Hacker News new | past | comments | ask | show | jobs | submit login

I don't understand how RPKI prevents route hijacking. It just signs that a certain AS owns a certain prefix, right? How does that stop another network from pretending to be peered with my network, then announcing an indirect route, copying the signature from my valid announcement of the same prefix?



RPKI stops jack shit thats why ASPA was invented it just needs to be implemented


It's DNS all over again, basically.

> it just needs to be implemented

Do you know BGPKit [1]? I'm not sure what the state of the project is, but I remember vaguely them implementing ASPA and being involved in the RFC back then.

[1] https://github.com/bgpkit


I love how it will only ever be one leaky abstraction after another (incompleteness theorem) with a Lindy value of a few years to realize that and have to hallucinate something new, but you all keep trying to secure what physics won’t allow us to.

You all should go touch grass and learn to roll with our human frailty and imperfection rather than drive yourselves mad bouncing off the walls of your language and mathematical primitives.

Just remember you’re one of billions and no one needs you specifically. Just enough people overall so that life isn’t so shit one would be better off dead themselves




Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: