Live data from Hacker News

White House asks agencies to step up internet routing security efforts

reuters.com

21–30 of 57 posts

Re: White House asks agencies to step up internet routing security efforts

#21
> The White House said on Tuesday it wants federal agencies to boost internet routing security on networks in the face of concerns raised by U.S. officials about China's ability to divert internet traffic.

Isn't that funny when the white house has been exposed secretly tapping every single non American (Chinese included) and American online activity, phones calls, mails, etc.

I'm not saying the Chinese should be able to do what the USA is already doing to the world but it's like seeing a thieft getting robbed by another criminal. Somehow its funny.

Re: White House asks agencies to step up internet routing security efforts

#22
post #3

This article leans more towards a general audience. For more a tech-leaning audience, perhaps see: * https://arstechnica.com/tech-policy/2024/06/fcc-pushes-isps-... * https://www.techspot.com/news/104590-white-house-declares-bg... * https://www.securityweek.com/white-house-outlines-plan-for-a... WH PR (linked to by Reuters): > While there is no single solution to address all internet routing vulnerabilities, the road…

RPKI unfortunately doesn’t prevent BGP hijacking though. You need every message to be signed.

The whole thing feels dishonest. BGP is working as intended, so should we really call hijacking a "vulnerability"? A failure to acknowledge that the protocol is fundamentally flawed and not fit for purpose.

Re: White House asks agencies to step up internet routing security efforts

#23
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Yes. Edit: SOX, HIPAA, NIST CSF. Government is not always bad.

These aren't great examples.

HIPAA is extraordinarily expensive, meanwhile healthcare providers continue to have abominable security because compliance is offloaded to a "compliance team" who comes around once in a while to check boxes without really understanding the system, which is managed by other people who don't really understand HIPAA. This is one of the reasons security in large organizations is hard. Bureaucracies gravitate toward bureaucratic solutions, but then the left hand doesn't know what the right hand is doing, which is a direct mechanism for security to get messed up.

SOX isn't really about "security", it's about auditing and so on, but it suffers from a disadvantageous trade off. Large companies are less likely to have accounting problems than smaller ones. The law was passed in response to major outliers like Enron, but basing rules on rare outliers generally results in bad rules. Meanwhile the smaller companies have disproportionately higher compliance costs, to the point that there have been proposals to exempt smaller companies. But that implies it probably isn't worth it for large companies because the rate of fraud is so low and it probably isn't worth it for small companies because the compliance costs are so high, and then there's nothing left.

Whereas NIST CSF is a different kind of thing because it's voluntary. This is where government publications can really do some good, because if they publish rubbish then nobody has to pay any attention to it and the cost is limited to the money they spent creating it, but if it's good then it's valuable to anyone who uses it. The government should definitely lean towards this method, but it's hard to call this one "regulations" -- and the criticism you're responding to was that corporations would end up "just gaming the regulations".

Re: White House asks agencies to step up internet routing security efforts

#24
post #6
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Assuming I'm understanding the article correctly, this seems to be about federal agencies being tasked with increasing the security of their own networks, not private companies being regulated. I don't think federal agencies tend to make a profit, and they're usually the ones making the regulations, not gaming them.

The FCC is separately discussing regulating private companies' use of BGP:

https://docs.fcc.gov/public/attachments/DOC-402579A1.pdf

https://docs.fcc.gov/public/attachments/DOC-402609A1.pdf

Re: White House asks agencies to step up internet routing security efforts

#25
post #22
post #3

Earlier quoted context omitted.

RPKI unfortunately doesn’t prevent BGP hijacking though. You need every message to be signed.

The whole thing feels dishonest. BGP is working as intended, so should we really call hijacking a "vulnerability"? A failure to acknowledge that the protocol is fundamentally flawed and not fit for purpose.

BGP is working as intended, according to how it was designed before we had the opportunity to have decades of observations about how it can be abused.

