nanog mailing list archives

Re: Prefix hijacking, how to prevent and fix currently


From: Randy Bush <randy () psg com>
Date: Fri, 29 Aug 2014 18:39:32 +0900

Loose mode would drop failing routes, iff there is covering (i.e. less
specific is ok) route already in RIB.
isn't that exactly the hole punching attack?
No, as the the more specific route is signed and is preferred (longest
match routing) against the less specific hijacked route

clearly i am missing something.  got a write-up?

randy


Current thread: