nanog mailing list archives

Re: "Is BGP safe yet?" test


From: Baldur Norddahl <baldur.norddahl () gmail com>
Date: Tue, 21 Apr 2020 11:09:31 +0200



On 21.04.2020 10.56, Sander Steffann wrote:
Hi,

Removing a resource from the certificate to achieve the goal you describe will make the route announcement NotFound, 
which means it will be accepted. Evil RIR would have to replace an existing ROA with one that explicitly makes a route 
invalid, i.e. issue an AS0 ROA for specific member prefix. This seems like a pretty convoluted way to try and take a 
network offline.
I've seen worse…
Sander


As long Good RIR continues to publish a valid ROA for the real ASN that evil AS0 ROA would have no effect?

Regards,

Baldur


Current thread: