Live data from Hacker News

Shutting Down the BGP Hijack Factory

dyn.com

11–20 of 63 posts

Re: Shutting Down the BGP Hijack Factory

#12

I have worked for a medium size ISP for many years (3 upstream Tier-1 provider, presence on 2 IXP) and we sometimes suffer from BGP hijaking. We had developed a software that every hour checks the BGP prefix assigned to every peer and update the BGP filter automatically. It takes some time to engineering it and develop but after then, it works like a charm.

That’s a 1-hour attack window though. It should be event driven, something where peers can securely signal changes as they happen

Re: Shutting Down the BGP Hijack Factory

#15
post #6

Well its nice that they are now shut down, although the process seems to been fairly slow and arduous. They were already identified as misbehaving in 2014, getting kicked out from deixp in 2017, and only now disconnected by transits. And even in the latest episode they could play this game of cat and mouse for a (short) while. And what if Guilmette wouldn't had noticed this, or bothered to rant on nanog, would that h…

The lessons learned section of the article hints at orgs being way too permissive or unresponsive when bad behavior occurs. The thing is though, this isn't a world where that kind of softness and leniency makes any sort of sense.

Re: Shutting Down the BGP Hijack Factory

#17
post #6

Well its nice that they are now shut down, although the process seems to been fairly slow and arduous. They were already identified as misbehaving in 2014, getting kicked out from deixp in 2017, and only now disconnected by transits. And even in the latest episode they could play this game of cat and mouse for a (short) while. And what if Guilmette wouldn't had noticed this, or bothered to rant on nanog, would that h…

The lessons learned section of the article hints at orgs being way too permissive or unresponsive when bad behavior occurs. The thing is though, this isn't a world where that kind of softness and leniency makes any sort of sense.

It makes sense from a not-wanting-to-get-sued-for-breach-of-contract standpoint.

The contract at IXPs almost universally includes a phrase like "will not engage in fraudulent announcement of routes", but proving that happened to the satisfaction of a non-profit's board of directors is difficult. You really have to have completely collinear anatidae.

Re: Shutting Down the BGP Hijack Factory

#19
I fail to understand why there is no quick and official way to terminate such bad actors. Isn’t there a task force for monitoring and enforcing some rules? There should be a SPoC for every AS, available 24/7 so that such notorious players are kicked out immediately. We live in an age where everything can be traced and monitored and we allow BGP hijacking and other similar acts. Oh well, my romantic idea for a properly moderated network.

Re: Shutting Down the BGP Hijack Factory

#20

I fail to understand why there is no quick and official way to terminate such bad actors. Isn’t there a task force for monitoring and enforcing some rules? There should be a SPoC for every AS, available 24/7 so that such notorious players are kicked out immediately. We live in an age where everything can be traced and monitored and we allow BGP hijacking and other similar acts. Oh well, my romantic idea for a properl…

The short answer is no, the internet doesn't have any centralized authority to kick people off, or even to set rules, let alone monitor or enforce them. Each Autonomous System has the autonomy to set its own rules for who it connects to.
Post reply on HN