Skip to content

Is it normal for my upstream's upstream to email me directly?

Networking by Carl 24 replies 2.6K views
#11

Good point. The email said "before escalating to NOC" which implies the NOC is separate and higher. But if they were really upstream ops, wouldn't they already be NOC?

6 #12

Correct. "Upstream operations" wanting to "escalate to NOC" is organizational nonsense. Operations *is* NOC in most Tier 2 structures, or at least sits adjacent. The phrasing treats NOC as a distant authority, which is how victims imagine it, not how it works.

mitigated 800Gbps before breakfast
#13

Following. Had a similar email last month but ignored it. Nothing happened. Maybe I got lucky, maybe they moved to easier targets.

#14

Same here. Ignored, nothing happened.

#15

In Italy we have legal requirement for certified email (PEC) for formal abuse notifications. Any email not PEC is not legally valid escalation. Makes filtering these trivial. Is there no equivalent in Ireland?

1 #16

No PEC equivalent for technical abuse. Commercial law has some registered email schemes but nothing binding on network operations.

8 #17

Chicago perspective: my upstream (Cogent reseller) has never contacted me directly for anything. All abuse goes through the reseller. The one time I got a "network security" email direct to my WHOIS address, it was Cloudflare wanting me to switch to their enterprise plan. At least that was honest sales.

visit twice: install and decom
5 #18

For my association in Lyon we have OVH. They send abuse from @ovh.net, never from some "upstream." The idea of upstream's upstream contacting me directly is strange. OVH is big, maybe different for small regional?

prix fixe infrastructure: €5/mo
#19

Seoul datacenter scene: LG U+ and KT both go through your colo contract. Never direct. The only direct emails I get are from KISA (government) for national infrastructure alerts, and they use .go.kr with full certificate chains.

one small ping for man...
#20

I wrote a script to check the domain against Certificate Transparency logs — https://crt.sh. Zero certificates. Three week old domain, no TLS history, no subdomains in censys. Real network ops at least have a portal cert, usually mail encryption. The infrastructure footprint is null.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft