Live data from Hacker News

Helping to secure internet routing

aws.amazon.com

11–20 of 54 posts

Re: Helping to secure internet routing

#12
>We are happy to have over 99% of our IPv4 and IPv6 -Space covered under a Route Origination Authorization, and that we are right now dropping RPKI invalid routes in every single Point-of-Presence for AS16509.

Does anyone know if AWS is going to push the remaining 1% to implement ROA?

Also, it sounds like an unsigned route - which I think most BGP announcements are - is still accepted, right? Any idea when we can start to require routes be signed?

Re: Helping to secure internet routing

#13
post #4

Does this give AWS any ability to block/censor or influence access to segments of the internet that they might not politically "approve" of?

Amazon at any point can create a firewall (it would be business suicide however to do so for geopolitical reasons). This however has nothing to do with that.

Re: Helping to secure internet routing

#14
post #12

>We are happy to have over 99% of our IPv4 and IPv6 -Space covered under a Route Origination Authorization, and that we are right now dropping RPKI invalid routes in every single Point-of-Presence for AS16509. Does anyone know if AWS is going to push the remaining 1% to implement ROA? Also, it sounds like an unsigned route - which I think most BGP announcements are - is still accepted, right? Any idea when we can sta…

Making RPKI mandatory is like turning off IPv4 after everyone has adopted IPv6.

Re: Helping to secure internet routing

#15
post #9
post #7

Earlier quoted context omitted.

Who is the authority on the integrity of routing?

The certificate authority that signs the routes. So yeah, this will centralize control of routing and expose it to things like government censorship and corporation exploitation. Sometimes the wild west is better than an authoritarian government. Like DNSSEC this is only good for megacorps and nationstates. If anything it will expose human people to more abuse and exploitation.

Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different?

A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from

Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hosting and I think the domain was terminated

Re: Helping to secure internet routing

#16
post #12

>We are happy to have over 99% of our IPv4 and IPv6 -Space covered under a Route Origination Authorization, and that we are right now dropping RPKI invalid routes in every single Point-of-Presence for AS16509. Does anyone know if AWS is going to push the remaining 1% to implement ROA? Also, it sounds like an unsigned route - which I think most BGP announcements are - is still accepted, right? Any idea when we can sta…

There can be legitimate use cases why a network maybe have a very few amount of prefixes not signed or even invalid: canaries and beacons.

For example, running tests to a signed, unsigned and invalid prefix can provide insight into how other networks are routing to them.

One example is a beacon to probe to determine if a network has enabled origin validation. Failure to connect, or a change in the routing path can provide insight into which networks on the internet have enabled origin validation.

Re: Helping to secure internet routing

#17
post #15
post #9

Earlier quoted context omitted.

The certificate authority that signs the routes. So yeah, this will centralize control of routing and expose it to things like government censorship and corporation exploitation. Sometimes the wild west is better than an authoritarian government. Like DNSSEC this is only good for megacorps and nationstates. If anything it will expose human people to more abuse and exploitation.

Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hostin…

It seems like we should be more focused on the possibility of this being abused rather than asking if it’s been abused yet.

Re: Helping to secure internet routing

#18
post #15
post #9

Earlier quoted context omitted.

The certificate authority that signs the routes. So yeah, this will centralize control of routing and expose it to things like government censorship and corporation exploitation. Sometimes the wild west is better than an authoritarian government. Like DNSSEC this is only good for megacorps and nationstates. If anything it will expose human people to more abuse and exploitation.

Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hostin…

In this case, certificate revocation being so broken probably saved Parler from having it being done to them.

Re: Helping to secure internet routing

#20
post #4

Does this give AWS any ability to block/censor or influence access to segments of the internet that they might not politically "approve" of?

No. If anything this makes it harder for anyone to block segments of the internet, by ensuring the integrity of routing to any given netblock.

[deleted]
Post reply on HN