6 ms·
BGP operators _have_ self-organized sufficient security measures. Compared to just about any other attack vector on the internet, BGP hijacking is among the le
by ozr 2y ago
BGP operators _have_ self-organized sufficient security measures. Compared to just about any other attack vector on the internet, BGP hijacking is among the least likely to impact most people.
- ronsor 2y agoThis is very true. Personally I would be more concerned about SS7 attacks.
- anilakar 2y agoThe SS7 telephone signaling network is regulated here because telcos could not be arsed to implement security measures themselves.
- sambazi 2y agoafaik there is filtering of 'announcements' in ss7 similar to manrs/rpki
- karma_pharmer 2y agoWith cryptography? I doubt it. Not the same thing as RPKI.
- immibis 2y agoWhat does the cryptography add? RIRs publish who owns which prefixes, and sign this list. If you're America worried about foreign countries hijacking BGP, you can ignore announcements received from overseas about prefixes that are owned by American actors, unless they add a record indicating they expect to deploy them overseas. You don't need any additional cryptography for this, or any protocol change.
- coretx 2y agoPolitical routing is a faux pas. Also, not the state(s) is/are a authority. The RIR's are. They operate a realm, and nation state and/or individual interests don't end at a border. The realm doesn't even have them. Never the less, you are right about the need for more information being shared although it's hard to oversee what new security issues that may introduce.
- immibis 2y agoYou might think the state is not an authority, but everyone else who thought that got jailed by the state, so it seems to be the case that it is one. If the state and some protocol disagree, and the state has the power to imprison people using the protocol if they don't cooperate to subvert it (something like this happened to Ethereum IIRC), the protocol has to just deal with it.
- coretx 2y agoStates often delegate some of their authority to other institutions. As is the case when it comes to internet governance. Look at the ITU/UN https://en.wikipedia.org/wiki/Multistakeholder_governance https://en.wikipedia.org/wiki/Multistakeholder_governance for example. It's outright crazy to see US diplomats work their ass off globally only to see some lower institution ( The FCC ) with less intelligence, capabilities, etc. undermine their work and formal US geopolitical grand strategy & policy. Or it's all just a ruse, and the joke is on us.
- immibis 2y agoThey can add rules or un-delegate it at any time.
- karma_pharmer 2y agoAnd yet SS7 still has no cryptographic security measures.
- sambazi 2y agocould you elaborate on why would you ascribe different impact to this seemingly similar problem?
- awaythrow999 2y agoThreat models matter. If you're defending against nation state actors in a military/cyber context it is an essential part of the overall defense strategy. Ignoring BGP on the grounds that "it was always insecure" is then just weird, if not reckless. The SCION project (Iirc from ZTH) solved all of this and also has been extensively tried in the field.
- kaliszad 2y agoIf you are defending against a nation state, you should be worried about your staff being bribed, otherwise coerced or worse just being foreign agents. In properly run networks, BGP hijacks shouldn't have a noticeable impact.
- alephnerd 2y ago> In properly run networks, BGP hijacks shouldn't have a noticeable impact Bullshirt. Even AWS Route53 has fallen victim to BGP hijacking. It takes 1 mistake for SHTF
- ta1243 2y ago> you should be worried about your staff being bribed, otherwise coerced or worse just being foreign agents This is it, find a senior network operator, pick up their kids from school, and take them home. You now have an agent with full access over that network.
- hanszarkov 2y agoBut what I do have are a very particular set of skills, skills I have acquired over a very long career. Skills that make me a nightmare for people like you
- mschuster91 2y ago> Compared to just about any other attack vector on the internet, BGP hijacking is among the least likely to impact most people. But when it happens, it impacts massive amounts of people - about once a year on average [1]. Sometimes it's censorship gone bonkers, sometimes it's likely a three-letter agency, sometimes it's fat fingers, and sometimes it's cybercriminals attempting to loot cryptocurrency wallets. [1] https://en.wikipedia.org/wiki/BGP_hijacking https://en.wikipedia.org/wiki/BGP_hijacking
- phicoh 2y agoBGP hijacking also works on a small scale. If you don't use DNSSEC and somebody hijacks the prefix(es) that host your DNS, they can obtain a letsencrypt certificate and redirect all your traffic. If you don't have a CAA record and somebody hijacks the prefix(es) where your webserver is hosted, they can also obtain a letsencrypt certificate and redirect your traffic.
- foobiekr 2y agoThat issue isn’t a dnssec problem, it’s that Let’s Encrypt was not familiar with the route hijacking threat model. It was pointed out early to them and they ignored it.
- rixthefox 2y agoWhy blame LetsEncrypt? Instead blame the operators who are refusing to address basic network security. I run a network, we do the whole shabang of RPKI, DNSSEC, and CAA. It sounds a whole lot like operators who refuse to address clear security issues. LetsEncrypt is not to blame when someone spoofs your address space. LetsEncrypt is not a LIR/RIR, their business is not IP resources but SSL certificates. They are a CA. They have no tools available to them to address that problem.
- immibis 2y agoBecause Let's Encrypt is the CA that hands out certificates without actually verifying identity.
- g15jv2dp 2y agoIf everything but the least likely attack vector gets secured, then the least likely will soon become the most likely.
- rabite 2y agoGiven that accidents involving BGP within the past several years have led to worldwide outages in the world's most used websites this is just not true. Also thousands of known bad announcements occur every year, which are usually used in a very small window to send large volumes of abusive advertisements. There's no reason not to force the industry to hold people accountable for false announcements. The privilege of announcement should be acquired by posting a significant amount of capital as a bond, from which damages can be removed when a system makes a false announcement. The vast majority of damages are a result of network operators on the subcontinent -- it is high time we figure out how to make them take the issue seriously, and pay out the nose until they do.
- zokier 2y agoWell over a decade after publication of RPKI it has been deployed at only 22% of US networks https://observatory.manrs.org/ https://observatory.manrs.org/ There is no justification for that not to be 100% at this point. With this data at hand, can you really claim that the industry has sucessfully self-regulated itself?
- icedchai 2y agoLegacy prefixes do not support RPKI unless you sign ARIN’s registration agreement and agree to pay. Many early IP address holders (including myself!) have never signed.
- gonzo 2y agoWhy pay for something that was never agreed to be so?
- rixthefox 2y agoYou don’t have to pay a dime. But don’t expect the rest of the Internet (that DO pay for their resources) to continue to guarantee reachability to your address space. If you won’t get on board with RPKI/IRR you can’t cry foul when the rest of the Internet is paying the price to be reachable. I am a resource holder and I pay my dues. I have no problems with paying for that privilege. Internet access is not an inalienable right. It is a privilege. Even as it’s become increasingly more and more of a utility. Until laws start to reflect that, it is still a privilege at best. Edit: before someone says anything about the trust anchors. Reminder, There are two overarching namespaces to the Internet. IP and DNS. You are free to ignore the authorities of both but don’t expect the rest of the Internet to play along when you want to use .billybob as your TLD.
- icedchai 2y agoAs long as RPKI "unknown" / not-found prefixes are able to be globally routed, I will not pay. I have a legacy ARIN /24 from the 90's. It was cheaper for me to get an ASN and IPv6 block through a RIPE LIR than go through ARIN. As for IRR, one of my upstreams created an RADB entry for me on behalf of my ASN, so not too concerned there.