Quick fix for an early Internet problem lives on a quarter-century later
washingtonpost.com
washingtonpost.com
Looking back, it's doubtful that a secure version up front would have worked. Routers were pretty feeble back then, and getting them to verify crypto signatures for advertisements would have been a non-starter.
This is especially true since there are still many issues with the secure replacements when it comes to key distribution issues, manipulating path costs, etc. With all of the modern crypto we have now, it's still a non-trivial problem to solve.
But they cost a lot more and required more technical rigor to implement (yes I am looking at you Sprint/ Microsoft) and some times Good enough for jazz is the way to go.
- not controlled by you
- tell you about their own view of the Internet
- and tell you about views of the Internet passed on from other neighbors
You can arrange to absolutely trust a given neighbor to be that neighbor, but until every BGP speaker in the world has that relationship, you can't trust the data that they pass on.
And every BGP speaker in the world has both direct controls (advertise this AS, don't advertise that AS) and influential controls (pretend that this AS is farther away than it is, prefer this AS here and not there because it's cheaper for us) that are both necessary and desirable, because money constrains what engineering can do.
http://www.cisco.com/web/about/ac123/ac147/archived_issues/i...
and
https://web.eecs.umich.edu/~zmao/eecs589/papers/draft-white-...
provide more detail on this.
And yes, HTTPS is rather a joke. But what about properly implemented SSH, IPSec or OpenVPN?
Solving the trust problem in routing would require ISPs to manually whitelist which AS advertisements are valid on any given interconnect - you know something is wrong if Comcast advertises some Virgin Media network, or whatever.
Encryption by itself can't solve trust. It can only protect against MITM.
https://www.youtube.com/watch?v=_Mn4kKVBdaM BGP at 18: Lessons In Protocol Design