Friday, 9 October 2026

Protocol Downgrades

Protocol downgrades, also known as downgrade attacks, bidding down attacks and rollback attacks, is when a computer system is coaxed into abandoning a high quality mode of operation in favour of a lower quality mode of operation.

A historical example was a flaw in OpenSSL that enabled an attacker to use a lower version of TLS between client and server.

What is HSTS?

HSTS is HTTP Strict Transport Security. This is a web security policy defined under RFC6797 forcing browsers to use HTTPS only. This protects users from attacks like protocol-downgrade and cookie hijacking.

Sunday, 4 October 2026

Internet Gateways (IGWs) In Depth

All WinJoes know what an internet gateway is. Many affectionally refer to these as IGWs. But few know what these gateways do in amazing depth.

We aim to bridge that gap and confer, dare we say it, in-depth knowledge. We educate the new generation of "gateway gurus", or "IGW gurus".

So one question for you - NAT. How do IGWs interact with NATs - if at all? Does this differ in AWS versus other clouds? Exercise for the reader.

Subnets are Routing Boundaries not Security Boundaries

AWS, as well as other cloud providers, use subnets to partition virtual networks (e.g. in AWS VPC - Virtual Private Cloud).  

These subnets divide up the IP address space into separate compartments for routing traffic.

In AWS, another way of saying this is "each subnet is a slice of your VPC's CIDR block".

Each subnet block in AWS is tied to a particular AZ, or Availability Zone. Subnets cannot span AZs and this preserves the availability pattern (e.g. one private subnet per AZ).

There are many types of subnet in AWS.  Examples are:
  • Public subnet - subnet has a direct route to an internet gateway. Resources in the public subnet can access the public internet.
  • Private subnet - subnet has NO direct route to an internet gateway. Resources in the subnet require a NAT device to access the public internet
  • VPN-only subnet - the subnet has a route to a Site-to-Site VPN connection through virtual private gateway. The subnet has no route to an internet gateway
  • Isolated subnet - not connected to the internet - in fact, no routes to destination outside its VPC
  • EVS subnet - a type of subnet created by Amazon EVS (very specific to VMware)
(Sidebar: internet gateway - bridge ("network bridge","network component")  between private network and the internet,enabling traffic routing, protocol translation, NAT, DHCP and security filtering)


Choosing Network Size in AWS - Forward Slash Notation

Network size (in terms of IP address ranges) in AWS is specified using CIDR notation. 

(Sidenote: CIDR stands for classless interdomain routing, which replaced the now obsolete classful networking architecture which prevailed from 1981 to 1993, when CIDR was introduced.  If you are interested in the classful system have a look at RFC 791 which covers IP and describe the class system).

Example:

192.162.1.0/24

The forward slash 24 means the first 24 bits are fixed.  The rest (i.e. last 8 bits) are flexible.

From the AWS documentation: 

"When working with networks in the AWS Cloud, you choose your network size by using CIDR notation. In AWS, the smallest IP range you can have is /28, which provides 16 IP addresses (2^4). The largest IP range you can have is a /16, which provides 65,536 IP addresses (2^16)."

AWS Global Infrastructure and Services

AWS Regions and Availability Zones

AWS Service Endpoints

AWS Services by Region

Python secrets module

The secrets module in Python is used to generate cryptographically strong random numbers.

This should be used in preference to the random module, for modeling and simulation, not cryptography.

The background -

Random numbers are used in cryptographic applications e.g. in key generation, initialization vectors and nonces, and salts in certain signature schemes.

One-time pads also require a truly random source.