netsec-sig - RE: [Security-WG] BCP for Origin validation (RFC7115)
Subject: Internet2 Network Security SIG
List archive
- From: "Spurling, Shannon" <>
- To: "" <>
- Subject: RE: [Security-WG] BCP for Origin validation (RFC7115)
- Date: Fri, 19 Apr 2019 18:14:30 +0000
I take it as the opposite. That the origin announcement can be faked, like in the hijacking attack. Even with a valid source ROA, If you can make your AS path shorter for some of the Internet, it doesn’t matter what the owners ASN is. You can fool some of the internet all of the time. I guess that’s where the IRR data and filters help out. Personally, it seems a lot more palatable than cryptographically signing everything and trying to produce some “Chain of Trust” to try to authenticate every little piece. That’s a lot of things to break. How often and what is my mechanism to roll my keys? Who keeps the keys and how secure are they?
Shannon Spurling
From: <>
On Behalf Of David Farmer
I completely agree about the Path issues, but that is the next paragraph from the one I quoted. To me, the paragraph I quoted isn't about Path issues at all, it about the fact that it is possible for a prefix owner to lie about the origin of a prefix. I'm not sure what's to be gained by doing so maliciously, but it is certainly a vector from mistakes.
Thanks
On Fri, Apr 19, 2019 at 11:31 AM "Montgomery, Douglas (Fed)" <> wrote:
-- =============================================== |
- [Security-WG] BCP for Origin validation (RFC7115), David Farmer, 04/19/2019
- RE: [Security-WG] BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), Michael H Lambert, 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), Brad Fleming, 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), Montgomery, Douglas (Fed), 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), David Farmer, 04/19/2019
- RE: [Security-WG] BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), ssw, 04/19/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), Steven Wallace, 04/23/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), David Farmer, 04/23/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), Montgomery, Douglas (Fed), 04/23/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- Re: [Security-WG] [External] RE: BCP for Origin validation (RFC7115), ssw, 04/19/2019
- RE: [Security-WG] BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), David Farmer, 04/19/2019
- Re: [Security-WG] BCP for Origin validation (RFC7115), Montgomery, Douglas (Fed), 04/19/2019
- RE: [Security-WG] BCP for Origin validation (RFC7115), Spurling, Shannon, 04/19/2019
- <Possible follow-up(s)>
- Re: [Security-WG] BCP for Origin validation (RFC7115), John Kristoff, 04/20/2019
Archive powered by MHonArc 2.6.19.