Live data from Hacker News

Possible BGP hijack of 1.1.1.1

bgpstream.com

111–120 of 158 posts

Re: Possible BGP hijack of 1.1.1.1

#111

Earlier quoted context omitted.

That isn't a reserved/private network either.

I shake my head in bewilderment when I see stuff like this - just why would people make things harder for themselves. I very highly doubt that they are so large that they ran out of IP space in the enormity of 172.16/12 to encompass all of their OSPF/BGP router-id /32s and individual /30 OSPF router-to-router links.

> enormity

What's enormous about an IPv4 /12? :)

When the German army requested an allocation of IPv6 address space, they were given a /28, but complained that 2^100 IPs is not enough for them and they actually need a /22.

Re: Possible BGP hijack of 1.1.1.1

#112

Earlier quoted context omitted.

I'm not sure when modern tech got this idea that if everyone has been using something "wrong" for decades, it's still wrong. That space has never been previously announced, it's assigned to APNIC for _research_, it's in dozens of makes and models of router as admin interfaces, blackholed or otherwise. I get the impulse to say "you used it wrong, now it's broken", but we didn't get to a functioning worldwide internet…

I don't disagree with you that things have coalesced by consensus over a period of the past 25 years, for what IP space people should and can use, and what IP space you shouldn't use (eg: I have no doubt that a bunch of enterprise end users are using some of the US military/DoD assigned /8s internally, because those never show up on the global internet. It's wrong, but they do it anyways). However, the RFC1918 IP ran…

> v6 adoption

Good one.

Re: Possible BGP hijack of 1.1.1.1

#115

Earlier quoted context omitted.

I shake my head in bewilderment when I see stuff like this - just why would people make things harder for themselves. I very highly doubt that they are so large that they ran out of IP space in the enormity of 172.16/12 to encompass all of their OSPF/BGP router-id /32s and individual /30 OSPF router-to-router links.

> enormity What's enormous about an IPv4 /12? :) When the German army requested an allocation of IPv6 address space, they were given a /28, but complained that 2^100 IPs is not enough for them and they actually need a /22.

Well it's not so enormous, but it's also accompanied by 10/8 and 192.168/16. Many networks use some combination of all three internally for different purposes.

Re: Possible BGP hijack of 1.1.1.1

#116

Earlier quoted context omitted.

To be fair 1.1.1.1 had been unassigned/non-routable up until April.

To be fair, unallocated or unassigned IP space isn't fair game to use for testing outside of an air gapped lab. I've never in my career thought it would be a good idea to "test" unallocated public unicast address space on my edge routers.

  On an airgapped lab it is bad practice. Same -though DNS related- with using *.local as a LAN TLD
We just should not.

Re: Possible BGP hijack of 1.1.1.1

#117
post #43
post #7

Earlier quoted context omitted.

1.1.1.1 is a DNS resolver that does not track activity. A BGP compromise means that someone could have compromised it and redirect/intercept traffic of those trusting it to be Cloudflare.

A BGP attack does not compromise the destination host. It reroutes (some) traffic destined for the host. Any traffic using TLS to establish destination authenticity (e.g DNS TLS, DNS over HTTP) or content authenticity (e.g. DNSSEC) would detect the attack, while other types of traffic (traditional DNS) could be exploited.

This could be a first step to compromise TLS traffic as well: https://www.princeton.edu/~pmittal/publications/bgp-tls-hotp...

Re: Possible BGP hijack of 1.1.1.1

#118

Earlier quoted context omitted.

Just tested - loaded. Site seems to be working, have wandered about a bit. What was the problem?

One of BT's routers was rebooted as a result of this report and that seems to have cleared up the problem. Thank you for all your assistance in this - and also everybody else that helped to pinpoint the problem.

No problem - happy to help.

Re: Possible BGP hijack of 1.1.1.1

#119

Earlier quoted context omitted.

Is there a CAA equivalent for ARIN assignments?

RPKI, but it's barely used

This is currently used to sign ROA. A rogue actor can easily work around that by including the original AS in the AS path of the announce.
Post reply on HN