nanog mailing list archives

Re: "Is BGP safe yet?" test


From: Rubens Kuhl <rubensk () gmail com>
Date: Mon, 20 Apr 2020 16:01:54 -0300

On Mon, Apr 20, 2020 at 3:37 PM Denys Fedoryshchenko <
nuclearcat () nuclearcat com> wrote:

There is simple use case that will prove this page is giving false
positive
for their "name&shame" strategy.
Any AS owner with default route only (yes it happens a lot) users will
get:
"YOUR ISP TERRIBLE, HIS BGP NOT SAFE!".
But he have nothing to validate! His BGP is implemented safely,
its just his upstream is not validating routes.


So, that same ISP who is not validating because it has a default route
could push its providers to do validation and then be as safe as other
validating themselves ?


Rubens

Current thread: