nanog mailing list archives

Re: RPKI unknown for superprefixes of existing ROA ?


From: William Herrin <bill () herrin us>
Date: Sun, 22 Oct 2023 09:27:34 -0700

On Sun, Oct 22, 2023 at 9:10 AM William Herrin <bill () herrin us> wrote:
In essence, this means that a ROA to AS0 doesn't work as intended.

Let me ground it a bit:

He's saying that someone could come along and advertise 0.0.0.0/1 and
128.0.0.0/1 and by doing so they'd hijack every unrouted address block
regardless of the block's ROA.

RPKI is unable to address this attack vector.

Regards,
Bill Herrin


-- 
William Herrin
bill () herrin us
https://bill.herrin.us/


Current thread: