HeadlinesBriefing favicon HeadlinesBriefing.com

Telnet Traffic Claims Debunked

Hacker News: Front Page •
×

Contrary to recent reports claiming Telnet's demise, Terrace research shows no evidence that core network providers blocked the protocol after a GNU Inetutils CVE announcement. While GreyNoise reported a dramatic drop from 74,000 to 11,000 Telnet sessions, Terrace found continued traffic from networks supposedly affected by this supposed blocking.

Terrance researchers cross-checked GreyNoise data against their own network sensors, RIPE Atlas measurements, and open threat data. They successfully performed Telnet traceroutes from 55 of 56 reportedly-affected autonomous systems, confirming no widespread filtering of port 23 traffic. Their analysis shows January 14 was actually part of a relative spike in Telnet scanning activity.

The methodology discrepancy likely stems from counting total sessions rather than unique network endpoints. A single coordinated actor or small group of IPs could generate thousands of sessions, creating artificial trends. Researchers suspect threat actors may have fingerprinted GreyNoise's detection apparatus and specifically avoided it, rather than reflecting actual network filtering.