And BGP is not really fundamentally flawed, what is fundamentally flawed is trying to get everyone to build an authoritative database on who owns which IPs and how they connect to their upstreams/downstreams, without it being possible for someone to manipulate that database nefariously. As we are on hacker news, you are probably aware that there is no such thing as a hack-proof system. The old IRR system would have been perfect if every IRR hoster had a dedicated team of highly trained NOC engineers who are capable of making cross references using the RIR databases to the fullest and investigate any anomalies to prevent any malicious submissions. Unfortunately, that doesn't scale as well as rolling out something smarter like RPKI. Unfortunately, everything was already setup to use the IRRs and some people like it that way, so getting to 100% RPKI adoption has been slow, just like IPv4 addresses will probably always be worth more than IPv6 even though in principle, IP address space should have zero inherent value because it's just a number and should not have any limited supply.

Source: Former RADB admin.

Re: White House asks agencies to step up internet routing security efforts

#26
post #4

This article leans more towards a general audience. For more a tech-leaning audience, perhaps see: * https://arstechnica.com/tech-policy/2024/06/fcc-pushes-isps-... * https://www.techspot.com/news/104590-white-house-declares-bg... * https://www.securityweek.com/white-house-outlines-plan-for-a... WH PR (linked to by Reuters): > While there is no single solution to address all internet routing vulnerabilities, the road…

So ROA/ROV are for preventing prefix hijacking and IANA will personally issue a certificate to verify organization owns ASN. But what impacts does this have on performance? Great we solved hijacking issue. But this other ASN which used to be a preferred route doesn’t use ROA/ROV (yet or refuses). Now traffic reroutes to a less efficient path?

[deleted]

Re: White House asks agencies to step up internet routing security efforts

#27

> The White House said on Tuesday it wants federal agencies to boost internet routing security on networks in the face of concerns raised by U.S. officials about China's ability to divert internet traffic. Isn't that funny when the white house has been exposed secretly tapping every single non American (Chinese included) and American online activity, phones calls, mails, etc. I'm not saying the Chinese should be able…

Thieves are probably more likely to want good locks on their house, it's for sure true with pentesters.

Security issues is a security issue, the justification is mostly just puffery. Even the white house statement is vague as hell with things some adversary might be able to do grasping at something to relate what is an industry-specific esoteric issue to some hypothetical tangible real world consequence.

It's like how Net Neutrality had that fake Comcast ad where you had to pay for tiers of internet to try to make sense of what really was a B2B market intervention to stop ISPs from rent-seeking tech companies. It made it relatable even if it wasn't at all what would have (and didn't happen I suppose) happened.

Re: White House asks agencies to step up internet routing security efforts

#28

> The White House said on Tuesday it wants federal agencies to boost internet routing security on networks in the face of concerns raised by U.S. officials about China's ability to divert internet traffic. Isn't that funny when the white house has been exposed secretly tapping every single non American (Chinese included) and American online activity, phones calls, mails, etc. I'm not saying the Chinese should be able…

Why thief? All countries do protect their citizens and government from external dangers. Why is one of them suddenly "thief"?

Re: White House asks agencies to step up internet routing security efforts

#29

It’s interesting how easy it is to get someone to announce your prefixes, it often just takes a credible letter of authority, in my understanding all processes rely on manual due diligence. If an organization e.g. has a valid RIPE database entry that it can announce a given prefix under its own ASN I could set up an account at a cloud provider like Vultr using the business data of said company, charge it with 10 USD…

I have had to delete a lot of invalid routes from an IRR database due to things like this. Generally, we needed someone to notify us that someone was using a cloud provider to announce their prefix unexpectedly. I would love to build a system to be constantly cross referencing IRR changes to detect stuff like this proactively, it wouldn't be simple but it would be possible. Unfortunately very, very few people understand how the IRR works.

Re: White House asks agencies to step up internet routing security efforts

#30

Earlier quoted context omitted.

And now every website has an excuse to require a verified phone number... I guess it probably does raise the baseline, but at the cost of those who have good security practices.

There's a simple way to tell if 2FA is being used for security or to harvest phone numbers: Does the site let you use an email instead of a phone number? If you can't use an email, the purpose is to harvest phone numbers.

> Does the site let you use an email instead of a phone number?

Or TOTP.

Post reply on HN