Live data from Hacker News

White House asks agencies to step up internet routing security efforts

reuters.com

51–57 of 57 posts

Re: White House asks agencies to step up internet routing security efforts

#51
post #34

Earlier quoted context omitted.

HIPAA is not extraordinarily expensive.

For small entities it is. Which, in turn, causes there to be fewer small entities, less competition, and higher prices. Which is extraordinarily expensive. Also notice that a large part of the cost is poorly accounted for, because the way many of the non-destructed entities comply with it is by adopting cloud-hosted EMR systems that handle a lot of the compliance burden for them. Which aren't exactly cheap, but more…

I really don't think this is true. What cost factors are you thinking of? We host lots of small HIPAA-complying businesses, and in my career I've consulted for many dozens more. As near as I can tell, there's actually not a whole lot to it.

Re: White House asks agencies to step up internet routing security efforts

#52
post #5

I don't want this to sound cynical, but do we have any examples where the US government successfully got the corporations to actually increase security, as opposed to just gaming the regulations to make more money instead?

Plenty of that with airplanes.

Re: White House asks agencies to step up internet routing security efforts

#53
post #51

Earlier quoted context omitted.

For small entities it is. Which, in turn, causes there to be fewer small entities, less competition, and higher prices. Which is extraordinarily expensive. Also notice that a large part of the cost is poorly accounted for, because the way many of the non-destructed entities comply with it is by adopting cloud-hosted EMR systems that handle a lot of the compliance burden for them. Which aren't exactly cheap, but more…

I really don't think this is true. What cost factors are you thinking of? We host lots of small HIPAA-complying businesses, and in my career I've consulted for many dozens more. As near as I can tell, there's actually not a whole lot to it.

This is what the government calls the "administrative simplification":

https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad...

It's 115 pages. Just training the staff to comprehend what's in it is a non-trivial undertaking, assuming people are actually going to comply with it.

It has some fun provisions, like prohibiting disclosure of certain information except where disclosure is mandatory, which means there is no "err on the side of caution" and you need staff to know exactly what the conditions are if you want to avoid breaking the law.

There are various rules about computer systems and access controls that are all reasonable and expected in a large bureaucracy but not anything a small medical practice is going to be familiar with. So they'll have someone host it for them who has lawyers on staff and pay them a premium for it. That makes it "easier" and then the expense gets accounted for as something else. But now we're back to many of these systems being proprietary and miserable, because they're specialized to the limited (and extremely "enterprise") market of customers who need HIPAA compliance, and now small entities have to deal with the daily horrors of using "enterprise software" for their ordinary work.

Compliance costs also often seem low because people aren't actually complying. But then you're creating a competitive disadvantage for companies that actually follow the law.

Re: White House asks agencies to step up internet routing security efforts

#54
post #46
post #42

Earlier quoted context omitted.

Average AS Path being about 1 isn't right. For direct peer CDN content sure Even AWS has their own path that's at least 2 from GTT, Areilon, NTT, etc from wherever you connect. if you are at a data center and use blended IP Transit that's another ASN to add to the path RIPE report had the average at 3-4 in 2012.

Path length is dependent on where you stand and look at it all, of course. If anyone knows of a place in which a border router is only one (or 1.1 average) hop away from every other network on the planet, please let me know what real estate prices are like there, though. (I suspect the 1.1 figure measures something quite different - the average path length inside a CDN or similar, which probably should be closer to o…

I would wager the 1.1 figure is "average path length from CDN to end user", and quite possibly weighted by bytes served.

Most of the major players in the space (Netflix, Akamai, YouTube, Facebook, etc) have boxes inside ISP networks across major metros, so the path length to reach those ISPs' users is in fact 1 assuming a cache hit, and the RTT is certainly less than 20ms.

Re: White House asks agencies to step up internet routing security efforts

#55
post #45
post #38

Earlier quoted context omitted.

I think you missed the parent commenter's point. The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path. In practice, I suspect there will be very little impact for most traffic, since typical aspath lengths are, like, 2. (Mostly, direct peering between CDNs and ISPs if the data isn't cached within the ISP network to begin…

> The purported performance hit wouldn't be from the propagation delay on any given router, but rather from shifts in traffic resulting in a longer path. You are right, I neglected to point out that origin validation is (in the absence of shenanigans) not going to cause one path to be preferable to another: if the origin is the same AS, either both paths or neither is valid. If the origin in two paths is two differen…

You're certainly not wrong here -- it all depends what you're measuring and how. The 5-5.5 figure seems to be average length inside the internet routing tables, which is going to be skewed by smaller networks with relatively sparse connectivity and how IP space is carved up geographically.

> And perhaps also relevant to the parent's question: path length itself is a pretty poor indicator of network performance by just about any measure you can name (excepting perhaps the TTL field), and is a last resort measure used only when all else is equal.

Perhaps I focused the conversation in the wrong direction by mentioning AS path (and then further by describing the AS path between CDNs and end-users and framing that as "typical"). For a major CDN, most of the bytes served are originating from and destined to the same metro. Unless those CDNs have some serious problems with their RPKI setups, I expect that those bytes are going to continue flowing the same way they have been.

Re: White House asks agencies to step up internet routing security efforts

#56
post #51

Earlier quoted context omitted.

I really don't think this is true. What cost factors are you thinking of? We host lots of small HIPAA-complying businesses, and in my career I've consulted for many dozens more. As near as I can tell, there's actually not a whole lot to it.

This is what the government calls the "administrative simplification": https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad... It's 115 pages. Just training the staff to comprehend what's in it is a non-trivial undertaking, assuming people are actually going to comply with it. It has some fun provisions, like prohibiting disclosure of certain information except where disclosure is mandatory, which means there…

Yeah, if that's what you mean, this just isn't expensive. If you do a lot of consulting for HIPAA companies, you get HIPAA-trained a bunch (ie: you fast-forward through a lot of videos with an HTML5 video playback speed hack). They're not a big deal; maybe a hundred or two per seat?

It's not my impression that HIPAA is one of the more burdensome regs regimes, and this comment sort of reinforces that belief.

Re: White House asks agencies to step up internet routing security efforts

#57
post #56

Earlier quoted context omitted.

This is what the government calls the "administrative simplification": https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/ad... It's 115 pages. Just training the staff to comprehend what's in it is a non-trivial undertaking, assuming people are actually going to comply with it. It has some fun provisions, like prohibiting disclosure of certain information except where disclosure is mandatory, which means there…

Yeah, if that's what you mean, this just isn't expensive. If you do a lot of consulting for HIPAA companies, you get HIPAA-trained a bunch (ie: you fast-forward through a lot of videos with an HTML5 video playback speed hack). They're not a big deal; maybe a hundred or two per seat? It's not my impression that HIPAA is one of the more burdensome regs regimes, and this comment sort of reinforces that belief.

I feel kind of the opposite. Like the way "compliance" works in corporations is everyone has to sit through a boring training video so they can check the box that says "trained staff on regulatory compliance" when the real cost is not just watching the video but actually diligently putting it into practice. Which is pretty cheap for the companies who skip doing that part, admittedly, but if that's expected to be the method of "compliance" then what's the point of the law?
Post reply on HN