It's outright crazy to see US diplomats work their ass off globally only to see some lower institution ( The FCC ) with less intelligence, capabilities, etc. undermine their work and formal US geopolitical grand strategy & policy.
Or it's all just a ruse, and the joke is on us.
The SCION project (Iirc from ZTH) solved all of this and also has been extensively tried in the field.
Bullshirt. Even AWS Route53 has fallen victim to BGP hijacking. It takes 1 mistake for SHTF
This is it, find a senior network operator, pick up their kids from school, and take them home.
You now have an agent with full access over that network.
But when it happens, it impacts massive amounts of people - about once a year on average [1]. Sometimes it's censorship gone bonkers, sometimes it's likely a three-letter agency, sometimes it's fat fingers, and sometimes it's cybercriminals attempting to loot cryptocurrency wallets.
If you don't have a CAA record and somebody hijacks the prefix(es) where your webserver is hosted, they can also obtain a letsencrypt certificate and redirect your traffic.
I run a network, we do the whole shabang of RPKI, DNSSEC, and CAA. It sounds a whole lot like operators who refuse to address clear security issues. LetsEncrypt is not to blame when someone spoofs your address space.
LetsEncrypt is not a LIR/RIR, their business is not IP resources but SSL certificates. They are a CA. They have no tools available to them to address that problem.
An attacker can get around that if a CA does not use DNSSEC validation to check the CAA. But that would be a problem with the CA system.
LetsEncrypt does in fact do things to mitigate this attack, but they have nothing to do with DNSSEC: they do multi-perspective lookups, so you'd need Internet-wide routing control.
With DNSSEC, somebody can reroute traffic all they like, they cannot generate fake DNS responses that are DNSSEC valid for DNSSEC secured victim domain. So if the CAA record is properly set to only allow the dns-01 validation method for ACME, there is simply no way to obtain a false certificate even if the attacker controls all of BGP.
There's no reason not to force the industry to hold people accountable for false announcements. The privilege of announcement should be acquired by posting a significant amount of capital as a bond, from which damages can be removed when a system makes a false announcement. The vast majority of damages are a result of network operators on the subcontinent -- it is high time we figure out how to make them take the issue seriously, and pay out the nose until they do.
https://observatory.manrs.org/
There is no justification for that not to be 100% at this point.
With this data at hand, can you really claim that the industry has sucessfully self-regulated itself?
If you won’t get on board with RPKI/IRR you can’t cry foul when the rest of the Internet is paying the price to be reachable.
I am a resource holder and I pay my dues. I have no problems with paying for that privilege.
Internet access is not an inalienable right. It is a privilege. Even as it’s become increasingly more and more of a utility. Until laws start to reflect that, it is still a privilege at best.
Edit: before someone says anything about the trust anchors. Reminder, There are two overarching namespaces to the Internet. IP and DNS. You are free to ignore the authorities of both but don’t expect the rest of the Internet to play along when you want to use .billybob as your TLD.
As for IRR, one of my upstreams created an RADB entry for me on behalf of my ASN, so not too concerned there.
You can then issue RPKI ROAs.
Is BGP an attack vector that matters for the vast majority of threat models right now? I would say no. Given that: there is no need for (inevitably) poor regulation.
The point is that, in practice, the attacks are so uncommon and mitigated by so many other factors that the cost involved of further mitigation it isn't worth it.
You develop a threat model to specifically get rid of concerns like this; not to list every possible attack vector imaginable.