Live data from Hacker News

Using BGP data to find Spammers

bgpmon.net

11–17 of 17 posts

Re: Using BGP data to find Spammers

#11
post #4

The bit I had hoped to see at the end of this article: "and here's how we stopped these bogus routes at their upstream links, to prevent this problem from recurring". Disappointing to see so much analysis and no solution.

This has been a problem people thought had been happening for a while. It's only with this detailed analysis that the light is being cast on it. Now we can work on solutions. And we will.

Because Pakistan BGP-hijacking YouTube wasn't enough of a reason?

Re: Using BGP data to find Spammers

#12
post #8

Interesting that people sophisticated enough in internet routing protocols to squat on unused IP space can get paid more working for spammers than legitimate companies.

Why? Crime always paid more to compensate the added risk.

I understand why criminals would need to be paid more, I'm just surprised that spamming is lucrative enough to hire skilled engineers.

Re: Using BGP data to find Spammers

#13
This was fascinating to me. It feels like a major failing that I could register routes for address space I don't control. Kudos to the authors for explaining things in a way that a novice networking guy like myself could understand.

Re: Using BGP data to find Spammers

#14

This was fascinating to me. It feels like a major failing that I could register routes for address space I don't control. Kudos to the authors for explaining things in a way that a novice networking guy like myself could understand.

[deleted]

Re: Using BGP data to find Spammers

#15
post #11
post #4

Earlier quoted context omitted.

This has been a problem people thought had been happening for a while. It's only with this detailed analysis that the light is being cast on it. Now we can work on solutions. And we will.

Because Pakistan BGP-hijacking YouTube wasn't enough of a reason?

That was a censorship attempt that was fat finger'd to cause a leak. We all knew what happened there.

Re: Using BGP data to find Spammers

#16

Interesting that people sophisticated enough in internet routing protocols to squat on unused IP space can get paid more working for spammers than legitimate companies.

BGP is actually a pretty simple routing algorithm once you get your head around it. Certainly no harder than OSPF. I got my head around it originally back in the late 1990s and haven't touched it since and still can remember big parts of how it works.

Spam pays a lot. I mean, like, a lot. So it doesn't surprise me that some people can basically choose their own hours, work on something challenging and get paid well for doing it, all for a crime that Russia will never extradite them for, is going to be happier doing that than sitting in an office 9-5 and every other week on 24x7 on-call babysitting some Cisco firewalls.

Re: Using BGP data to find Spammers

#17
post #15
post #11

Earlier quoted context omitted.

Because Pakistan BGP-hijacking YouTube wasn't enough of a reason?

That was a censorship attempt that was fat finger'd to cause a leak. We all knew what happened there.

That's still the kind of thing we wan to prevent. Seems like a good argument for adding some kind of range enforcement to BGP routers, similar to HTTPS certificate pinning.
Post reply on HN