4 ms·
One more reason to TLS all the things although it might not be enough to discourage these practices. A VPN would not change much unless the exit node is ran by
by CloudNetworking 7y ago
One more reason to TLS all the things although it might not be enough to discourage these practices.
A VPN would not change much unless the exit node is ran by an ISP/Hosting provider not affected by the route hijacking.
- _ink_ 7y agoTrouble is, if you control the IP you can obtain a valid certificate from many CAs. BGP hijacking gives you control over an IP.
- CloudNetworking 7y agoYeah, good point. What I had in mind is this traffic being redirected for massive surveillance, traffic patterns, etc - which TLS would not fully solve, but it adds extra security or even partial obfuscation over your traffic patterns.
- OBLIQUE_PILLAR 7y agoI don't think you fully understand how BGP is currently used. None of this would happen if all ISPs had proper route filters.
- CloudNetworking 7y agoYou gotta tell me where do you buy your crystal balls mate, mine doesn't allow me to publicly assume the level of knowledge someone has over a protocol and infrastructure, specially when that person hasn't made a single comment about it. But going back to the main topic: None of this would happen if everyone was a nice person and we loved each other, either. Alas, it happens and you better add layers of defence.