Is regulated BGP security coming?
blog.apnic.net
blog.apnic.net
The FCC and by extension the USA should GTFO and let the multi stakeholder models do their work.
Was that because the government mandated that outcome?
When Let's Encrypt eventually stops behaving in an altruistic fashion, we'll stop doing near-mandatory TLS.
Regardless, for HTTP there's an entire 'year 2000's web' worth of people out there using browsers that can access the non-corporate web. As the corporate web diverges with things like stateful HTTP extensions, UDP HTTP, and CA TLS only implementations (if not spec) there's no need to switch to a niche protocol like Gemini. Just making a normal website on the web is enough to bring back the old small web environment. As a human person not operating under a profit motive and just doing things for kicks this is just fine. A silver lining like how usenet is actually good again now that most people don't get it from their ISP.
Their root CA can't really be revoked either unless you want to turn off most of the internet. Not that big CAs would ever suggest anything like that in the name of "security"
Has it really been so many years since people used to do tcp injections and walk around coffee shops or whatever returning results faster than the internet server and injecting goatse?
You guys have forgotten who tls protects.
The risk comes from the absolutely bonkers corporate/institutional use cases of automatically executing all random unverified programs sent to you. When you remove this crazy use case suddenly all the problems (and bonkers requirements) go away.
Seeing a goatse is not the end of the world and actual MITM injection attacks like you describe are rather rare now. I miss when wifi use to be open and that issue mattered.
Though I'd prefer a decentralized/pinned approach when single point of failure (read as: CA) is the alternative.
... and coretx's "nobody wants to peer with an idiot" is clearly not working here. These networks are still being peered with.
Maybe the regulators should start by regulating only international peering.
The idea to regulate only international peering looks best so far. It's much like (m)any other regulations that are only present on the border between countries, and are absent inside.
The concepts of "national" and "international" don't map very well to the internet.
Many companies run multiple ASes, and many companies are peering at IXPs all over the world...
With China specifically it could work, because they internally control their points of peering with the rest of the world. With Russia, less so. With a "normal" Western country, likely infeasible, but in the latter case the internet access is not controlled and weaponized by the government, so there is no real need, self-regulation suffices.
[0] corporations being legally people.
If I have the underlying context right here, this is effectively regulation prohibiting people from lying in the course of their normal operations, which smells a lot like a typical fraud statute, and government restrictions on fraud-like things have almost always been upheld as constitutional. (The main exception I'm aware of is US v Alvarez, but even there, SCOTUS said it was only a problem to ban lying for lying's sake; banning lying with the purpose of getting a benefit is acceptable).
Government is a “multi stakeholder” model. Whether that or private you get a committee determining based upon the biases of the committee.
Same old human bullshit all the way down no matter the semantic bullshit that annotates how the technical decision was made.
a.k.a RPKI
You all should go touch grass and learn to roll with our human frailty and imperfection rather than drive yourselves mad bouncing off the walls of your language and mathematical primitives.
Just remember you’re one of billions and no one needs you specifically. Just enough people overall so that life isn’t so shit one would be better off dead themselves
> it just needs to be implemented
Do you know BGPKit [1]? I'm not sure what the state of the project is, but I remember vaguely them implementing ASPA and being involved in the RFC back then.
“…a idiot…”
You’re right about peering with idiots. A shame social media is so popular since that’s about all it gets us. Peering with idiots.
It's outright crazy to see US diplomats work their ass off globally only to see some lower institution ( The FCC ) with less intelligence, capabilities, etc. undermine their work and formal US geopolitical grand strategy & policy.
Or it's all just a ruse, and the joke is on us.
The SCION project (Iirc from ZTH) solved all of this and also has been extensively tried in the field.
Bullshirt. Even AWS Route53 has fallen victim to BGP hijacking. It takes 1 mistake for SHTF
This is it, find a senior network operator, pick up their kids from school, and take them home.
You now have an agent with full access over that network.
But when it happens, it impacts massive amounts of people - about once a year on average [1]. Sometimes it's censorship gone bonkers, sometimes it's likely a three-letter agency, sometimes it's fat fingers, and sometimes it's cybercriminals attempting to loot cryptocurrency wallets.
