Live data from Hacker News

Is BGP safe yet?

isbgpsafeyet.com

51–60 of 98 posts

Re: Is BGP safe yet?

#53
post #25

Any reasons on why an ISP would not implement it other than effort/cost? Just for someone like me whose networks knowledge is very naive.

They may be worried that their larger clients don't have things configured correctly, and they don't want to break things for them.

They may have older hardware that needs to be upgraded before they can use this feature.

They might even have their own way of filtering that they think is good enough.

Though, all of those really boil down to effort/cost.

Re: Is BGP safe yet?

#55

Earlier quoted context omitted.

I get the same result for A&A, but frankly I trust them more than some random site with (apparently) an axe to grind.

My hope would be that A&A have a process manually whitelisting the route that made the test fail because in fact (as of course it would be) it's actually deliberately not signed but it is really their route. But on some level that's like assuming the reason the guy with the handgun is on your plane is that he's a sky marshal and not that some idiot let a concealed handgun through security. I mean, sure, maybe, but, m…

And now thanks to jsty's sibling comment I don't have to ask, thanks! It does seem like they've been more than "cautious" enough at this point and should just implement RPKI.

Re: Is BGP safe yet?

#56

Earlier quoted context omitted.

Hmm, I'd disagree. The fact that Anapaya Systems (the for profit company mentioned) has the only commercial implementation/adjacent software is a problem, yes. But "snake oil" doesn't quite match up with the fact that SCION right now provides the backbone for the Swiss financial network moving 200 billion CHF each day [1], so at least some level of workable technology has to be there. And for no one to be taking it s…

200billion CHF....how big is that in bandwidth?

2.6 million transactions per day [0], which in ISO 20022 XML format messages works out to (rough guess) 20GB per day for an average of 1.8Mbps...

[0]: https://www.scion.org/ssfn-scion/

Re: Is BGP safe yet?

#57

RPKI doesn't make BGP safe, it makes it safer . BGP hijacks can still happen. RPKI only secures the ownership information of a given prefix, not the path to that prefix. Under RPKI, an attacker can still claim to be on the path to a victim AS, and get the victim's traffic sent to it. The solution to this was supposed to be BGPSec, but it's widely seen as un-deployable.

[flagged]

Re: Is BGP safe yet?

#58

RPKI doesn't make BGP safe, it makes it safer . BGP hijacks can still happen. RPKI only secures the ownership information of a given prefix, not the path to that prefix. Under RPKI, an attacker can still claim to be on the path to a victim AS, and get the victim's traffic sent to it. The solution to this was supposed to be BGPSec, but it's widely seen as un-deployable.

[flagged]

[deleted]

Re: Is BGP safe yet?

#59
i'm getting:

  Free SAS ISP signed unsafe
but when testing i'm getting a success

Your ISP (Free SAS, AS12322) implements BGP safely. It correctly drops invalid prefixes. Tweet this → Details fetch https://valid.rpki.isbgpsafeyet.com correctly accepted valid prefixes

fetch https://invalid.rpki.isbgpsafeyet.com correctly rejected invalid prefixes

Re: Is BGP safe yet?

#60
post #20

Earlier quoted context omitted.

SCION is generally considered snake oil within the network operator community. Its weird single vendor for profit company that ships it's software, the fact that no router hw asic fwding supports what they want to do and then the general scummy inclusion of block chain / crypto as well as some "green washing" for PR hype. Sure the swiss have their toy but no one is taking it seriously.

Hmm, I'd disagree. The fact that Anapaya Systems (the for profit company mentioned) has the only commercial implementation/adjacent software is a problem, yes. But "snake oil" doesn't quite match up with the fact that SCION right now provides the backbone for the Swiss financial network moving 200 billion CHF each day [1], so at least some level of workable technology has to be there. And for no one to be taking it s…

I don't think the swiss banking network is really the right thing to point to. Folks measure networks in bps/pps, not financial transactions - nevermind the actual control plane bits (num of prefixes, as paths, etc.). Plus it's all within one country where you have the luxury of being able to directly influence and steer those companies into adopting this.

As for BT - they're just one broadband ISP operating primarily in a single country. I don't see that moving the needle - you're missing CDNs, traditional large scale "tier 1s" and cloud or large hosting networks.

RPKI got to where it is today through community engagement by folks like Job S. and others - hitting the conferences, direct engagement with operators and raising the bar from a software quality and standards perspective - which still continues today. That's how you get the internet to adopt something that is considered the new normal.

As for your ISP list - I know there are networks listed there that aren't running scion in a production capacity (perhaps you can run scion in a virtualized environment on top of them which is different than those companies running it on their production network).

As for the block chain - it was all the Sui stuff.

Post reply on HN