40 ms·
> Some form of cryptographic ownership verification is the logical next step to prevent these things from happening. a.k.a RPKI
by alfons_foobar 2y ago
> Some form of cryptographic ownership verification is the logical next step to prevent these things from happening.
a.k.a RPKI
- immibis 2y agoI don't understand how RPKI prevents route hijacking. It just signs that a certain AS owns a certain prefix, right? How does that stop another network from pretending to be peered with my network, then announcing an indirect route, copying the signature from my valid announcement of the same prefix?
- alexdns 2y agoRPKI stops jack shit thats why ASPA was invented it just needs to be implemented
- benprone 2y agoI love how it will only ever be one leaky abstraction after another (incompleteness theorem) with a Lindy value of a few years to realize that and have to hallucinate something new, but you all keep trying to secure what physics won’t allow us to. You all should go touch grass and learn to roll with our human frailty and imperfection rather than drive yourselves mad bouncing off the walls of your language and mathematical primitives. Just remember you’re one of billions and no one needs you specifically. Just enough people overall so that life isn’t so shit one would be better off dead themselves
- cookiengineer 2y agoIt's DNS all over again, basically. > it just needs to be implemented Do you know BGPKit [1]? I'm not sure what the state of the project is, but I remember vaguely them implementing ASPA and being involved in the RFC back then. [1] https://github.com/bgpkit https://github.com/bgpkit