Hacker News new | ask | show | jobs
by 0x0 5088 days ago
I never understood why not the upstreams of "bulletproof hosts" simply disconnect / de-peer the entire AS until they clean up their act? Why won't their BGP neighbors take action?

If you can't get ScumBagISP-A to clean up their act, go to ScumBagISP-Upstream-B, and then the next hop ScumBagISP-Upstream-Nexthop-C, and the next, until you find a responsible carrier who can de-peer?

2 comments

ISPs have very complicated sharing agreements in place when it comes to BGP. At BGP level, contracts take precedence over technology.
That was tried about 5 years ago against the "Russian Business Network", AS40898.

http://blog.washingtonpost.com/securityfix/2007/11/russian_b...

As far as I know it only worked temporarily.