nanog mailing list archives

Re: Prefix hijacking, how to prevent and fix currently


From: Karsten Thomann <karsten_thomann () linfre de>
Date: Fri, 29 Aug 2014 11:43:39 +0200

Am 29.08.2014 11:39, schrieb Randy Bush:
Loose mode would drop failing routes, iff there is covering (i.e. less
specific is ok) route already in RIB.
isn't that exactly the hole punching attack?
No, as the the more specific route is signed and is preferred (longest
match routing) against the less specific hijacked route
clearly i am missing something.  got a write-up?

randy
sorry my mistake, you're right


Current thread: