Live data from Hacker News

White House asks agencies to step up internet routing security efforts

reuters.com

11–20 of 57 posts

Re: White House asks agencies to step up internet routing security efforts

#11
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

There are many, but perhaps the second part of your question is invisible, but is the meaningful one: "in a short timeframe" or "at reasonable cost" or something. People like to dump on government but they can move the acceptable window/best practice to a place that corps would not have gotten to by themselves. Crypto is one, OWASP springs to mind, etc. But the government is not a homogeneous monolithic entity and it…

I think there is a good argument to be made that many companies would have created a better infrastructure by now if the government wasn't involved.

Re: White House asks agencies to step up internet routing security efforts

#12

It’s interesting how easy it is to get someone to announce your prefixes, it often just takes a credible letter of authority, in my understanding all processes rely on manual due diligence. If an organization e.g. has a valid RIPE database entry that it can announce a given prefix under its own ASN I could set up an account at a cloud provider like Vultr using the business data of said company, charge it with 10 USD…

> what I did for my own organization and in my RIPE data there’s nothing that specifically says Vultr can announce my prefixes

In RIPE, each as-num should list out a policy of which other ASNs can import/export routes from that ASN. I think there should also be a route/route6 object.

Do vultr not check/enforce this? (Other providers do).

Re: White House asks agencies to step up internet routing security efforts

#13
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Obama was calling for 2FA back in 2016. https://www.wsj.com/articles/protecting-u-s-innovation-from-...

> we’re launching a new national awareness campaign to raise awareness of cyberthreats and encourage more Americans to move beyond passwords—adding an extra layer of security like a fingerprint or codes sent to your cellphone

Amongst other things.

Re: White House asks agencies to step up internet routing security efforts

#14

Earlier quoted context omitted.

There are many, but perhaps the second part of your question is invisible, but is the meaningful one: "in a short timeframe" or "at reasonable cost" or something. People like to dump on government but they can move the acceptable window/best practice to a place that corps would not have gotten to by themselves. Crypto is one, OWASP springs to mind, etc. But the government is not a homogeneous monolithic entity and it…

I think there is a good argument to be made that many companies would have created a better infrastructure by now if the government wasn't involved.

Yeah, like moving to IPv6 in a small time frame.

People arguing about public vs. private are missing the mark entirely. It has nothing to do with that. It's all about how many people have to do a task.

The US govt got to the moon and created a nuclear bomb in a relatively tiny amount of time, all entirely because it was a relatively small number of people focused on the same task. As for people who own routers? Thousands and thousands of them who all have different interests who aren't all focused on the same goal.

Getting a large group of people to do one simple task is 100x harder than getting a small group of people to do a complex task. This is why humanity got to the moon but still are stuck on IPv4.

Re: White House asks agencies to step up internet routing security efforts

#15
post #3

This article leans more towards a general audience. For more a tech-leaning audience, perhaps see: * https://arstechnica.com/tech-policy/2024/06/fcc-pushes-isps-... * https://www.techspot.com/news/104590-white-house-declares-bg... * https://www.securityweek.com/white-house-outlines-plan-for-a... WH PR (linked to by Reuters): > While there is no single solution to address all internet routing vulnerabilities, the road…

RPKI unfortunately doesn’t prevent BGP hijacking though. You need every message to be signed.

It solves a class of hijacks, where an autonomous system announces a prefix it is not authorized to announce. This is typically the operator error use case or uneducated bad actor use case. What it does not cover is if an autonomous system crafts an announcement containing the valid origin autonomous system in which case you would need a mechanism to validate the entire AS_PATH itself. ROA is only concerned about the origin in the AS_PATH.

Re: White House asks agencies to step up internet routing security efforts

#16
post #14

Earlier quoted context omitted.

I think there is a good argument to be made that many companies would have created a better infrastructure by now if the government wasn't involved.

Yeah, like moving to IPv6 in a small time frame. People arguing about public vs. private are missing the mark entirely. It has nothing to do with that. It's all about how many people have to do a task. The US govt got to the moon and created a nuclear bomb in a relatively tiny amount of time, all entirely because it was a relatively small number of people focused on the same task. As for people who own routers? Thous…

The moon and the bomb are both examples of what happens when you take aim at a problem with completely unlimited money and zero red tape. 400,000 people contributed to the moon landing and the Manhattan Project employed over 130,000 people. These were not small groups.

Re: White House asks agencies to step up internet routing security efforts

#17
post #13
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Obama was calling for 2FA back in 2016. https://www.wsj.com/articles/protecting-u-s-innovation-from-... > we’re launching a new national awareness campaign to raise awareness of cyberthreats and encourage more Americans to move beyond passwords—adding an extra layer of security like a fingerprint or codes sent to your cellphone Amongst other things.

And now every website has an excuse to require a verified phone number...

I guess it probably does raise the baseline, but at the cost of those who have good security practices.

Re: White House asks agencies to step up internet routing security efforts

#18
post #6
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Assuming I'm understanding the article correctly, this seems to be about federal agencies being tasked with increasing the security of their own networks, not private companies being regulated. I don't think federal agencies tend to make a profit, and they're usually the ones making the regulations, not gaming them.

> they're usually the ones making the regulations, not gaming them.

Government agencies regularly game regulations that apply to them in the same way as corporations. See e.g. FOIA, Fourth Amendment, qualified immunity, civil asset forfeiture.

Re: White House asks agencies to step up internet routing security efforts

#19
post #13

Earlier quoted context omitted.

Obama was calling for 2FA back in 2016. https://www.wsj.com/articles/protecting-u-s-innovation-from-... > we’re launching a new national awareness campaign to raise awareness of cyberthreats and encourage more Americans to move beyond passwords—adding an extra layer of security like a fingerprint or codes sent to your cellphone Amongst other things.

And now every website has an excuse to require a verified phone number... I guess it probably does raise the baseline, but at the cost of those who have good security practices.

There's a simple way to tell if 2FA is being used for security or to harvest phone numbers: Does the site let you use an email instead of a phone number? If you can't use an email, the purpose is to harvest phone numbers.

Re: White House asks agencies to step up internet routing security efforts

#20

It’s interesting how easy it is to get someone to announce your prefixes, it often just takes a credible letter of authority, in my understanding all processes rely on manual due diligence. If an organization e.g. has a valid RIPE database entry that it can announce a given prefix under its own ASN I could set up an account at a cloud provider like Vultr using the business data of said company, charge it with 10 USD…

Can get US government also strong arm the organizations to do so?
Post reply on HN