Kitz Forum

Announcements => News Articles => Topic started by: jelv on April 21, 2020, 09:58:24 AM

Title: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: jelv on April 21, 2020, 09:58:24 AM
https://www.ispreview.co.uk/index.php/2020/04/cloudflare-ignite-consumer-isp-confusion-with-bgp-safety-test.html

Quote
Over the past few days we’ve had a small but growing stream of Tweets and Emails from people who have run Cloudflare’s new ‘Is BGP Safe Yet (https://isbgpsafeyet.com/)‘ tool and are worried that their UK broadband ISP is “unsafe” because it uses the Border Gateway Protocol (BGP) and not RPKI. Aside from poor timing with COVID-19, the result can be misleading.
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: jelv on April 21, 2020, 10:00:41 AM
AAISP

(https://forum.kitz.co.uk/index.php?action=dlattach;topic=24654.0;attach=28531;image)
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: j0hn on April 21, 2020, 10:18:40 AM
AAISP cheat the test.

From the comments section

Quote
Yeah, AAISP have hacked the Cloudflare test by manually dropping the invalid prefix Cloudflare announce on their routers.
AAISP’s MD has stated on Twitter that they are looking to develop in RPKI in their core routers, but as yet, they don’t support this.

It’s all an interesting debate!
However, until such time that the entire world – both ISPs on on-side, and the content providers on the other all support RPKI, set ROAs/route objects in a RIR, then there will still be glaring gaps in RPKI being effective at stopping prefix hijacking, (and until the next weakness is found)!
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: Chrysalis on April 22, 2020, 04:06:38 AM
interesting john i only read yesterday on revk blog about how they are been secure on bgp, when im back on pc ill link it, not sure if it was this specific feature though.
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: jelv on April 22, 2020, 10:13:44 AM
https://www.revk.uk/2020/04/bgp.html
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: Chrysalis on April 22, 2020, 12:03:03 PM
Yep that's the post, thanks, having another read of it though, he didn't say its been deployed, just that its in the works.
Title: Re: Cloudflare Ignite Consumer ISP Confusion with BGP Safety Test
Post by: j0hn on April 22, 2020, 02:17:41 PM
https://www.revk.uk/2020/04/bgp.html

Confirms what I said above, not yet deployed.
They simply cheat the test by dropping the invalid prefix.
Virgin do the same.