Earlier quoted context omitted.
Thanks for the updates. I wish I could get this information somewhere other than hacker news though. :(
The team is updating the status page but not with granular detail because they'd have to spend time discussing what to say. I'm giving you the blow by blow.
Route Leak Impacting Cloudflare
101–110 of 164 posts
Re: Route Leak Impacting Cloudflare
#102Earlier quoted context omitted.
We're definitely still working on it. Sorry you're affected by this. We're talking with the network providers involved. If anyone from the Verizon NOC is online... call me!
Confirming widespread FiOS issues in NYC as well, not limited to CloudFlare IPs.
Re: Route Leak Impacting Cloudflare
#103Earlier quoted context omitted.
At 3-4 major leaks per year it seems like we should probably fix BGP one of these days...
The way I understand it it's not BGP, it's mostly human error, or malicious intent. The protocol is fine.
What you are describing is a protocol problem.
Re: Route Leak Impacting Cloudflare
#104“AS396531 "Allegheny Technologies Incorporated" is leaking a better-reachable route for AS13335 "Cloudflare, Inc." towards AS701 "Verizon Business/UUnet" explaining the current LSE going on.” https://twitter.com/OhNoItsFusl/status/1143117619106652160
That appears to be a steel/alloys company. Why are they operating BGP equipment?
Re: Route Leak Impacting Cloudflare
#105What a great idea it is to have half the internet behind Crimeflare! It shows!
It's a route leak, which can affect any arbitrary amount of ISPs, because the BGP protocol is totally unauthenticated.
Re: Route Leak Impacting Cloudflare
#106What's weird is that 8.8.8.8 is also intermittently down for me. Are other people having issues with Google DNS too? https://i.imgur.com/3ySmVLW.png
Re: Route Leak Impacting Cloudflare
#107Earlier quoted context omitted.
The way I understand it it's not BGP, it's mostly human error, or malicious intent. The protocol is fine.
An unauthenticated protocol that allows unsigned routes to be blindly accepted is not a good protocol, that's why Cloudflare has been pushing RPKI for a while https://blog.cloudflare.com/rpki/ https://blog.cloudflare.com/rpki-details/
BGP was designed for operators to implement a routing policy. In most implementations it allows everything by default with no modifications to route metadata, so if you do not set up your policy correctly you'll have issues like this.
Re: Route Leak Impacting Cloudflare
#108Does anyone know which global sites were unavailable because of Cloudflare crash?
Re: Route Leak Impacting Cloudflare
#109What's weird is that 8.8.8.8 is also intermittently down for me. Are other people having issues with Google DNS too? https://i.imgur.com/3ySmVLW.png
Google rate limits ICMP to 8.8.8.8. It’s not meant to be used as your personal “is the internet up” test.
Re: Route Leak Impacting Cloudflare
#110Does anyone know which global sites were unavailable because of Cloudflare crash?
You're not going to be able to get a solid list, this is a different category of problem than something like CloudBleed, and even then the list wasn't solid. This issue is affecting AWS, Cloudflare, Cloudflare DNS, Google DNS, and the tens of thousands of other services that depend on them, but it's region specific and will break different things for different users as the leak propagates.
90 AS 13335 Cloudflare, Inc. 18 AS 7018 AT&T Services, Inc. 8 AS 63949 Linode, LLC 8 AS 2828 MCI Communications Services, Inc. d/b/a Verizon Business 6 AS 26769 Bandcon 6 AS 16509 Amazon.com, Inc. 4 AS 6428 CDM 4 AS 2914 NTT America, Inc. 2 AS 9808 Guangdong Mobile Communication Co.Ltd. 2 AS 6939 Hurricane Electric LLC 2 AS 62904 Eonix Corporation 2 AS 55081 24 SHELLS 2 AS 54113 Fastly 2 AS 46606 Unified Layer 2 AS 45899 VNPT Corp 2 AS 4246 New Jersey Institute of Technology 2 AS 3257 GTT Communications Inc. 2 AS 27695 EDATEL S.A. E.S.P 2 AS 22781 Strong Technology, LLC. 2 AS 20473 Choopa, LLC 2 AS 16625 Akamai Technologies, Inc. 2 AS 12129 123.Net, Inc.