4 ms·
I'm not a networker, but sounds like from a correctness standpoint, a problem on Fastly's end -- they're reusing frontend IPs for distinct sets of machines, and
by _wmd 8y ago
I'm not a networker, but sounds like from a correctness standpoint, a problem on Fastly's end -- they're reusing frontend IPs for distinct sets of machines, and traffic directed to the 'wrong' PoP is dropped hard rather than attempting any kind of internal routing
Of course that kind of routing would create a potential bottleneck for an attacker to exploit ("simply" force traffic to the wrong IPs to the wrong PoP, assuming $attacker had this level of access to the backbone), but that's the problem Fastly are supposedly paid to deal with
Their scheme is fine and dandy with a protocol like DNS where UDP retries are transparent and TCP is a tiny fraction of weird traffic, but for business applications handling credit cards, surely the occasional RST is already too many
Or another way to look at it, basically they're saying their IP addresses are special snowflakes and actually the full address includes the route, and source networks are wrong for assuming things work the way they're supposed to everywhere else on the Internet
- windowsworkstoo 8y agoNot really. Anycast is fairly standard and usable for stateful connections - the issue is again middleboxes fucking with stuff and a weird default of incorporating TTL in the ECMP hashing algo
- toast0 8y agoExpecting all flows to have all packets on a flow delivered via the same path is extremely optimistic.
- deleted 8y ago[deleted]
- deleted 8y ago[deleted]
- jiveturkey 8y ago> Anycast is fairly standard and usable for stateful connections please cite some sources to back this up. i find this statement surprising.
- cnst 8y ago> Of course that kind of routing would create a potential bottleneck for an attacker to exploit ("simply" force traffic to the wrong IPs to the wrong PoP, assuming $attacker had this level of access to the backbone) It's actually simpler than that — the state of the TCP connection is controlled by the hosts to the TCP connection, so, all it takes is for a "client" host to pretend that the connection has already been established (sending a single packet alleging as such) — no need for any special access to any backbone.