-channels/

ioda.inetintel.cc.gatech.edu
4
0
6
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

Iran is currently enduring its longest-ever internet shutdown, which began shortly after the Feb-28 airstrikes.

My latest post covers all of 2026, outages within the whitelisted traffic, and other observations from our data. #DigitalBlackOutIran‌

https://www.kentik.com/blog/internet-and-airstrikes-tracking-irans-extended-communication-blackout/

infosec.exchange
3
0
3
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 8mo ago

Iran's shutdown is now 15 days and counting. Small amounts of service have been restored in recent days.
#DigitalBlackoutIran #IranRevoIution2026

State telecom TIC (A49666) re-established many of its lost connections with outside providers, such as GBI (AS200612) at 22:02 UTC on Jan-22.

infosec.exchange
4
0
6
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 5mo ago

In my latest post for @kentikinc@bird.makeup , I introduce the concept of ephemeral leaks, short-lived routing anomalies that appear briefly during #BGP convergence and fill the output of public leak detection tools like @cloudflareradar@noc.social and its predecessors.

https://www.kentik.com/blog/ephemeral-leaks-and-automated-bgp-route-leak-detection/

infosec.exchange
2
0
2
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

A recent target of airstrikes, Sharif University of Technology (AS12660) went offline at 23:12 UTC (2:42am local) today.

https://apnews.com/video/ict-building-at-tehrans-sharif-university-of-technology-reduced-to-rubble-after-more-us-israeli-strikes-b9a5dcd64f444ad193f8b68dd08b9be7

@IODA@mastodon.social view:
https://ioda.inetintel.cc.gatech.edu/asn/12660-IR?from=1775395741&until=1775482141

apnews.com
2
0
3
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

James Cowie on the Geopolitics of Internet Infrastructure

Recently came across this old talk (Nov 2011) at Harvard by @jimcowie@social.secret-wg.org, a mentor of mine and pioneer in exploring the intersection of internet measurement and geopolitics.

Check it out here:
https://www.youtube.com/watch?v=xx13GO2kJU0

2
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago
Replying to
Some of the traffic lost on Mar-15 was recovered on Mar-18.
2
0
1
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 5mo ago
Replying to
See my analysis of the rise of whitelisted traffic during Iran's shutdown here: https://www.kentik.com/blog/irans-internet-blackout-peering-into-the-worlds-worst-internet-shutdown/
kentik.com
1
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

I spoke with AL-Monitor for their story on the ongoing internet shutdown in Iran:

https://www.al-monitor.com/originals/2026/03/irans-longest-ever-internet-blackout-leaves-99-offline-what-know?gift_code=KDCGAnTkNQvme2XZ-qSaj1RY3s4

al-monitor.com
1
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

Another internet outage in Iran at 12:00 UTC further reduced the small amount of traffic being let out of the country. #IranUSWar #DigitalBlackOutIran‌

Numerous networks impacted.

infosec.exchange
1
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago
Replying to
Continuing nationwide power outage in #Cuba is resulting in reduced internet traffic volumes as residents cannot get online. Outage began at 17:40 UTC (1:40pm local) on Mar-16.
0
0
2
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago
Replying to
kentik.com
0
0
1
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 2mo ago
Replying to
It was inevitable that a massive deployment of ROAs like this would create RPKI-invalid due to mismatches on maxlen, causing routes to be withdrawn. Here's one example out of over 600 that I found: https://bgp.tools/rpki-history?cidr=103.151.148.0%2f23&asn=4808
bgp.tools
0
1
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 2mo ago
Replying to
New Chinese AS0 ROAs knocked out a few routes originated by Windstream (ex: 118.188.144.0/21) 🤔 https://bgp.tools/rpki-history?cidr=118.188.128.0%2F17&asn=
bgp.tools
0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 1mo ago
Replying to
Update to the original analysis: https://www.kentik.com/blog/from-ukraine-to-the-cloud-stories-of-ipv4-migration/
kentik.com
0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 1w ago
Replying to
Wave 2 (03:52 UTC on Sep-27): Affected networks: AS​​199995, AS43668, AS48648, AS28858, AS43743, AS51124, AS35689, AS41645, AS44820 and several more. https://ioda.inetintel.cc.gatech.edu/asn/199995?from=1790011111&until=1790615911&view=view1
IODA
ioda.inetintel.cc.gatech.edu

IODA

IODA (Internet Outage Detection and Analysis) monitors Internet infrastructure connectivity to identify outages.

0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 6mo ago

ICYMI: In December, I published a long-form piece based on the firsthand experiences of a Syria Telecom insider during the height of the civil war.

Only after the fall of Bashar al-Assad in December 2024 did this senior telecom engineer feel safe enough to tell his remarkable story.

Read it here:
https://syriauntold.com/2025/12/27/keeping-syria-connected-during-war/

syriauntold.com
0
0
3
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 7mo ago
Replying to
@dbelson @cloudflareradar wow fascinating
0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 2mo ago
Latest chart for traffic to Iran since December 2025. After two shutdowns, traffic levels have not returned to pre-Jan-8 levels, and is unlikely to do so in the foreseeable future. #DigitalBlackOutIran‌
0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 1mo ago
Taking a look at this BGP hijack of 162.55.80.0/24 that targeted Virtualizor in recent days. Hijackers forged the origin to make the route RPKI-valid: ... 6204 62390 24940 (hijack AS path) ... 24940 (legit AS path) More from the victim here: https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
virtualizor.com

Security Incident – BGP Hijacking – Virtualizor

0
0
0
0
Open post
Doug Madory @dougmadory@infosec.exchange
· 2mo ago
Replying to
@petrillic@hachyderm.io A "maximum-prefix limit" might also have been helpful. The Voxility AS-SET is pretty broad unfortunately. The fact that this is the second time this leak went only through AS3356, implies there is something the other transits are doing to block these leaks when the happen. https://bgp.tools/as-set/RADB::as-voxility-set
bgp.tools
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:08:21 UTC