Live data from Hacker News

Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

blog.cloudflare.com

141–150 of 291 posts

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#141

My favorite outage when I worked for a voip company was when one of our tech support people told a new customer that she needed to ‘add our ip address to your router’, meaning add it to the firewall whitelist, but she repeated that verbatim to the telco tech who misunderstood and then escalated her way up the chain at a major telco until some engineer with the wrong rights said ‘fuck it’ and updated bgp to route all…

"Engineer"

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#142
post #120
post #85

Earlier quoted context omitted.

So we run into the age-old problem of "who decides". Also, how do we prevent fragmentation when there is disagreement.

Freedom isn't free. Web of trust. Inconvenient, but that's a price I'm willing to pay for a network that empowers users rather than commercial interests.

The flaw here is that very few of the people who use and enjoy that internet are willing to pay that same price.

All is not lost though. You can always opt out and run your own DNS or use hostfiles. Then you can have the internet you want and everyone the can have the internet they want.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#143
post #36

Here's a shoutout to all the on-calls who woke up this morning to deal with "someone else's problem". I think everyone who woke up gets to, at least, order a "fancy coffee" and send the bill to Verizon.

Woke up repeatedly this morning to PagerDuty after working late last night. Threw numerous wailing electronics at wall. Later, ordered several “fancy coffees”. Will be sending bill to Verizon for two phones, a pager, a wall, and three fancy coffees.

Edit/Disclaimer: Yes, this is a joke. I woke up to several serious alarms just as the problem was starting. Luckily, I thought to check Cloudflare’s status page from my phone around the second or third time PagerDuty called me. I saw a preliminary notice from them indicating that they were observing networking issues. At that point, I decided I’d rather watch the world burn from my bed than my computer, so I “scheduled” maintenance for a few hours and went back to bed. Our whole infrastructure had split by that point, but there was nothing I could do about it.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#144
post #120
post #85

Earlier quoted context omitted.

So we run into the age-old problem of "who decides". Also, how do we prevent fragmentation when there is disagreement.

Freedom isn't free. Web of trust. Inconvenient, but that's a price I'm willing to pay for a network that empowers users rather than commercial interests.

Other than "not enough people are interested" what is stopping you or any group of people from using such a decentralized system as your primary name resolver today? I.e. if it's not in the web of trust use existing DNS as a fallback and watch it grow. I'm not sure I'd trust such a system to prevent banksite.com from being hijacked but I don't need to for you to.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#145
post #57

Earlier quoted context omitted.

The amount of posturing and blaming in Cloudflare's response is breathtakingly unprofessional. If the article was just a few sentences longer, you could have squeezed in a few more statements of blame. We know, they messed up. But Cloudflare isn't making itself look any better by rolling the bus over Verizon again and again.

I 100% agree with you, though I am unsurprised that HN is downvoting you. HN seems to revere Cloudflare bigtime despite the fact that Cloudflare often uses HN as their own corporate PR platform. I absolutely loathe Verizon and I'll be the first to line up for a good publish lashing of US ISPs, but even I feel like this blog post is unnecessarily unprofessional. What strikes me the most is that this whole "event" woul…

Please remember that this was early in the morning if and only if you happen to live in US time zones. There are many parts of the world where the sun shines when it is dark in the US.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#146

Cloudflare managed to get an in-depth blog post, one which has incident details, points blame to other parties, and makes some really quite aggressive (for corporate blog posts) claims, all during an incident, and they did all that in 8 hours . I'm impressed. At most other similar size companies, this would take 4 days. And in something like Amazon, it would be 2 weeks of approvals, editing, and review before a water…

Regarding those really aggressive claims, I was a bit shocked by that as well.

Either Cloudflare has some pre-existing beef with Verizon and is using this as an opportune moment to dump on them ... or Tom Strickx (who wrote the blog post) had his beauty rest interrupted early this morning to deal with Verizon's screw-up and was not having it.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#147

From the post: >"It doesn't cost a provider like Verizon anything to have such limits in place. And there's no good reason, other than sloppiness or laziness, that they wouldn't have such limits in place." Is "sloppiness or laziness" really the only possible attribution here? I'm not a big fan of Verizon but I'm a big fan of civility and empathy, two qualities which your blog post lacks. Outages are a really unfortun…

It was gross negligence that leads to this. Nothing more.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#148
post #133

Earlier quoted context omitted.

Blog posts are their speciality

(deleted) Yeah, that wasn’t contributing. Everyone has bad days.

Your profile mentions:

> Chief Architect, Information Security, Akamai Technologies. I do not speak for my employer.

Probably best to disclose this more directly in comments on topics related to competitors.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#149

It's clear that Verizon broke the Internet this morning through incompetent BGP management, and they could do it again. Who holds them accountable?

Who holds them accountable? Anyone working in their NOCs with thoughts of working elsewhere? Having a predetermination of "stupid and/or lazy" because of your workplace can't help employment prospects.

> Who holds them accountable?

> Anyone working in their NOCs with thoughts of working elsewhere? Having a predetermination of "stupid and/or lazy" because of your workplace can't help employment prospects.

Some people select workplaces based on the notion that they are lazy.

Re: Verizon and a BGP Optimizer Knocked Large Parts of the Internet Offline

#150

I appreciate how sympathetic Cloudflare is to the root-cause party because they answered the phone and undid what they shouldn’t have done. (If my understanding is correct, they shouldn’t have told Verizon about the better routing, while Verizon should have known better)

I read this as Allegheny's fault, actually. DQE published to Allegheny (DQE's customer), who in turn re-published to Verizon (Allegheny's other provider). While most of the 'prevention' section talks about what Verizon didn't do, it doesn't seem to mention that Allegheny should not have re-published the DQE-published routes up to Verizon. It's startling that Verizon doesn't appear to have any leak mitigations in plac…

Allegheny is a steel company. I don’t think most people expect them to have the same responsibility for internet health as Verizon, even though they are a $4B company.

(I’m from Pittsburgh, my grandfather and a bunch of my relatives worked for this company for decades. I’ve been kinda giggling about this intersection of my past and my present all day. I don’t work in the parts of Cloudflare that deal with this kind of thing; I’m glad my co-workers were on top of it.)

Post reply on HN