Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Presumably, a broken BGP advertisement. These days, they create breathless "news" stories like this one. Back in the '90s, when small-town ISPs managed to accidentally advertise short paths to huge chunks of the Internet, they broke the whole Internet. It's hard to get too wound up about it.

If you're worried that China is going to MITM your SSL sessions, remove their certificate from your cert store.

If I was a Chinese supercyberspy, I probably wouldn't do something as blatant as routing the entire Internet to China just to get traffic I wanted. I think I'd do something much more akin to spearphishing an overseas Google employee to get onto their internal network.



"Also, the list of hijacked data just happened to include preselected destinations around the world that encompassed military, intelligence and many civilian networks in the United States and other allies such as Japan and Australia"

If this claim is valid, it would seem likely that the bad BGP advertisement was not accidental.


If it wasn't accidental, then I doubt it was a serious operation. Most likely a fishing expedition. Testing the waters to see what the reaction is and what data (or kinds of data) they are able to harvest.


China just validated that they can intercept trafic for malicious intent, with no international retaliation to speak of. How is that not serious?


"This happens accidentally a few times per year, Alperovitch said."

They aren't the only ones.


Because so can practically any random company.


By 'serious operation,' I mean something they were after a specific goal, vs just probing for weaknesses.


Internet routing is supposed to be a distributed system alright, but most of the internet services (except China's) are not hosted in China. Wouldn't it be easy to add a policy to BGP that effectively blacklists (or gives a low priority) to routers in Chinese AS's?

I guess what would be difficult is to reach a consensus on adding the above route.. oh well.

Also relevant: http://asert.arbornetworks.com/2008/02/internet-routing-inse...


ever heard about Net Neutrality?


This has nothing to do with net neutrality - we're talking about routing policy, not traffic policy.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: