TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Helping to secure internet routing

116 pointsby mcbainover 4 years ago

10 comments

skynet-9000over 4 years ago
With RPKI, what happens if the RIR (i.e., ARIN, RIPE, etc)&#x27;s Certificate Authority decides to revoke the certificate for the netblock?<p>Does the netblock &quot;owner&quot; suddenly see all of its traffic dropped?<p>If so, this is a far more powerful takedown than simply a domain or CA takedown or revocation and takes immediate effect across the globe.<p>It&#x27;s basically a giant &quot;kill switch&quot; and centralizes enormous power in the RIR&#x27;s, which still have to operate according to the laws of the jurisdiction that they operate in, but span country laws.<p>Follow up question. What happens when a judge in (any country) issues legal notice to terminate the certificate to the RIR of a region for a netblock of an entity <i>in another country</i>?
评论 #25769810 未加载
评论 #25770499 未加载
评论 #25769957 未加载
ancardaover 4 years ago
&gt;We are happy to have over 99% of our IPv4 and IPv6 -Space covered under a Route Origination Authorization, and that we are right now dropping RPKI invalid routes in every single Point-of-Presence for AS16509.<p>Does anyone know if AWS is going to push the remaining 1% to implement ROA?<p>Also, it sounds like an unsigned route - which I think most BGP announcements are - is still accepted, right? Any idea when we can start to require routes be signed?
评论 #25769087 未加载
评论 #25768882 未加载
jgrahamcover 4 years ago
See also <a href="https:&#x2F;&#x2F;isbgpsafeyet.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;isbgpsafeyet.com&#x2F;</a> and <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;is-bgp-safe-yet-rpki-routing-security-initiative&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;is-bgp-safe-yet-rpki-routing-sec...</a>
ericpauleyover 4 years ago
See also: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;rpki&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;rpki&#x2F;</a> (2018)
godzillabrennusover 4 years ago
I’m happy to see this get addressed yet simultaneously disappointed that Pirate Bay can’t knock North Korea off the Internet anymore.
dangerboysteveover 4 years ago
listened to a good podcast about this a while back<p><a href="https:&#x2F;&#x2F;softwareengineeringdaily.com&#x2F;2020&#x2F;12&#x2F;02&#x2F;bgp-with-andree-toonk&#x2F;" rel="nofollow">https:&#x2F;&#x2F;softwareengineeringdaily.com&#x2F;2020&#x2F;12&#x2F;02&#x2F;bgp-with-and...</a>
jharohitover 4 years ago
We need to get to a fully trustless routing mechanism on global networks
评论 #25770473 未加载
jtdevover 4 years ago
Does this give AWS any ability to block&#x2F;censor or influence access to segments of the internet that they might not politically &quot;approve&quot; of?
评论 #25768245 未加载
评论 #25768680 未加载
评论 #25770623 未加载
ed25519FUUUover 4 years ago
ISPs need this big time.
rossdavidhover 4 years ago
Well, I feel so much more secure about that, now.