Live data from Hacker News

Shutting Down the BGP Hijack Factory

dyn.com

61–63 of 63 posts

Re: Shutting Down the BGP Hijack Factory

#61

Earlier quoted context omitted.

> collinear anatidae I'm stealing this phrase, please and thank you.

Why? It sounds incredibly pretentious. I think most people would appreciate Plain English [0]. [0] https://en.wikipedia.org/wiki/Plain_English

>>> collinear anatidae

> sounds incredibly pretentious. I think most people would appreciate Plain English [0].

I can't speak for most people, but I didn't know what it meant, learned it after reading it, and found it quite appropriately funny and witty. I also learned a new word. There was nothing I found pretentious about it.

I think a helpful and reasonably objective criterion in deciding this might be whether the use of the phrase was (1) necessary to send the correct message, (2) required to understand the received message, and (3) liable to send an incorrect message. If #1 = no and #2 = yes, or if #3 = yes, then you should probably avoid using it. In this case it's #1 = no and #2 = no and #3 = no, so it's fine.

Re: Shutting Down the BGP Hijack Factory

#62

Earlier quoted context omitted.

a few days, maximum. If you're $SMALLISP and you have a /22 of space, and your upstream is $MEDIUMISP, you give a LOA (letter of authorization) to $MEDIUMISP allowing them to announce your prefix to their peers and upstreams. If $MEDIUMISP can't produce that LOA on demand and the ARIN/RIPE/WHOIS/APNIC/AFRINIC whois data, email/admin/technical contacts for the /22 owned by $SMALLISP don't respond with "yup that's our…

If you think a requirement to forge a paper document is going to stop a spammer who hijacks IP space... One more count of fraud don’t mean a thing to these criminal operations.

I would not rely on it at all. At a certain point a bgp hijacker has to have some sort of physical interconnection to get to upstreams or an IX. Either equipment colocated at or near an IX, a transport circuit, something. Showing a forged LOA to somebody's colocation process is something that can be helpful in getting them to physically power off/disconnect a customer's equipment for abuse.

Re: Shutting Down the BGP Hijack Factory

#63
post #57

Earlier quoted context omitted.

If you look up the BGP routes for a Bitcanal IP address (185.215.113.235) on HE's looking glass ( https://lg.he.net/ ) it does not appear any routes are present. I believe HE's BGP page may still be out of date, or the peers are present but not active.

Last time I checked it took multiple days for it to update when routes disappear (I would assume they cache them for a while, in case it's just a temporary change).

For historical record, as of today, Hurricane isn't listed anymore, but Cogent is again, and GTT for ip6... Way to remain united against abuse... just, wow.
Post reply on HN