[194884] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IPv4 Hijacking For Idiots

daemon@ATHENA.MIT.EDU (Scott Christopher)
Tue Jun 6 19:28:39 2017

X-Original-To: nanog@nanog.org
From: Scott Christopher <s@xopher.net>
To: nanog@nanog.org
Date: Tue, 06 Jun 2017 16:14:59 +0300
In-Reply-To: <115957cb-34f8-e2ee-b53b-12b3d5842521@efes.iucc.ac.il>
Errors-To: nanog-bounces@nanog.org

Hank Nussbacher wrote:=20

> 2.  Create a domain called acme-corp.com and a user called peering

Or one could register a=D1=81me.com

(If the reader can't tell the difference between acme.com and a=D1=81me.com=
 ,
the reader is using one of the multitude of email clients and/or fonts
that presents Unicode poorly.)

> 3.  Contact an IX, preferably not one in a Westernized, clueful area:
> https://en.wikipedia.org/wiki/List_of_Internet_exchange_points

I don't think the ordinary Westernized IX is immune to this. Any system
requiring human scrutiny is only as secure as the laziest human employed
by it. Don't underestimate the "too busy to check this crap"
attitude and its potential for serious problems.

--=20
Regards,
  S.C.

home help back first fref pref prev next nref lref last post