Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Cogent knows that Rascom shouldn't be announcing those prefixes, and refusing to route traffic to them unless there's manual verification

I run a large production BGP network. With two exceptions every provider needed a Letter of Authorization from me to send to their upstream that authorized the announcement of my IP space (the exceptions being India where they wanted to charge extra for filtering announcements, and Russia where they offered to not do filtering for an extra charge).

This "manual verification" already takes place. It just doesn't apply to large transit providers interconnecting like what happened here



The challenge is with scale. If I'm a network who has many networks downstream of me I might have 50 to 100 prefix changes in a month. None of my upstream providers are going to like manually vetting all of those - and none of my customers don't want to wait days before their announcements propagate. So there is this sort of state you can land yourself as a "you're a big customer, we seem to trust you".

The reality is that RPKI Origin Validation solves this (but not as path spoofing, we need ASPA for that) and people need to publish valid ROAs.


Back in the 90's, nobody did LOAs. I remember reading prefixes over the phone to a guy at InternetMCI when I was moving an ISP from a 56K line to a T1. Fun times!




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: