Sent from my iPhone
On Aug 4, 2016, at 14:55, Randy Bush <[email protected]> wrote: >> fine, bad terminology. was following the original. > > the document is not strong on rigor > >> Is it not possible to define a ROA that includes a prefix-length >> -or-longer up-to and including a /128 or /32? > > quite possible. but > >>> rpki-based origin authentication doe not help here because the >>> attacker requesting my prefix be blackholed with merely forge my AS >>> on the path. It's a leaky bucket, peers can generate prefix list filters for their route objects. If they send spurious junk it's associated with their down-stream cone not someone else's. If they're insufficiently good at filtering, their customers can jack each other. It's transit providers there's no point in filtering the Internet cone from. The threat of more specific routes arriving from your transits with wacky as paths is real but that's prefix hijacking today and 20 years ago. > > randy > _______________________________________________ GROW mailing list [email protected] https://www.ietf.org/mailman/listinfo/grow
