3 ms·
I'm pretty sure that BGP is still horribly insecure at its core, which means that all it takes for BGP hijacking to occur is for someone to forget to configure
by LambdaComplex 4y ago
I'm pretty sure that BGP is still horribly insecure at its core, which means that all it takes for BGP hijacking to occur is for someone to forget to configure their filters properly.
(See: that time that a bunch of Google traffic started getting routed through Russia. Or the time that YouTube became inaccessible to the entire world)
- thayne 4y agoWe've seen several major incidents caused by mistakes in the past few years. It's only a matter of time before an actively malicious attack on BGP causes major damage.
- the_biot 4y agoBGP by itself is insecure, but an (RPKI) infrastructure has grown up around it so that it can, and should be by now, secure. Yet BGP injection attacks (ASN or prefix theft) happen regularly. The reason is that not everybody follows the best practice here. It may well take a massively disruptive attack before this gets any better.