Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Huge Internet Security Hole Demonstrated » Hole can be closed; but it is costly and disruptive
Uniqs:
38
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« The DNS exploit is bigger...  

TKJunkMail
Enjoy the sun
Premium
join:2002-03-03
Avalon, NJ
·Sprint Mobile Broa..
·Comcast

Hole can be closed; but it is costly and disruptive

Given the cost and effort required to close this hole, it may be some time before it is closed.

Kent and BBN colleagues developed Secure BGP (SBGP), which would require BGP routers to digitally sign with a private key any prefix advertisement they propagated. An ISP would give peer routers certificates authorizing them to route its traffic; each peer on a route would sign a route advertisement and forward it to the next authorized hop.

"That means that nobody could put themselves into the chain, into the path, unless they had been authorized to do so by the preceding AS router in the path," Kent said.

The drawback to this solution is that current routers lack the memory and processing power to generate and validate signatures. And router vendors have resisted upgrading them because their clients, ISPs, haven't demanded it, due to the cost and man hours involved in swapping out routers.

--
My BLOG .. .. Internet News .. .. My Web Page
Ask yourself one question: 'Do I feel lucky?' Well, do ya punk?

asdfdfdfdfdfdf

@Level3.net

Re: Hole can be closed; but it is costly and disruptive

I think you are right. What annoys me though, is when I read things like:
quote:
who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. "I went around screaming my head about this about ten or twelve years ago.... We described this to intelligence agencies and to the National Security Council, in detail."

quote:
Stephen Kent, chief scientist for information security at BBN Technologies, who has been working on solutions to fix the issue, said he demonstrated a similar BGP interception privately for the Departments of Defense and Homeland Security a few years ago.

Our government insists that they need backdoors and broad powers to monitor anyone's communications without fussy things like warrants and they talk of dire scenarios like terrorists bringing down our communications infrastructure and plunging us into chaos and and yet this same government can't be bothered to light fires under some asses to make sure resources are devoted to getting this sort of thing fixed.
Should make us wonder whether they believe their own breathless rhetoric.

cork1958
Cork

join:2000-02-26
Fruitport, MI
·Verizon Online DSL
·Charter Pipeline

Re: Hole can be closed; but it is costly and disruptive

said by asdfdfdfdfdfdf :

I think you are right. What annoys me though, is when I read things like:
quote:
who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. "I went around screaming my head about this about ten or twelve years ago.... We described this to intelligence agencies and to the National Security Council, in detail."

quote:
Stephen Kent, chief scientist for information security at BBN Technologies, who has been working on solutions to fix the issue, said he demonstrated a similar BGP interception privately for the Departments of Defense and Homeland Security a few years ago.

Our government insists that they need backdoors and broad powers to monitor anyone's communications without fussy things like warrants and they talk of dire scenarios like terrorists bringing down our communications infrastructure and plunging us into chaos and and yet this same government can't be bothered to light fires under some asses to make sure resources are devoted to getting this sort of thing fixed.
Should make us wonder whether they believe their own breathless rhetoric.
Does ANYBODY believe their breathless rhetoric?
--
The Firefox alternative.
»www.mozilla.org/projects/seamonkey/
Forums » Huge Internet Security Hole Demonstrated« The DNS exploit is bigger...  


Tuesday, 08-Dec 22:59:26 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [193] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [50] The Future Of Wi-Fi Is Bright
· [48] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [19] AT&T Releases Network Reporting iPhone App
Most people now reading
· Comcast refused to install 400' feet. [Comcast HSI]
· Man Downloads Child Porn "Accidentally," Faces 20 Years [Security]
· ICC Strats??? [World of Warcraft]
· Throttling of NNTP traffic ?? [Cogeco]
· Servers UP!!! [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [ Classes] ATTN Death Knights - Post your spec for critique! [World of Warcraft]
· Top 10 things to do while servers are down! [World of Warcraft]
· Microsoft Security Bulletin(s) for December 8, 2009 [Security]