Skip to content

BGP hijack infecting networks caused by a comedy of errors

arstechnica.com
16 pointsjnord3 comments
On HN

Comments

When I was in school 15 years ago, BGP was described to me as a sketchy game of telephone.

“Oh yeah you want to route to a 129.37.x.x address? I know a guy who knows a guy. Said he’s the owner of the whole 129./ block. In fact, he’s my personal friend. I mean friend’s friend… Why don’t I just take those pesky packets off your hands and we walk away”

Has anything fundamentally changed?

How could they? The alternative starts to look like every router maintains complete "internet state"...which turns out isn't possible. Awareness is complex and expensive. And there are endless variables and "whys" to consider

It is now:

I know a guy who says he's supposed to handle traffic for a guy who's NIC signed a message saying he owns a whole /19. I've got receipts (RPKI).

So, umm ok, I'm going to need you to just give me all his traffic, ummm, ok?

Basically it's duct tape, bailing wire, spit... and crypto. What could possibly go wrong?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.