Live data from Hacker News

Route Leak Impacting Cloudflare

cloudflarestatus.com

131–140 of 164 posts

Re: Route Leak Impacting Cloudflare

#131
post #115

Earlier quoted context omitted.

Why not? Pretty much everyone that needs a redundant internet connection (dual ISP) does it.

> Why not? It seems silly to me that an end user company not providing any network services which only has a 256 IP block has the ability to break a significant portion of the internet with a configuration mistake. There are several ways to setup dual ISPs and routing that don't involve such risk.

You need BGP and provider independent space for your two ISPs to both announce your space. What's the alternative approach?

Re: Route Leak Impacting Cloudflare

#132

Earlier quoted context omitted.

How is it bait and switch? 8.8.8.8 was never marketed as a "ping me to see if the Internet is up" service, as far as I know. Just as a fast, public DNS server.

An important use of well known easy to type IP addresses is when you're mucking around to figure out if your upstream network isn't working. I could see if they attempted to set a new standard by just not responding to ICMP at all (although turning around an icmp echo takes less work than a DNS lookup...), but responding intermittently is actively harmful.

You haven't identified the "bait" bit of the bait and switch. At no point has Google promised to respond to pings on 8.8.8.8, nor are they obliged to ever do so. Rejecting ICMP isn't "a new standard".

Re: Route Leak Impacting Cloudflare

#133
post #131
post #115

Earlier quoted context omitted.

> Why not? It seems silly to me that an end user company not providing any network services which only has a 256 IP block has the ability to break a significant portion of the internet with a configuration mistake. There are several ways to setup dual ISPs and routing that don't involve such risk.

You need BGP and provider independent space for your two ISPs to both announce your space. What's the alternative approach?

Don't rely on a single IP routing through multiple ISPs, use DNS.

Re: Route Leak Impacting Cloudflare

#134

Earlier quoted context omitted.

An important use of well known easy to type IP addresses is when you're mucking around to figure out if your upstream network isn't working. I could see if they attempted to set a new standard by just not responding to ICMP at all (although turning around an icmp echo takes less work than a DNS lookup...), but responding intermittently is actively harmful.

You haven't identified the "bait" bit of the bait and switch. At no point has Google promised to respond to pings on 8.8.8.8, nor are they obliged to ever do so. Rejecting ICMP isn't "a new standard".

The promise is implicit when competing for mindshare with 4.2.2.2. Typing an IP address into a router setup is quite infrequent, compared to "let's check connectivity by ping x.x.x.x". Setting expectations that 8.8.8.8 can fill this role is the bait.

As I said, it's much easier to respond to a ping than even a cached DNS query. Or it would also be consistent to simply never respond to ping.

Now obviously in the modern "you get nothing for nothing" world, Google is able to violate whatever expectations they'd like. But "rate limiting" in a way that makes basic ping(8)s look flaky, especially on a service that will be used for debugging, is downright nasty and deserves to be shouted from the rooftops (iff it's true).

Re: Route Leak Impacting Cloudflare

#135
The main internet and phone service provider of the Netherlands is down. Even the emergency number (112, our equivalent of 911) is down. Almost everyone is unreachable. The whole telephone network is disrupted.

I wonder if it's related to this? It does say this kind of BGP thing can be a deliberate malicious attack. Perhaps this? https://en.wikipedia.org/wiki/BGP_hijacking

Re: Route Leak Impacting Cloudflare

#136

There's one thing I don't understand about this all, it looks like Allegheny Technologies Incorporated (AS396531, a suspected original leaker) was originally announcing 192.92.159.0/24. How the heck did their peers not manage to filter a sudden announcement for a range big enough that it managed to snag both 8.8.8.8 and 1.1.1.1. Do upstreams really allow a tiny /24 AS to randomly announce a /4 and get away with it? O…

This is the problem with BGP

Re: Route Leak Impacting Cloudflare

#137

The main internet and phone service provider of the Netherlands is down. Even the emergency number (112, our equivalent of 911) is down. Almost everyone is unreachable. The whole telephone network is disrupted. I wonder if it's related to this? It does say this kind of BGP thing can be a deliberate malicious attack. Perhaps this? https://en.wikipedia.org/wiki/BGP_hijacking

Oh, and the country's train and public transport infrastructure is experiencing some major problems too due to the phone service outage.

Re: Route Leak Impacting Cloudflare

#140

The main internet and phone service provider of the Netherlands is down. Even the emergency number (112, our equivalent of 911) is down. Almost everyone is unreachable. The whole telephone network is disrupted. I wonder if it's related to this? It does say this kind of BGP thing can be a deliberate malicious attack. Perhaps this? https://en.wikipedia.org/wiki/BGP_hijacking

Oh, and the country's train and public transport infrastructure is experiencing some major problems too due to the phone service outage.

You have to wonder if these outages aren't the result of hostile states laying the groundwork and testing the viability of certain attacks.
Post reply on HN