3 ms·
How much longer are we going to have this broken system in place, where large swaths of the internet can be hijacked at will? We have plenty of smart people, bu
by killbrad 10y ago
How much longer are we going to have this broken system in place, where large swaths of the internet can be hijacked at will? We have plenty of smart people, but here we are still...
- notliketherest 10y agoDo you have an alternative solution?
- bpchaps 10y agoWell, for one, don't allow people to get masters degrees in security if they don't know how to run ls. Met a guy like that at my last place... Next, hire more security people who just want to take things apart. There's this weird culture around "oh no, he's a hacker" that prevents legitimately curious people from getting into security. It stinks. After that, realize that your federally mandated audits are bullshit. They don't catch anything. Then, hire a pentester to try his damnedest to break in. Forbid them from using paid-for tools and give them a chance to learn, but hire someone else afterwards if they're not able to do the job. Yeah. Once you're done there, realize that your security is probably going to fail eventually, and just do the best you can with a good team of security experts and actually listen to them. Emphasis on the fucking listen to them.
- lukeadams 10y agoNot just any alternative, but one that can be implemented in a manner backwards-compatible with BGP. "Oh hey, lets get every core router on the planet to use this new protocol!" won't happen overnight. ;)
- tomjen3 10y agoCriminal hacking charges for the people involved in pushing the change and full liability for all cost in cleaning it up. This means people will be really careful and take steps to not make this mistake again.
- mryan 10y agoPerhaps criminal negligence, rather than hacking? It is an interesting thought - opening yourself to charges of criminal negligence for misconfiguring devices/software would be a big change for our industry.
- mariuolo 10y agoBGP is based on mutual trust and mistakes like this are unavoidable. All they did was announcing a better route for those prefixes and other routers obliged. I'm sure swamping their own network with unwanted traffic was punishment enough.