Live data from Hacker News

Ask HN: Is Google Compute down?

news.ycombinator.com

41–50 of 80 posts

Re: Ask HN: Is Google Compute down?

#41

Hi all - Seth from Google here. Our team is aware and we are working on mitigation. In short, a third party telco provider is advertising on one of our IP blocks. Unfortunately that's all the information I can share at this time.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

> This kind of thing should not be possible.

It sounds like you're asking google to solve https://en.wikipedia.org/wiki/BGP_hijacking ?

Re: Ask HN: Is Google Compute down?

#43

Hi all - Seth from Google here. Our team is aware and we are working on mitigation. In short, a third party telco provider is advertising on one of our IP blocks. Unfortunately that's all the information I can share at this time.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

Check out BGPSec and RPKI - they should prevent issues like this one. They're not widely implemented/enforced. Maybe it's going to change though now that it looks like we've got a "misconfiguration" somewhere every month or so.

Re: Ask HN: Is Google Compute down?

#44

We urgently need a solution for routing traffic to IP addresses that is better than BGP.

Agreed. This appears to be a repeat of the attack covered here: https://news.ycombinator.com/item?id=18385920

I'm not familiar with BGP routing attacks; the article above seems to imply the attacker needs to compromise certs in order to glean useful data from the attack.

If that's accurate, is this Google-oriented traffic vulnerable to this type of attack?

Re: Ask HN: Is Google Compute down?

#45

Hi all - Seth from Google here. Our team is aware and we are working on mitigation. In short, a third party telco provider is advertising on one of our IP blocks. Unfortunately that's all the information I can share at this time.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

Resource Public Key Infrastructure, but ISPs are too cheap to actually implement it.

Re: Ask HN: Is Google Compute down?

#47

Earlier quoted context omitted.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

> This kind of thing should not be possible. It sounds like you're asking google to solve https://en.wikipedia.org/wiki/BGP_hijacking ?

Sorry, I didn't intend it to be directed at google.

Re: Ask HN: Is Google Compute down?

#48

Hi all - Seth from Google here. Our team is aware and we are working on mitigation. In short, a third party telco provider is advertising on one of our IP blocks. Unfortunately that's all the information I can share at this time.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

yeah there's been proposals on improving BGP security for at least 14 years that I've been aware of :)

Getting the big ISPs/Telcos to adopt them... that's another matter

Re: Ask HN: Is Google Compute down?

#49

Hi all - Seth from Google here. Our team is aware and we are working on mitigation. In short, a third party telco provider is advertising on one of our IP blocks. Unfortunately that's all the information I can share at this time.

EDIT: This is a general statement, I am not complaining to google here. This kind of thing should not be possible. Are there any protocol proposals or other kind of upgrades to the routing protocols that would prevent these kind of mistakes/attacks?

> This kind of thing should not be possible.

When reality conflicts with what you believe to be possible, it's time to reexamine your assumptions.

Post reply on HN