Live data from Hacker News

Helping to secure internet routing

aws.amazon.com

41–50 of 54 posts

Re: Helping to secure internet routing

#41
post #4

Does this give AWS any ability to block/censor or influence access to segments of the internet that they might not politically "approve" of?

Why the downvotes for this question? Given recent events, this seems like an incredibly important consideration. No matter your perspective, this seems like something to think about. If you think Amazon did the right thing, then you would probably want them to be able to refuse routes from networks that are too dangerous. If you think Amazon did the wrong thing, then you may be afraid that this gives them even more p…

FYI, asking about downvotes usually yields downvotes.

That said, votes usually come in waves. It'll end up where it needs to.

Re: Helping to secure internet routing

#42
post #25

Earlier quoted context omitted.

> Does the netblock "owner" suddenly see all of its traffic dropped? Assuming everyone implements RPKI validation AND the RIR signs a new valid ROA with a different origin: Yes, eventually. Depends on sync intervals. It's unlikely it would even be legally possible to compel them to do this. Individual ASNs can still choose to accept the invalid route anyway. The RIR already has the power to revoke assignments, and IR…

"It's unlikely it would even be laglly possible to compel them to do this." But then, at a higher level, look at the unilateral/collective censorship ("deplatforming") that is happening right now... and being carried out in part by Amazon. None of the censors have been legally compelled to take any such actions.

What you are calling "censorship" is a free market business transaction. There are many cloud services, colo facilities, etc. If Amazon chooses not to do business with you there are certainly other options.

This certainly happens at the local level all the time: really toxic customers can get "fired" and banned from all the local movie theaters or all the local grocery stores. It is really no different online - some people just got used to living consequence-free on the internet. Wider society had no idea what the internet was at first then later didn't grasp the seriousness or impact the internet had. Fewer people hold such obviously disprovable beliefs now. The internet is just slowly catching up with how the physical world usually works. Neo-Nazi groups often can't find private venues willing to host their rallies, caterers willing to serve them food, etc. Newspapers refuse to run ads all the time. Broadcast networks don't hand over the microphone to everyone who demands it. If every newspaper in the country refuses to run your political ad that doesn't make it a grand conspiracy to censor you - perhaps you're just an asshole they don't want to do business with.

RIRs are not regular for-profit businesses and operate under very different policies for many reasons not the least of which is there are no alternatives since the RIR controls your access to the internet within your region via IP assignments.

Re: Helping to secure internet routing

#43
post #38

Earlier quoted context omitted.

I believe it is likely that global IPv4 routing goes away before universal adoption of IPv6 at clients. Transitional technologies allow IPv4 holdouts to have "working" Internet despite an increasing proportion of IPv6 nodes, there's some device somewhere which is mapping your connection to some IPv6-only service as an imaginary IPv4 connection. Such things wouldn't scale with 99% of users and usages, but can handle s…

> a transition device nearer almost all remaining IPv4 users and that's turning their traffic into IPv6 for the long haul anyway. This is mostly impossible, because an IPv4 packet doesn't have room for an IPv6 destination. The opposite direction (NAT64) is common, but that's for IPv6 clients talking to IPv4 servers.

If you're using DS-Lite then the traffic is IPv4 from the user's device to their local router, v6 from there to... somewhere, and then v4 between that somewhere and the endpoint. Initially that "somewhere" is the user's ISP, but we can imagine it getting outsourced further and further upstream until eventually "the IPv4 internet" is a single datacenter that every ISP outsources to.

Re: Helping to secure internet routing

#44

Earlier quoted context omitted.

"It's unlikely it would even be laglly possible to compel them to do this." But then, at a higher level, look at the unilateral/collective censorship ("deplatforming") that is happening right now... and being carried out in part by Amazon. None of the censors have been legally compelled to take any such actions.

What you are calling "censorship" is a free market business transaction. There are many cloud services, colo facilities, etc. If Amazon chooses not to do business with you there are certainly other options. This certainly happens at the local level all the time: really toxic customers can get "fired" and banned from all the local movie theaters or all the local grocery stores. It is really no different online - some…

If the reason for the decision is objectionable speech then what term do we use.

Anyway, it does not change the point of the original comment which is that these entities are collectively taking action based on objectionable material without any legal compulsion.

Re: Helping to secure internet routing

#45
post #37

Earlier quoted context omitted.

> if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? But Gaddafi was already in control of all Libyan ISPs and the .ly ccTLD. Why would DNSSEC have made his job any easier? Also, surely Facebook was more instrumental in the Arab Spring than bit.ly was.[0] If anything, the lack of DNSSEC made it easier for Gaddafi to spoof DNS results for facebook.com and other sites. [0] https://en.wikipedia.or…

Gaddafi was not, to my knowledge, in control of any WebPKI CA=True certificates.

For what it's worth this Gaddafi -> Libya -> bit.ly connection has to be one of the weirdest beliefs you've exhibited over a long period.

At first I thought it was just an extended bit, like the whole Cody Johnston "teleporting boars" thing [0]

But I don't think it can be, I think you're serious and er, that's not great basically. Maybe take a few minutes to think about it more clearly, discuss it with somebody you trust, and see if you can't figure out where you went wrong.

[0] https://twitter.com/drmistercody/status/1046558632878399489

Re: Helping to secure internet routing

#48

Earlier quoted context omitted.

"It's unlikely it would even be laglly possible to compel them to do this." But then, at a higher level, look at the unilateral/collective censorship ("deplatforming") that is happening right now... and being carried out in part by Amazon. None of the censors have been legally compelled to take any such actions.

What you are calling "censorship" is a free market business transaction. There are many cloud services, colo facilities, etc. If Amazon chooses not to do business with you there are certainly other options. This certainly happens at the local level all the time: really toxic customers can get "fired" and banned from all the local movie theaters or all the local grocery stores. It is really no different online - some…

It's pretty clear what trusting Amazon with internet routing will accomplish. The 73% of Republicans think the election was fraudulent - that basket of deplorable assholes will be routed straight to the nearest landfill.

Any protocol which lets them do that will surely face a lot of opposition.

"Only trust Operating Systems signed by us for your own security", "Only trust Apps signed by us for your own security", "Only trust routes signed by us for your own security", yeah I think we all know how that usually goes.

Re: Helping to secure internet routing

#49
post #15
post #9

Earlier quoted context omitted.

The certificate authority that signs the routes. So yeah, this will centralize control of routing and expose it to things like government censorship and corporation exploitation. Sometimes the wild west is better than an authoritarian government. Like DNSSEC this is only good for megacorps and nationstates. If anything it will expose human people to more abuse and exploitation.

Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hostin…

> Has this happened as HTTPS adoption has increased?

This is such a naive way of looking at things. First a trap is built. Then you wait. Years. Only when the trap is filled to the brim does it snap shut. Many examples of that pattern.

Re: Helping to secure internet routing

#50
post #15

Earlier quoted context omitted.

Has this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hostin…

Let's put it another way. Do you think the Arab spring and Libyan civil war would've taken place if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? I don't. Now think of that on kind of thing happening with routes. Yikes. At least with the way things are now there's no ground truth. Every AS has it's own perception of the routing table and the ability to act on it. That's the way it should be.…

Anyone can still accept routes that don't have the stamp of authority.

I would also point out that the big authorities handing out the certification for this can also just revoke your IP block instead. You could still announce the block but since you're not longer in legitimate ownership of the IP block, it's likely that you'll quickly be blocked from announcing it.

Post reply on HN