Live data from Hacker News

White House asks agencies to step up internet routing security efforts

reuters.com

41–50 of 57 posts

Re: White House asks agencies to step up internet routing security efforts

#41

Earlier quoted context omitted.

> Does the site let you use an email instead of a phone number? Or TOTP.

TOTP is so good, it should be treated equally to or superior than phone number or e-mail as a requirement, by regulation, as an option for any site conducting business in US Dollars. E-mail is terrible for secure authentication. Banks have had plenty of time to implement this and haven't. TOTP can eliminate the password altogether, and make login usernames long-lived long TOTP or HOTP codes and I have just solved the…

> TOTP can eliminate the password altogether

Does anyone have TOTP-only authentication?

Re: White House asks agencies to step up internet routing security efforts

#42
post #38
post #36

Earlier quoted context omitted.

> But what impacts does this have on performance? Great we solved hijacking issue. But this other ASN which used to be a preferred route doesn’t use ROA/ROV (yet or refuses). No performance impact: a routing table is a very (ahaha) binary thing, it takes a destination address and does a longest prefix match search in a table to find the next hop interface, to which it routes the packet. Route validity is considered (…

I think you missed the parent commenter's point. The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path. In practice, I suspect there will be very little impact for most traffic, since typical aspath lengths are, like, 2. (Mostly, direct peering between CDNs and ISPs if the data isn't cached within the ISP network to begin…

Average AS Path being about 1 isn't right. For direct peer CDN content sure Even AWS has their own path that's at least 2 from GTT, Areilon, NTT, etc from wherever you connect. if you are at a data center and use blended IP Transit that's another ASN to add to the path RIPE report had the average at 3-4 in 2012.

Re: White House asks agencies to step up internet routing security efforts

#43

it looks like route views and bgpmon got embraced, extended, and largely extinguished by cisco? I've been out of this loop for a long time. is there a free service around for monitoring tables or something you can connect an openbgpd instance to for doing analysis?

There are several such sites. bgp.tools and bgp.he.net are two of the ones I use for web based monitoring.

Re: White House asks agencies to step up internet routing security efforts

#45
post #38
post #36

Earlier quoted context omitted.

> But what impacts does this have on performance? Great we solved hijacking issue. But this other ASN which used to be a preferred route doesn’t use ROA/ROV (yet or refuses). No performance impact: a routing table is a very (ahaha) binary thing, it takes a destination address and does a longest prefix match search in a table to find the next hop interface, to which it routes the packet. Route validity is considered (…

I think you missed the parent commenter's point. The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path. In practice, I suspect there will be very little impact for most traffic, since typical aspath lengths are, like, 2. (Mostly, direct peering between CDNs and ISPs if the data isn't cached within the ISP network to begin…

> The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path.

You are right, I neglected to point out that origin validation is (in the absence of shenanigans) not going to cause one path to be preferable to another: if the origin is the same AS, either both paths or neither is valid.

If the origin in two paths is two different ASes, either both are valid or shenanigans are afoot - perhaps there's a hijack being prevented, perhaps the network operator has screwed up their ROAs, perhaps the network operator is measuring sBGP uptake, perhaps the network operator is doing a rather bizarre and ineffectual form of traffic ingress management, or perhaps the network is in a transition from one AS to another, but those are all "shenanigans" in which routing efficiency is secondary to some other goal.

An alternative source for average BGP path length is https://blog.apnic.net/2024/01/10/bgp-in-2023-bgp-updates/ - where many other similar statistics can be found, and independently repeatable methodology is available. The average BGP path length for IPv4 is around 5.5 hops, and for IPv6 it is just shy of 5 hops. These numbers have been stable for a while with IPv4 slowly shrinking and IPv6 slowly growing, albeit in both cases by around 0.2 hops a decade.

And perhaps also relevant to the parent's question: path length itself is a pretty poor indicator of network performance by just about any measure you can name (excepting perhaps the TTL field), and is a last resort measure used only when all else is equal. The case of a prefix hijack being thwarted by origin validation is an extreme example in which the shorter (invalid) path represents 100% packet loss and the longer (valid) path given preference due to origin validation is infinitely more performant.

edit: oh, disclaimer - I am a co-author of one of the RPKI RFCs, and while I am personally not involved in secure BGP at present my employer definitely is. Opinions presented are mine.

Re: White House asks agencies to step up internet routing security efforts

#46
post #42
post #38

Earlier quoted context omitted.

