Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It has authentication for only one hop, if routes propagated all the way up the chain with signatures, it would be much easier to block/limit bad AS behavior.


Your peering relationship is only for one hop. What it lacks is prefix/path validation, not authentication.


But authentication of every advertised range all the way up the chain would allow upstream providers to easily differentiate valid large prefix announcements that were done intentionally (e.g. big ISP announcing some routes) from crazy nonsense done by an unknown party that isn't a big ISP. We definitely need prefix filtering, but there needs to be some easily verifiable source of identity tied to each announcement to be able to automate the process of accepting and rejecting large prefix announcements.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: