AS3266: BitCanal hijack factory, courtesy of many connectivity providers
job at instituut.net
Tue Jun 26 21:52:57 UTC 2018
On Tue, Jun 26, 2018 at 09:57:14PM +0200, Radu-Adrian Feurdean wrote:
> On Tue, Jun 26, 2018, at 20:23, Job Snijders wrote:
> > I'm very happy FranceIX apply filters - however Bitcanal is known to
> > submit fabricated/falsified IRR information to databases like RADB
> > and RIPE. I've reported this multiple times over the years to IRR
> > database operators.
> > In conclusion in the case of Bitcanal, most of your filtering is
> > useless (and so is mine). Participants like Bitcanal dillute the
> > value of your route servers and the IXP as a whole.
> I can confirm that this mornig (~09h30 CEST, when I read the first
> message in the thread) there were no BitCanal announces received from
> FranceIX Paris RS.
What about now? Still squeaky clean? What about now? What about
tomorrow? You only need to announce hijacked routes for the duration of
the spamming campaign (usually just a few hours). The presence of this
type of actor poses a risk to all connnected to the IX fabric.
More information about the NANOG