I think you missed the parent commenter's point. The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path. In practice, I suspect there will be very little impact for most traffic, since typical aspath lengths are, like, 2. (Mostly, direct peering between CDNs and ISPs if the data isn't cached within the ISP network to begin…

Average AS Path being about 1 isn't right. For direct peer CDN content sure Even AWS has their own path that's at least 2 from GTT, Areilon, NTT, etc from wherever you connect. if you are at a data center and use blended IP Transit that's another ASN to add to the path RIPE report had the average at 3-4 in 2012.

Path length is dependent on where you stand and look at it all, of course.

If anyone knows of a place in which a border router is only one (or 1.1 average) hop away from every other network on the planet, please let me know what real estate prices are like there, though.

(I suspect the 1.1 figure measures something quite different - the average path length inside a CDN or similar, which probably should be closer to one but might involve sneaky things like an overlay network).

Re: White House asks agencies to step up internet routing security efforts

#47
post #40

> The White House said on Tuesday it wants federal agencies to boost internet routing security on networks in the face of concerns raised by U.S. officials about China's ability to divert internet traffic. Isn't that funny when the white house has been exposed secretly tapping every single non American (Chinese included) and American online activity, phones calls, mails, etc. I'm not saying the Chinese should be able…

I don't understand why IT laypeople so often appeal to moral hypocrisy in matters of internal state interests: The basis for national security recommendations is not fairness for all human beings. Yes, if you're not a citizen, you are discriminated against. Sometimes, even if you are. That's the case for every nation. It also has limited bearing on whether a security policy is in the government's self-interest.

What is your point? Appealing to morals and pointing out hypocrisy to convey the message about someone not being trustworthy is fundamental.

Trusting US/Five eyes controlled companies with your data is a bad move. No matter if private or enterprise.

It is like people being perplexed about people complaining about some company or product. 'So choose another one?' Ye well others might wanna know about it too...

Re: White House asks agencies to step up internet routing security efforts

#48
post #34

Earlier quoted context omitted.

These aren't great examples. HIPAA is extraordinarily expensive, meanwhile healthcare providers continue to have abominable security because compliance is offloaded to a "compliance team" who comes around once in a while to check boxes without really understanding the system, which is managed by other people who don't really understand HIPAA. This is one of the reasons security in large organizations is hard. Bureauc…

HIPAA is not extraordinarily expensive.

For small entities it is. Which, in turn, causes there to be fewer small entities, less competition, and higher prices. Which is extraordinarily expensive.

Also notice that a large part of the cost is poorly accounted for, because the way many of the non-destructed entities comply with it is by adopting cloud-hosted EMR systems that handle a lot of the compliance burden for them. Which aren't exactly cheap, but more than that they're usability fiascos that imperil patient care.

Re: White House asks agencies to step up internet routing security efforts

#49

Earlier quoted context omitted.

> Does the site let you use an email instead of a phone number? Or TOTP.

TOTP is so good, it should be treated equally to or superior than phone number or e-mail as a requirement, by regulation, as an option for any site conducting business in US Dollars. E-mail is terrible for secure authentication. Banks have had plenty of time to implement this and haven't. TOTP can eliminate the password altogether, and make login usernames long-lived long TOTP or HOTP codes and I have just solved the…

Email is pretty reasonable for secure authentication. All but the most anachronistic mail servers use TLS these days and you're under no obligation to use any of the few that don't. The notion that email is insecure is from the old days when the links weren't encrypted.

SMS, on the other hand, is an abomination to this very day and should not be used by anyone for anything.

Re: White House asks agencies to step up internet routing security efforts

#50
post #40

Earlier quoted context omitted.

I don't understand why IT laypeople so often appeal to moral hypocrisy in matters of internal state interests: The basis for national security recommendations is not fairness for all human beings. Yes, if you're not a citizen, you are discriminated against. Sometimes, even if you are. That's the case for every nation. It also has limited bearing on whether a security policy is in the government's self-interest.

What is your point? Appealing to morals and pointing out hypocrisy to convey the message about someone not being trustworthy is fundamental. Trusting US/Five eyes controlled companies with your data is a bad move. No matter if private or enterprise. It is like people being perplexed about people complaining about some company or product. 'So choose another one?' Ye well others might wanna know about it too...

It's a non-sequitur. BGP validation was not recommended because of a moral claim. It was recommended for national readiness against an adversary. It also wouldn't be hypocritical if the USA (or China) subsequently engaged in BGP attacks. In fact, you can trust them to.
Post reply on HN