BGP hijack infecting networks caused by a comedy of errors

14 pointsposted 4 hours ago
by jnord

3 Comments

justonceokay

3 hours ago

When I was in school 15 years ago, BGP was described to me as a sketchy game of telephone.

“Oh yeah you want to route to a 129.37.x.x address? I know a guy who knows a guy. Said he’s the owner of the whole 129./ block. In fact, he’s my personal friend. I mean friend’s friend… Why don’t I just take those pesky packets off your hands and we walk away”

Has anything fundamentally changed?

vlan0

2 hours ago

How could they? The alternative starts to look like every router maintains complete "internet state"...which turns out isn't possible. Awareness is complex and expensive. And there are endless variables and "whys" to consider

jeffrallen

3 hours ago

It is now:

I know a guy who says he's supposed to handle traffic for a guy who's NIC signed a message saying he owns a whole /19. I've got receipts (RPKI).

So, umm ok, I'm going to need you to just give me all his traffic, ummm, ok?

Basically it's duct tape, bailing wire, spit... and crypto. What could possibly go wrong?