|
|
|
|
|
by diath
2246 days ago
|
|
> To me this whole article just reads like a network operator complaining that someone else is trying to hold them accountable. Not really though, they do agree in the post that something needs to be done, they just don't agree that RPKI is quite the right answer and that Cloudflare's fearmongering scaretactic is the right move to push for RPKI. |
|
They also grab Coronovirus as a rationale for doing nothing right now:
"Since this has now happened a few times, we felt it worth giving some more information that may be useful to customers and others who've seen these tweets (either directed at us, or at other ISPs), explaining a bit about what BGP is and how RPKI can extend it, and also our feelings about Cloudflare attempting to build support in this manner, especially now, during the Corona Virus situation."
If you look at this NANOG thread [2] nobody is complaining about ATT announcing they have implemented RPKI. So is there a negative downside? No. Has CloudFlare pushed some carriers into an awkward position given they are showcasing the true state of carriers as it pertains to route security in BGP? Yes. Andrews & Arnold are trying to tell their customers that their safety is paramount. Yet, they don't have a timeline to address the problem that other carriers have spent considerable time implementing over the last couple years. So, while Andrews & Arnold may be a great ISP - are they above public disclosure of an area they need to improve? No.
I applaud CloudFlare for showing end users which carriers are not spending time and resources on doing their due diligence to protect their customers. Especially business customers who rely on their parent AS to operate their business safely. Andrews & Arnold's response is suspect at best given their subjective response to the "why" behind why they've chosen to do nothing.
Finally - beyond CloudFlare NIST has been publishing these statistics for much longer. Just because CloudFlare has shown light on the topic - does not mean they are the bad actor. There are plenty of other outlets that have been highly supportive of these deployments - NIST [3] and RIPE [4], among very vocal proponents.
So, after parsing the reality of the values of RPKI for a small amount of time - the question around why Andrews & Arnold have chosen to do nothing feels different and, in my opinion, even more appropriate. Beyond that their response feels very hollow and weak on the technicalities which have put them in a spotlight they'd rather not deal with right now.
[0] https://blog.cloudflare.com/rpki/ [1] https://blog.thousandeyes.com/visualizing-the-benefits-of-rp... [2] https://mailman.nanog.org/pipermail/nanog/2019-February/thre... [3] https://rpki-monitor.antd.nist.gov/#rpki_adopters [4] https://labs.ripe.net/Members/antony_stergiopoulos/results-o...