https://observatory.manrs.org/
There is no justification for that not to be 100% at this point.
With this data at hand, can you really claim that the industry has sucessfully self-regulated itself?
https://observatory.manrs.org/
There is no justification for that not to be 100% at this point.
With this data at hand, can you really claim that the industry has sucessfully self-regulated itself?
If you won’t get on board with RPKI/IRR you can’t cry foul when the rest of the Internet is paying the price to be reachable.
I am a resource holder and I pay my dues. I have no problems with paying for that privilege.
Internet access is not an inalienable right. It is a privilege. Even as it’s become increasingly more and more of a utility. Until laws start to reflect that, it is still a privilege at best.
Edit: before someone says anything about the trust anchors. Reminder, There are two overarching namespaces to the Internet. IP and DNS. You are free to ignore the authorities of both but don’t expect the rest of the Internet to play along when you want to use .billybob as your TLD.
As for IRR, one of my upstreams created an RADB entry for me on behalf of my ASN, so not too concerned there.
You can then issue RPKI ROAs.
Is BGP an attack vector that matters for the vast majority of threat models right now? I would say no. Given that: there is no need for (inevitably) poor regulation.
The point is that, in practice, the attacks are so uncommon and mitigated by so many other factors that the cost involved of further mitigation it isn't worth it.
You develop a threat model to specifically get rid of concerns like this; not to list every possible attack vector imaginable.