6 ms·
Someone’s Been Siphoning Data Through a Huge Security Hole in the Internet
- ak217 13y agoVery interesting - is BGP fundamentally vulnerable to this attack? Is there a way to put the equivalent of a certificate revocation list on top of BGP?
- windexh8er 13y agoTo your first, yes and no. Most BGP implementations are configured in such a way to protect consumption of prefixes that are larger than normal. A large prefix would be a /30 for instance in IPv4. This generally is a very specific route and is considered a bad thing in the global BGP table. Why? Because you don't advertise 2 reputable addresses at a time, you go for smaller prefixes to make the table manageable to make routing decisions on. So the no part is that generally all configurations of BGP will prevent the more specific routes like this. However it's just a numbers game of advertising a prefix one bit larger than the real advertised by, say splitting that network in half. As for the second part of the question, no. There's no signing of any owned AS announcements. At best you can have a digest to validate your peer. But peering configurations in BGP are generally very specific, as in your peer is a host route, generally reachable directly via the transport provided by, say, a purchased circuit. So - is it trivial to swing routes on improperly configured downstream? Sure. You have to find a broken subset of routing configuration at a very critical point in the network though which would indicate a core router at a large telecom hotel is comprised or, an administrator is in cahoots with the redirect operation. There's a lot more with regard to possibilities - but just a high level take away.
- windexh8er 13y agoAnd the best solution to replace BGP out there is LISP. However, even in LISP there are fundamental flaws that weren't designed for from inception. When I had control over an AS I made a very specific point to always monitor path changes for performance and security reasons all the time. If you have an AS and you're not - then you're doing it wrong with the most critical piece of your infrastructure.
- jlgaddis 13y agoHeh, most AS's don't even adhere to BCP38 and you expect them to be monitoring for path changes and hijacks?
- windexh8er 13y agosigh Another BGP finger-pointing article that still doesn't get it right.
- hornd 13y agoCould you explain it better for the uneducated like me?
- rsingel 13y agoSo the totality of your criticism of a story from one of the best security reporters in the business is sigh and "doesn't get it right"? And this is the top comment on Hacker News? Sigh
- kintamanimatt 13y agoNew comments tend to be placed at or near the top so they're given just enough visibility to be read and voted on. The top comment doesn't necessarily mean it's the most popular.
- windexh8er 13y agoBest security reporter does not equte to any level of understanding of BGP. You're asserting a false parallel. And, see my other comments.
- AsymetricCom 13y agoNever mind that, the article is simply written horribly.
- r0h1n 13y agoHere's the post at Renesys upon which this article is based: http://www.renesys.com/2013/11/mitm-internet-hijacking/ http://www.renesys.com/2013/11/mitm-internet-hijacking/ FWIW, I found the renesys post more informative than the Wired article (though on a standalone basis it is pretty good too).
- runjake 13y agoWe know. The article you linked to is mentioned and linked in the Wired article at least twice, if you read through it.
- r0h1n 13y agoI know you know :) Just wanted to say that there's a difference in the way both were written, and that I personally found the Renesys piece more interesting. I don't think all readers will have the time to read two long pieces on the same subject, so a bit of context helps.
- ommunist 13y agoThat someone in Minsk may well be US operative working at huge IBM facility in Minsk.
- Anon84 13y agoRelated discussion https://news.ycombinator.com/item?id=6773889 https://news.ycombinator.com/item?id=6773889
- callesgg 13y agoIs this realy a bug?
- PhantomGremlin 13y agoBah. Real simple cure for this nonsense. Too bad it's unlikely to happen. Back when Usenet mattered, there used to be something called a "Usenet Death Penalty". What we need here is an "Autonomous System Death Penalty". BGP works between "Autonomous Systems" (aka AS). ISPs almost invariably are. Bigger companies usually are. Anyone who wants to be independent of their upstream IP connection gets an AS number. The only way some ISP in Belarus can interfere with your IP packets is to announce over BGP that packets should be sent to their AS. So anyone who was affected by some rogue ISP in Belarus should simply tell their BGP routers to totally ignore anything from that AS. Forever. And if they're a govt agency they simply tell Comcast, Verizon, AT&T, etc to drop any and all packets from that AS. To anywhere! And if it's a govt agency making this "request", there's a good chance that the Tier 1 IP providers will comply. Done. That podunk ISP in Belarus has now been disconnected from a large part of the Internet. And good luck with them trying to get Verizon etc to undo that. So, what the death penalty means is "you get to intentionally mess around with routing just once, then you go away forever". Now that podunk ISP can either go out of business or it can go begging IANA for a new AS number. And since ICANN (which operates IANA) answers (at least for now) to the US Dept of Commerce, it might not be too easy to get a new AS. Yes I know the propeller-head nerds who operate the "technical" Internet would immediately think my proposal is much too harsh. But, ultimately, nerds need to understand that sometimes things are done for "political" rather than "technical" reasons. And the managers who sign the nerds' paychecks are political creatures; they almost invariably aren't nerds.
- bowlofpetunias 13y agoYou may want to consider omitting the final paragraph of your argument.
- PhantomGremlin 13y agoYeah, I know. In re-reading that paragraph it does seem over-the-top. As you point out, it could (should?) probably have been omitted entirely.
- downer91 13y agoIt's simple! Just ban the number they've been assigned and that solves the problem once and for all! ...but what if they make a request under the guise of a different organization, to be assigned new numbe-- ONCE AND FOR ALL.
- apierre 13y agoMaybe Dr Evil in his secret volcano lair.
- stevehawk 13y agoa map where blue is land? who the hell made this map? Buster?
- ds9 13y agoLet's assess the damage. Says the article: "The stakes are potentially enormous, since once data is hijacked, the perpetrator can copy and then comb through any unencrypted data freely" Apparently then, the harm amounts to: H1. The method is a little stealthier than the NSA's other modus operandi, the badge + "national security letter" + secrecy order, and similar conduct of other state actors. H2. The reach extends surveillance capabilities outside the attacker's territory. On the other hand: M1. There is no new MITM that was not possible before. Well-encrypted traffic is still opaque, and plaintext traffic is still vulnerable, regardless whether it is hijacked BGP-wise or by the on-premises tactics. M2. This does not go unnoticed, there is no way to force affected parties to shut up about it, and like the other wiretapping, this will bring on countermeasures. It's self-limiting.
- gwu78 13y agoOff-topic: I alwyas liked the idea of like loose source routing. And the original netcat supports it. Does your kernel support it? Would you use it if you could?
- cpsempek 13y agoI love the picture of Iceland.
- coldcode 13y agoSomeone or the NSA? If I was them I would hijack some poor country ISP and siphon everything through them. At this point assuming it's the NSA should be the default assumption. Remember that Snowden's encrypted data (assuming it's real) includes everything not yet public. So likely we only know a fraction. Thus assuming NSA is probably safe.
- AsymetricCom 13y agoMaybe it was Santa Claus and he used Iceland because it reminds him of the Arctic. During this time of year, assuming it's Santa Claus should be the default assumption. Remember that He is "making a list" and "checking it twice". So assuming it's Santa Claus is the best bet.
- IvyMike 13y agoI think from the NSA's perspective this is both crude and unnecessary. They have better ways.
- question612 13y agoI can't understand it.It seems to be business so, why did`nt make`em pay ?