TCP/BGP vulnerability - easier than you think

Joe Abley jabley at isc.org
Wed Apr 21 04:19:44 UTC 2004



On 20 Apr 2004, at 23:40, Patrick W.Gilmore wrote:

> And how do you track a thousand passwords?  Okay, maybe that is not 
> too hard.

Right :-)

> But how do you guarantee a thousand peers will never screw up and 
> forget, lose, fat-finger, etc. a single one of them?  This one I would 
> really like to know, 'cause I sure as hell can't figure it out.

If someone forgets a password, you talk on the phone and agree a new 
one, and apply it to both sides. It's the same kind of procedure that I 
guess we would follow if peers spontaneously forgot our IP addresses or 
AS numbers. Or you could just tell them what their password is, since 
you have all the details in your peering database (see above).

(If the reaction to this is "hey, not everybody has a peering database 
you know" then people should let me know; we can tidy up and publish 
the postgres schema that we use if there is interest).


Joe




More information about the NANOG mailing list