5 ms·
Why do these routing leaks go through China and Russia so often?
by nnnmnten 7y ago
Why do these routing leaks go through China and Russia so often?
- godzillabrennus 7y agoNever attribute to malice that which is adequately explained by stupidity.
- peteradio 7y agoThis rule is over applied. If someone doesn't hold the door for you then don't assume they did it out of malice. That would be an appropriate use of this rule. Applying it in cases where there are known and obvious instances of malice doesn't make sense.
- Bluecobra 7y agoAgreed. It’s remarkably easy to screw up BGP by misconfiguration by changing (or deleting) a route map or prefix list. There’s over 800K autonomous systems participating in BGP now, so I’m certain mistakes happen all the time but don’t get reported.
- kps 7y ago“Once is an accident. Twice is a coincidence. Three times is an enemy action.”
- OBLIQUE_PILLAR 7y agoYou should go read the nanog-l archives and see how often this happens.
- ptaipale 7y agoI guess they go through other places much more often, but that's not news. When it's through a suspicious country, it makes the news.
- rando444 7y agoThe key bit is at the end: >It also reveals that China Telecom, a major International carrier, has still implemented neither the basic routing safeguards necessary both to prevent the propagation of routing leaks nor the processes and procedures necessary to detect and remediate them in a timely manner when they inevitably occur. So basically a lack of external pressure combined with a lack of caring about preventing this.
- segfaultbuserr 7y agoChina Telecom has minimum routing safeguards. I don't know how it works exactly, but I've heard anecdotes from Chinese network operators on multiple occasions, they say you can even steal free IP addresses from China Telecom through BGP, and normally they don't even care...
- tgragnato 7y agoThe Great Firewall partially relies on spoofing IP addresses (via BGP) for active probing. Might be related?
- hiram112 7y ago> So basically a lack of external pressure combined with a lack of caring about preventing this Could someone who's paranoid guess that this is done on purpose, the goal being to capture all the packets before sending them back towards the correct ISPs?
- codedokode 7y agoBecause ISPs do not want to implement secure routing protocols.