VirMach/LET/ColoCrossing Down?

When did this happen? I read reports at least once a month about stolen IP space by some fuckhead routing a smaller table and it being accepted upstream by incompetent/bribed providers.

Okay, there are two mechanisms: IRR and RPKI.

IRR is essentially a type of a “database system” provided by some companies, which basically say:
1.2.3.0/24 can be announced by AS1234
One of the most used IRR databases is RADB. The problem is that basically anyone who pays can insert entries. That doesn’t mean the system is useless - it mostly works for basic customer<>ISP prefix validation (assuming the ISP is legitimate).

RPKI is not dissimilar, but the whole database thing is provided by RIR’s. Which means they validate whether you own the IP space or not. Some large providers (including Tier 1’s like NTT) started filtering prefixes with invalid RPKI in their core network, which means they don’t check only prefixes of their customers, but EVERYTHING in their routing table.

This should prevent larger scale hijacks.

The problem is that not everyone has RPKI, or even IRR deployed. Lots of IP space is “unprotected”

12 Likes

Thank you so much for the detailed description!

I didn’t realise you have a blog. Adding it to my RSS reader!

4 Likes

CloudFlare released a blog post as well. I would say it’s more detailed and goes more into depth of the tech involved. But hey, I was first and it was supposed to be an ELI5 :smile:

Thank you very much! While I don’t post too often I certainly appreciate that.

3 Likes