ISC StormCast for Tuesday, October 5th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 October 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, October 5, 2021 edition of the Sands and the Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich. |
| 0:09.6 | And I'm recording from Jacksonville, Florida. |
| 0:14.5 | Big story today, of course, was Facebook's outage. |
| 0:18.0 | And while, of course, it's not necessarily sort of a security event that |
| 0:22.9 | affects many of us, has made the news big time. So I figured I'll talk a little bit about |
| 0:28.5 | what we know has happened at this point. As I'm recording this, Facebook is a backup now for |
| 0:37.4 | about half an hour or an hour after being down for |
| 0:41.0 | approximately five and a half or six hours. There is no official statement yet from Facebook |
| 0:47.7 | as to what happened, but Brian Kreps is reporting and he usually is right about these things that the root cause was a BGP update that apparently went wrong. |
| 1:02.5 | Now initially, a lot of reports suggest that it's a DNS problem. |
| 1:07.4 | And of course, DNS is a common culprit for issues like this, and DNS certainly had |
| 1:14.3 | issues, but DNS was only down because, well, there was a BGP, a routing problem. At approximately |
| 1:22.6 | 1130 Eastern or 1530 UTC, the Facebook IP address prefixes were withdrawn from Global Routing |
| 1:33.1 | Table, pretty much bringing down anything Facebook related. |
| 1:36.7 | So Facebook, Instagram, as well as WhatsApp, were not reachable because while the Internet |
| 1:43.4 | no longer knew how to reach the respective |
| 1:46.5 | IP addresses. And with that, of course, Facebook DNS servers were also not reachable, |
| 1:52.7 | and that's why it sort of manifested itself as a DNS problem initially. What prolonged the |
| 1:59.9 | outage was that the BGP update not only removed access |
| 2:05.2 | from the outside to Facebook, but also router administrators were no longer able to actually |
| 2:12.1 | reach affected routers in order to fix the problem that the initial bad update caused. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