If you don't have a CAA record and somebody hijacks the prefix(es) where your webserver is hosted, they can also obtain a letsencrypt certificate and redirect your traffic.
I run a network, we do the whole shabang of RPKI, DNSSEC, and CAA. It sounds a whole lot like operators who refuse to address clear security issues. LetsEncrypt is not to blame when someone spoofs your address space.
LetsEncrypt is not a LIR/RIR, their business is not IP resources but SSL certificates. They are a CA. They have no tools available to them to address that problem.
An attacker can get around that if a CA does not use DNSSEC validation to check the CAA. But that would be a problem with the CA system.
LetsEncrypt does in fact do things to mitigate this attack, but they have nothing to do with DNSSEC: they do multi-perspective lookups, so you'd need Internet-wide routing control.
With DNSSEC, somebody can reroute traffic all they like, they cannot generate fake DNS responses that are DNSSEC valid for DNSSEC secured victim domain. So if the CAA record is properly set to only allow the dns-01 validation method for ACME, there is simply no way to obtain a false certificate even if the attacker controls all of BGP.
There's no reason not to force the industry to hold people accountable for false announcements. The privilege of announcement should be acquired by posting a significant amount of capital as a bond, from which damages can be removed when a system makes a false announcement. The vast majority of damages are a result of network operators on the subcontinent -- it is high time we figure out how to make them take the issue seriously, and pay out the nose until they do.
https://observatory.manrs.org/
There is no justification for that not to be 100% at this point.
With this data at hand, can you really claim that the industry has sucessfully self-regulated itself?
If you won’t get on board with RPKI/IRR you can’t cry foul when the rest of the Internet is paying the price to be reachable.
I am a resource holder and I pay my dues. I have no problems with paying for that privilege.
Internet access is not an inalienable right. It is a privilege. Even as it’s become increasingly more and more of a utility. Until laws start to reflect that, it is still a privilege at best.
Edit: before someone says anything about the trust anchors. Reminder, There are two overarching namespaces to the Internet. IP and DNS. You are free to ignore the authorities of both but don’t expect the rest of the Internet to play along when you want to use .billybob as your TLD.
As for IRR, one of my upstreams created an RADB entry for me on behalf of my ASN, so not too concerned there.
You can then issue RPKI ROAs.
Is BGP an attack vector that matters for the vast majority of threat models right now? I would say no. Given that: there is no need for (inevitably) poor regulation.
The point is that, in practice, the attacks are so uncommon and mitigated by so many other factors that the cost involved of further mitigation it isn't worth it.
You develop a threat model to specifically get rid of concerns like this; not to list every possible attack vector imaginable.
1. LACNIC and RIPE have 100 year validity on their trust anchors.
2. All RIR trust anchors are valid for all IPs (past their allocations), due to, I assume, inter-RIR transfers.
Unless I'm mistaken a web application firewall is for a corporation to protect their intranet and not applicable for a core router.
A WAF and any other Perimeter security product can be used to enforce geoblocking (and other sorts of filtering) from an inbound standpoint at L7 (and why they are increasingly being subsumed under the API Security/Gateway segment or the SSE segment if you want to merge L3/4 and L7 security capabilities)
> I think either you misunderstand me or I misunderstand you
Probably on my end.
I mean any ISP can check if a packet leaving their network is actually a network they have under their control, routing doesn't have anything to do with that?
It doesn't work in the "Internet core". If you're Verizon and you got a packet from Comcast that says it's originally from Cogent, how do you validate that? This router that happens to be checking the packet prefers to send packets to Cogent via Sprint, but that doesn't mean Cogent also prefers to send packets to you via Sprint. Each router can have a different preference, too. (Example scenario only)
I think many providers now also limit UDP which might become an issue when http/3 gets more adopted.
(Tier 2 providers are those with lots of interconnections, but not the whole world, just regionally. Tier 3 providers are those who just buy wholesale internet service from another provider and don't have many if any other interconnections.)
No sane provider restricts UDP. You might be thinking of one of the more obscure protocols like SCTP.