5 ms·
Who is the authority on the integrity of routing?
by jtdev 6y ago
Who is the authority on the integrity of routing?
- colde 6y agoThe owner of the netblock.
- deleted 6y ago[deleted]
- superkuh 6y agoThe certificate authority that signs the routes. So yeah, this will centralize control of routing and expose it to things like government censorship and corporation exploitation. Sometimes the wild west is better than an authoritarian government. Like DNSSEC this is only good for megacorps and nationstates. If anything it will expose human people to more abuse and exploitation.
- ancarda 6y agoHas this happened as HTTPS adoption has increased? Do you believe BGP RPKI will be different? A lot of threads about rising use of encryption seem to have this fear - that it will be used against us at some point, and I'd really like to understand where this fear comes from Even taking a recent example of Parler; as far as I know it had HTTPS support and the corresponding X.509 cert was never revoked - instead hosting and I think the domain was terminated
- jtdev 6y agoIt seems like we should be more focused on the possibility of this being abused rather than asking if it’s been abused yet.
- skynet-9000 6y agoIn this case, certificate revocation being so broken probably saved Parler from having it being done to them.
- superkuh 6y agoLet's put it another way. Do you think the Arab spring and Libyan civil war would've taken place if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? I don't. Now think of that on kind of thing happening with routes. Yikes. At least with the way things are now there's no ground truth. Every AS has it's own perception of the routing table and the ability to act on it. That's the way it should be. Securing BGP means less security because there is no global consensus even implied in the protocol. Securing BGP means centralizing BGP, not security.
- dane-pgp 6y ago> if DNSSEC had been in place and Gaddafi had control of bit.ly's TLS keys? But Gaddafi was already in control of all Libyan ISPs and the .ly ccTLD. Why would DNSSEC have made his job any easier? Also, surely Facebook was more instrumental in the Arab Spring than bit.ly was.[0] If anything, the lack of DNSSEC made it easier for Gaddafi to spoof DNS results for facebook.com and other sites. [0] https://en.wikipedia.org/wiki/Social_media_and_the_Arab_Spring https://en.wikipedia.org/wiki/Social_media_and_the_Arab_Spri...
- tptacek 6y agoGaddafi was not, to my knowledge, in control of any WebPKI CA=True certificates.
- dane-pgp 6y agoObviously for facebook.com he would only be able to serve an unencrypted HTTP version (and HSTS-preloading would prevent that working in most cases), but by controlling the .ly ccTLD he could acquire TLS certificates for any "national" site. I'm not sure if any of that is relevant, though.
- tialaramex 6y agoFor what it's worth this Gaddafi -> Libya -> bit.ly connection has to be one of the weirdest beliefs you've exhibited over a long period. At first I thought it was just an extended bit, like the whole Cody Johnston "teleporting boars" thing [0] But I don't think it can be, I think you're serious and er, that's not great basically. Maybe take a few minutes to think about it more clearly, discuss it with somebody you trust, and see if you can't figure out where you went wrong. [0] https://twitter.com/drmistercody/status/1046558632878399489 https://twitter.com/drmistercody/status/1046558632878399489
- im3w1l 6y ago> Has this happened as HTTPS adoption has increased? This is such a naive way of looking at things. First a trap is built. Then you wait. Years. Only when the trap is filled to the brim does it snap shut. Many examples of that pattern.
- simonjgreen 6y agoActually, it's a level playing for all ISPs. So if you want safety, support your smaller ISPs rather than the big names who are often under the surveillance radar and will still be using RPKI.