Iraq Blocks Telegram, Leaks Blackhole BGP Routes
kentik.com
kentik.com
These announcement typically only intended for downstream providers (regional Iraqi ISPs in this case) but sometimes "leak" upstream - erroneously announced to the open internet which sometimes cause outages for the whole world. This is what famously happened with YouTube when Pakistan tried to do the same thing in 2008.
In this case the routes "leaked" upstream again like what happened before but seems like outage was mostly prevented by something called RPKI which is basically a technology to attest who really owns which prefix.
And yes. It is a problem. If your upstream does skulduggerous things, you can't "route around it" from the standpoint of being an endpoint. Your packets will go where your ISP says they go.
Unless...
You take a bit of the routing decision out of their hands, which takes a bit of footwork on your part. For instance, setting up a VPN to a network zone unpolluted by the faulty prefix announcement, which is basically going to be any non downstream of the hostile ISP provider.
Once you're out of that routing zone, normal network visibility is restored. Odds are even a national scale backbone provider is not going to be able to effectively block traffic that's routing out to a proxy, so all the the ISP has really done is made life more difficult for people unaware of how to set up such an arrangement.
Which now that you know about this, it is your duty to spread the knowledge of how to do so far and wide. If someone wants to block it, then that's all the justification needed for frustrating those efforts.
Today's highly-centralized server-client Web architecture does not have this property. Some P2P protocols are closer to the spirit of this quote.
Conclusion: architecture of "the Net" matters a lot (the original quote didn't use the term "Internet").
The quote has nothing to do with automatically and invisibly routing around censorship, e.g. a techno-system that somehow always works to oppose censorship. It's just that people will reconnect stuff eventually, bypassing any block somehow. At worst there are always sneakernets.
Then you need a zero-day, install software that turns almost all phones into nodes and there is nothing any authority can do to prevent communication ever.
edit: Adding China FW
Also, most people would definitely not appreciate their personal devices being hijacked as a mesh network for their neighbors teen watching tiktoks or whatever. Any such zero day exploit would be patched pretty quickly.
Example: Guy living in NY on the regular, traveling once a year to cuba and back. So somebody with a message to cuba, passes it along - it rides to the airport, and hops from a employee cellphone to the guy boarding his holiday plane. Add the transmission software being a virus for plausible deniability..
I'm all for balancing the power of governments with the power of their citizens but mesh networks have so many practical downsides that they are just Not The Way tbh.
Telegram has spread their hosting across the three big cloud providers; AWS, Azure, and Google Cloud. It is most likely the cloud providers who have enabled RPKI as a default.
Resource Public Key Infrastructure (RPKI) is a security framework by which network owners can validate and secure the critical route updates or Border Gateway Protocol (BGP) announcements between public Internet networks. BGP is essentially the central nervous system of the Internet and one of its fundamental building blocks. The main function of BGP is to facilitate efficient routing between Autonomous Systems (AS), by building and maintaining the Internet routing table. The Internet routing table is effectively the navigation system of the Internet and without it, traffic would be unable to flow between its constituent networks. Unfortunately, routing equipment alone cannot distinguish between legitimate and malicious routing announcements, but network operators who implement RPKI validation and filtering can choose to reject announcements from networks not authorized to advertise those resources. In other words, RPKI is essentially a secure identification system for the BGP route information between autonomous systems.
For more information, there is a good article here: https://phoenixnap.com/kb/rpki
Many will likely never use it. ARIN, for example, does not allow "legacy" networks to use RPKI unless they sign a registration agreement (and start paying for the privilege.)
There are five TAs which are RIRs (Regional Internet Registries) AFRINIC, APNIC, ARIN, LACNIC, and RIPE.
So similar to how your web browser can determine a website is valid or not by checking the certificate is signed by a CA. A network can determine a route is valid or not by checking the ROA is signed by a TA.
Basically, RPKI is to BGP as things like DKIM are to email, or DNSSEC is to the DNS system.
Different AS's announce route prefix's to attract packets from other AS's. Orgs like ARIN and such act as trust anchors (CA's, in Web of Trust parlance) for Network operators who use RPKI clients to validate incoming BGP announcements cryptographically against the trust anchor list.
The idea would be that an Iraqi telco could announce they terminate a prefix they don't, blackholing the traffic originating from within their network to those prefixes, but they wouldn't get the cryptographic vouch by their RIR, so other AS's would ignore altering their routing tables. Insulating the damage to essentially inside the network that was making the fraudulent announcement.
It could even still be worked around by people internal to that network as long as they cross into another AS's routing domain, say by VPN, which would then allow traffic to route as normal.
There is the argument to be made that RPKI is only as useful as the numbering authorities are capable of maintaining a strict position of neutrality. Thus is the way of all of all Trust. It is alas, the best we have.