You can potentially BGP hijack a domain (via DNS) and e-mail (via SMTP) as a private individual so easily. Image a nation-state. These protocols only have bandaids like DNSSEC and RPKI stopping you from doing it, which both have painfully small adoption and don't realistically stop a determined attacker.
This could happen at anytime by an individual with the motivation, and it only needs to be successful for a few minutes to gain access to a huge amount of private data.
This has to be a huge national security risk, right? Why do we not take it seriously?
No you can't.
Well various attacks exist against ip routing, dns, email forging etc,in practice they are really hard to pull off as an individual who isn't in a privileged network position (with possible exception of email forging. That one is a bit easier depending on stuff)
> You can potentially BGP hijack a domain (via DNS)
I think you might be confusing stuff here. Unless you bgp hijack the nameserver, but if you have that ability, why not go after the site directly?
Yes you can
> they are really hard to pull off as an individual who isn't in a privileged network position
“privileged network position”, as in someone with a couple of thousand dollars to spend.
Using this, you can advertise any IP prefix you want. Since a lot of providers advertise /23+ as well, if you hijack the /24, you will always be the BGP best path and will be able to accomplish a full internet-wide hijack.
Of course, the task requires a few weeks of planning and execution, but that doesn't stop it from being possible.
If you are a nation-state, you already have all of the above, and nobody to hold you accountable for using it.
Few weeks? With most providers you can get this done within 24h from the initial email to sales@
I’ve never had to deal with colo or think about hardware to have my IPs announce.
Shorter ASPath, planning which Tier 1/2 is the best to hijack from, and lack of LOA requirement or RPKI.
If an attacker wants to do this - they don't want to "just" cause damage. This is a limited opportunity. They want to do it right, and that takes planning.
I do agree that your idea is possible, but I don't think it captures the full severity of the issue.
domains and BGP don't really interact, can you explain what you mean?
At this point you can give any answers you like for such queries.
If the domain has DNSSEC, you either have to choose answers you've seen that may be misleading (e.g. old but still not expired answers) or some resolvers might notice your answers are bogus.
Many domains today don't have DNSSEC, so, you could give any answer and it will be indistinguishable from an answer by the legitimate authoritative DNS servers. Nobody would know any different.
Now that you can cause traffic to go wherever you want, you can easily satisfy most of the Ten Blessed Methods and get yourself certificates in the Web PKI ("SSL Certificates") or whatever else you needed to achieve.
In the distant future sometimes it may be possible that a recursive is able to assure itself that the answer is genuine via DPRIVE [DNS over HTTPS, or TLS, or QUIC or whatever else is invented] instead but in practice most of the routes by which we could get genuine answers ultimately rely on DNSSEC (DPRIVE is still doing something useful for you - privacy benefits, particularly oblivious transfer could mean you get trustworthy answers with a promise that your honest broker doesn't know what you asked, and the authoritative servers know what was asked but not who asked it)
The lion share of mailers don't check even them.
What do you suppose you can do to give that effect?
In the US SMS case LOAs work because it's in the interests of the people who can make it happen to make it happen. The LOA is just to cover their backsides, "Why did you redirect this Michigan man's SMS messages and thereby enable his life savings to be stolen?" "Oh we had this Letter of Authorization, so we honestly believed it's what he wanted". They don't believe that, but their lawyers are confident that it's enough excuse that, at least until after somebody powerful is inconvenienced, it will hold up.
But nobody benefits from helping you give effect to your (convincing but bogus) LOA for my email. My ISP doesn't want anything to do with this work, if you're lucky they'll tell you that it's none of their business - more likely it just goes in the round file and you never hear back from them.
There is no central clearing house for email that you can give a few bucks to for my emails so long as you have an LOA to keep them on the right side of the law. Instead for email everybody involved is getting paid by me, not by you, so they've got no reason to help you at all.
To any ISP as I ask them to announce your MX IP addresses.
> There is no central clearing house for email that you can give a few bucks to for my emails so long as you have an LOA to keep them on the right side of the law.
There is, it’s called BGP.