Page 1 of 1

BGP hijacking on Sonic

Posted: Sun Apr 19, 2020 7:20 am
by Tribune
This tool from Cloudfare says Sonic traffic is vulnerable to BGP hijacking.

Border Gateway Protocol (BGP) RPKI Implementation?

Posted: Sun Apr 19, 2020 10:37 am
by pandata
TLDR:
BGP disruptions happen frequently, generally by accident. But BGP can also be hijacked for large-scale spying, data interception, or as a sort of denial of service attack. Just last week, United States Executive Branch agencies moved to block China Telecom from offering services in the US, because of allegedly malicious activity that includes BGP attacks.

On Friday, the company launched Is BGP Safe Yet​, a site that makes it easier for anyone to check whether their internet service provider has added the security protections and filters that can make BGP more stable.
-source: ARS

Is there a timeline when Sonic will implement RPKI?
bgp.png
BGP
bgp.png (30.41 KiB) Viewed 6293 times

Sonic.net does not implement Border Gateway Protocol (BGP) safely!

Posted: Mon Apr 20, 2020 9:31 am
by tcsf108
https://isbgpsafeyet.com/

Your ISP (Sonic Telecom (Sonic.net, Inc.), AS46375) does not implement BGP safely.

It should be using RPKI to protect the Internet from BGP hijacks.

Details

fetch https://valid.rpki.cloudflare.com
correctly accepted valid prefixes

fetch https://invalid.rpki.cloudflare.com
incorrectly accepted invalid prefixes

Re: Sonic.net does not implement Border Gateway Protocol (BGP) safely!

Posted: Mon Apr 20, 2020 10:36 am
by anthony.n
We are aware of this issue and we are working on implementing RPKI as soon as we can! We will let you know when an update goes live or when we have a better ETA from our engineers.

Re: Sonic.net does not implement Border Gateway Protocol (BGP) safely!

Posted: Sat May 02, 2020 9:43 am
by alexis.frasz
Please do update us on the ETA. We love Sonic, but this is a serious concern that, sadly, will make us reconsider our options if unaddressed.

Re: Sonic.net does not implement Border Gateway Protocol (BGP) safely!

Posted: Mon Nov 27, 2023 10:38 am
by skyweir
Hi Guys,

We're 3 years out now and this still has not been adopted. What happened?