Someone’s Been Siphoning Data Through a Huge Security Hole in the Internet
wired.com
wired.com
Back when Usenet mattered, there used to be something called a "Usenet Death Penalty". What we need here is an "Autonomous System Death Penalty".
BGP works between "Autonomous Systems" (aka AS). ISPs almost invariably are. Bigger companies usually are. Anyone who wants to be independent of their upstream IP connection gets an AS number. The only way some ISP in Belarus can interfere with your IP packets is to announce over BGP that packets should be sent to their AS.
So anyone who was affected by some rogue ISP in Belarus should simply tell their BGP routers to totally ignore anything from that AS. Forever. And if they're a govt agency they simply tell Comcast, Verizon, AT&T, etc to drop any and all packets from that AS. To anywhere! And if it's a govt agency making this "request", there's a good chance that the Tier 1 IP providers will comply.
Done. That podunk ISP in Belarus has now been disconnected from a large part of the Internet. And good luck with them trying to get Verizon etc to undo that.
So, what the death penalty means is "you get to intentionally mess around with routing just once, then you go away forever". Now that podunk ISP can either go out of business or it can go begging IANA for a new AS number. And since ICANN (which operates IANA) answers (at least for now) to the US Dept of Commerce, it might not be too easy to get a new AS.
Yes I know the propeller-head nerds who operate the "technical" Internet would immediately think my proposal is much too harsh. But, ultimately, nerds need to understand that sometimes things are done for "political" rather than "technical" reasons. And the managers who sign the nerds' paychecks are political creatures; they almost invariably aren't nerds.
Nah, but I do think you can go fuck yourself for being so patronizing.
I don't think it's too harsh, but it would never happen, of course. It would all go out the window the first time some large corporation was affected.
There are already solutions for this (filtering inbound announcements, RPKI, etc.), but people (ISPs) don't use them. BCP38 solved the "IP spoofing" issue years ago but AS's don't even implement that.
(Side note: IANA doesn't directly issue ASNs to entities. Here in the U.S., for example, you get them from ARIN. And they'll gladly give 'em out ($500 each).)
HTTPS wasn't rolled out with 100% in a year or two either.
Disclaimer: I am an RPKI researcher.
...but what if they make a request under the guise of a different organization, to be assigned new numbe--
ONCE AND FOR ALL.
It would be nice to "send a message" by banning an AS number. The hassles involved in revoking that ban and/or obtaining a new AS number would make it unlikely that such opportunistic bad behavior would recur very often.
In this scenario, Renesys claims that it's obvious that this was no accident, but there's also mention of a Pakistani accidental hijack and a presumably accidental Chinese incident.
Intelligence agencies are masterful at the art of making things look like coincidences or accidents, and many smaller ISPs could make an accidental hijack that looks intentional and dangerous.
There is also the political problem of leaving the one nation in charge of something global (they don't like due process when it's about foreign matter). It'd better be an international body.
Depending on the providers in question, the specifics of their interconnects, and the explicits of any congestion mitigating traffic engineering, the shortest AS-Path announcement may come via an US peer.
There are a number of technical solutions for this, and interestingly I tend to apply them in Europe first.
FWIW, I found the renesys post more informative than the Wired article (though on a standalone basis it is pretty good too).
"The stakes are potentially enormous, since once data is hijacked, the perpetrator can copy and then comb through any unencrypted data freely"
Apparently then, the harm amounts to:
H1. The method is a little stealthier than the NSA's other modus operandi, the badge + "national security letter" + secrecy order, and similar conduct of other state actors.
H2. The reach extends surveillance capabilities outside the attacker's territory.
On the other hand:
M1. There is no new MITM that was not possible before. Well-encrypted traffic is still opaque, and plaintext traffic is still vulnerable, regardless whether it is hijacked BGP-wise or by the on-premises tactics.
M2. This does not go unnoticed, there is no way to force affected parties to shut up about it, and like the other wiretapping, this will bring on countermeasures. It's self-limiting.
who the hell made this map? Buster?
As for the second part of the question, no. There's no signing of any owned AS announcements. At best you can have a digest to validate your peer. But peering configurations in BGP are generally very specific, as in your peer is a host route, generally reachable directly via the transport provided by, say, a purchased circuit. So - is it trivial to swing routes on improperly configured downstream? Sure. You have to find a broken subset of routing configuration at a very critical point in the network though which would indicate a core router at a large telecom hotel is comprised or, an administrator is in cahoots with the redirect operation.
There's a lot more with regard to possibilities - but just a high level take away.
When I had control over an AS I made a very specific point to always monitor path changes for performance and security reasons all the time. If you have an AS and you're not - then you're doing it wrong with the most critical piece of your infrastructure.
Another BGP finger-pointing article that still doesn't get it right.
And this is the top comment on Hacker News?
Sigh