nanog mailing list archives
Re: rpki vs. secure dns?
From: Nick Hilliard <nick () foobar org>
Date: Sat, 28 Apr 2012 18:22:15 +0100
On 28/04/2012 14:04, Alex Band wrote:
they do not trust, or have a specific local policy for. In the toolsets for using the RPKI data set for routing decisions, such as the RIPE NCC RPKI Validator, every possible step is taken is taken to ensure that the operator is in the driver's seat.
Leaving aside technical matters, this is one of the more contentious political issues with RPKI. RPKI is a tool which can be used to locally influence routing decisions, but allows centralised control of prefix authenticity. If this central point is influenced to invalidate a specific prefix, then that will cause serious reachability problems for that prefix on the Internet. It will be difficult for politicians / legislators / LEAs to look at a technology like this and not see its potential for implementing wide-area Internet blocking. For sure, the LEAs currently looking at it are extremely interested. Nick
Current thread:
- Re: rpki vs. secure dns?, (continued)
- Re: rpki vs. secure dns? Randy Bush (Apr 30)
- Re: rpki vs. secure dns? Matt Ryanczak (Apr 27)
- Re: rpki vs. secure dns? Randy Bush (Apr 28)
- Re: rpki vs. secure dns? Matthias Waehlisch (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Randy Bush (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Florian Weimer (Apr 28)
- Re: rpki vs. secure dns? Nick Hilliard (Apr 28)
- Re: rpki vs. secure dns? Phil Regnauld (Apr 28)
- Re: rpki vs. secure dns? Nick Hilliard (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 28)
- Re: rpki vs. secure dns? Rubens Kuhl (Apr 28)
- Re: rpki vs. secure dns? Phil Regnauld (Apr 28)
- Re: rpki vs. secure dns? Alex Band (Apr 29)
- Re: rpki vs. secure dns? Jennifer Rexford (Apr 29)
- Message not available
- Re: rpki vs. secure dns? Stephane Bortzmeyer (Apr 29)
- Re: rpki vs. secure dns? Matthias Waehlisch (Apr 29)
- Re: rpki vs. secure dns? David Conrad (Apr 29)