Sent from my iPhone

On Aug 4, 2016, at 14:55, Randy Bush <[email protected]> wrote:

>> fine, bad terminology.  was following the original.
> 
> the document is not strong on rigor
> 
>> Is it not possible to define a ROA that includes a prefix-length
>> -or-longer up-to and including a /128 or /32?
> 
> quite possible.  but
> 
>>> rpki-based origin authentication doe not help here because the
>>> attacker requesting my prefix be blackholed with merely forge my AS
>>> on the path.

It's a leaky bucket, peers can generate prefix list filters for their route 
objects. If they send spurious junk it's associated with their down-stream cone 
not someone else's. If they're insufficiently good at filtering, their 
customers can jack each other. It's transit providers there's no point in 
filtering the Internet cone from. 

The threat of more specific  routes arriving from your transits with wacky as 
paths is real but that's prefix hijacking today and 20 years ago.

> 
> randy
> 

_______________________________________________
GROW mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/grow

Reply via email to