nanog mailing list archives

Re: Routing Insecurity (Re: BGP in the Washington Post)


From: Valdis.Kletnieks () vt edu
Date: Tue, 09 Jun 2015 21:19:23 -0400

On Tue, 09 Jun 2015 19:09:45 -0400, David Mandelberg said:
I don't think there's an update issue here. The crypto verification is
probably going to be deferred in addition to being low priority. If I
understand it correctly, this means that a route can be passed along
right away without waiting for the crypto checks.

Forward the route and then check it?

Didn't we have a very amusing afternoon a number of years ago when $VENDOR
did exactly that with some invalid routing data? Or am I mis-remembering
history, and therefor doomed to mis-repeat it?

Attachment: _bin
Description:


Current thread: