INSUBCONTINENT EXCLUSIVE:
Cloudflare has introduced a new tool to help improve BGP security which can hold ISPs accountable for their BGP safety measures.In a recent
to route internet traffic between internet networks worldwide
Since that time though, the system has seen the introduction of a number of new security measures including TLS, DNSSEC and projects like
the Resource Public Key Infrastructure (RPKI) to make it less vulnerable to leaks and hijacking.Unfortunately though, BGP hijacking still
occurs at the ISP level with Russia's state-owned telecoms provider Rostelecom and China Telecom being two of the biggest offenders
For example, traffic intended for more than 200 of the world's largest content delivery networks (CDNs) and cloud hosting providers was
recently redirected through Rostelecom.In an effort to hold ISPs accountable, Cloudflare has launched a new website called isBGPSafeYet
which allows users to check whether or not their ISP is using RPKI which helps filter out invalid traffic routes.The site runs a test where
it tries to fetch two pages (valid.rpki.cloudflare.com and invalid.rpki.cloudflare.com) to see an ISP has enabled RPKI
If the test fails, Cloudflare's site allows users to tweet out the fact that their ISP isn't using RPKI in the hope that public pressure
may lead to increased adoption of the public key infrastructure framework.While RPKI isn't perfect at preventing BGP hijacking, almost half
scripts used in its new website available on GitHub for others to use.Via ZDNet