Possible BGP hijack of 1.1.1.1
21–30 of 158 posts
Re: Possible BGP hijack of 1.1.1.1
#22How effective is this? Looking at https://bgp.he.net/ip/1.1.1.1 , 1.1.1.0/24 is apparently "ROA Signed and Valid". I don't know a lot about BGP. Does this mean hijacking this subnet is a bit harder than unsigned ones because some or all ISPs verify this announcement? Or is it faster/easier to detect? Maybe a wider question: is there some way to prevent BGP hijacking?
http://www.ausnog.net/sites/default/files/ausnog-03/presenta...
I've been out of the space for almost as long, so would love to be wrong, but I think its fair to say that not much has improved on this front since then.
Re: Possible BGP hijack of 1.1.1.1
#23Ah! That may have been the reason why my site wasn't resolving earlier today. It was the weirdest situation with people from all over the planet complaining without any apparent pattern, a RIPE check of the site from 10 different locations showed no issues in connectivity. Thanks for posting this.
Re: Possible BGP hijack of 1.1.1.1
#24Re: Possible BGP hijack of 1.1.1.1
#25Ah! That may have been the reason why my site wasn't resolving earlier today. It was the weirdest situation with people from all over the planet complaining without any apparent pattern, a RIPE check of the site from 10 different locations showed no issues in connectivity. Thanks for posting this.
No, the issue persists. While I can access your site from mobile and residential connection, any static business connection fails. No 1.1.1.1 involved. I tested this with two different Fibre connections (Berlin).
Re: Possible BGP hijack of 1.1.1.1
#26I doubt that this is a genuine hijacking attempt. All it takes is a Cisco router and some IT admin making up an address.
Re: Possible BGP hijack of 1.1.1.1
#27Would this affect certificate-validating clients doing DNS-over-HTTPS to 1.1.1.1 — doesn’t it have an ipAddress certificate and demand HTTPS resolution only?
So no. The only thing protecting you would be to have the expected hash of the certificate you expect to see (TOFU - Trust on First use, though you're screwed if you didn't contact 1.1.1.1 before the incident!).
Re: Possible BGP hijack of 1.1.1.1
#28What does this mean for those unfamiliar?
Re: Possible BGP hijack of 1.1.1.1
#29Re: Possible BGP hijack of 1.1.1.1
#30Would this affect certificate-validating clients doing DNS-over-HTTPS to 1.1.1.1 — doesn’t it have an ipAddress certificate and demand HTTPS resolution only?