Re: [GROW] WGLC: draft-ietf-grow-route-leak-problem-definition (ends: 8/24/2015 - Aug 24)

Christopher Morrow <christopher.morrow@gmail.com> Sun, 01 November 2015 23:39 UTC

Return-Path: <christopher.morrow@gmail.com>
X-Original-To: grow@ietfa.amsl.com
Delivered-To: grow@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 16EA21B3AB5; Sun, 1 Nov 2015 15:39:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2jlHXztadFVB; Sun, 1 Nov 2015 15:39:10 -0800 (PST)
Received: from mail-yk0-x232.google.com (mail-yk0-x232.google.com [IPv6:2607:f8b0:4002:c07::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D95B91B3AB1; Sun, 1 Nov 2015 15:39:09 -0800 (PST)
Received: by ykdr3 with SMTP id r3so124185596ykd.1; Sun, 01 Nov 2015 15:39:09 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=V7b+CpdJuhJdDfqTwky+zxT7nvFA3s5G2SxQTrv7OLg=; b=HE5T7l/8QQOzMbM0a37TkwB9QwKXkn1dvltx8n76HnXvUW0CA+9hUgUA1SDM3VCTp6 QGbaVvu6QrSqaweHPi8GbelrElY1/AsAX7uGonkSvnGXX74Ny46nOs//shYHdwptCdWq Wq3OAvllqnR7fnu5rpJJrj9ihKs/SLVWLy0GsX5lqHQjGGdd7LIeSbq5W1gqg0FQ7YQX 5PviR2BKzdJ2kuCvyyKbgeVX44T+XT5y/2H/P7+Me9M37qbHT6FIcIN0ZxRu7XM8Kg/x hpufdJenPPSy8IMNGaMM6cPRUNVTbMMjpd+47N9VuPX3UvgUH7jnv14PPesLKm4cy75M 9WHg==
MIME-Version: 1.0
X-Received: by 10.129.159.9 with SMTP id w9mr14241007ywg.56.1446421149199; Sun, 01 Nov 2015 15:39:09 -0800 (PST)
Received: by 10.13.202.16 with HTTP; Sun, 1 Nov 2015 15:39:09 -0800 (PST)
In-Reply-To: <20151030141520.GF1334@22.rev.meerval.net>
References: <CAL9jLaaOPvY2WZtunCOkuuCDV5-Do+cpHBfa8eEhquGdzSLVuA@mail.gmail.com> <20151030141520.GF1334@22.rev.meerval.net>
Date: Mon, 02 Nov 2015 10:39:09 +1100
Message-ID: <CAL9jLaa_GNXRi38-6x4PTs4Dy2T2AAwzmu1ok6QOWERzBshZuQ@mail.gmail.com>
From: Christopher Morrow <christopher.morrow@gmail.com>
To: Job Snijders <job@instituut.net>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/grow/mAci9Srdcq9krj15HbBhsrxJPaA>
Cc: "grow-chairs@ietf.org" <grow-chairs@ietf.org>, "grow@ietf.org grow@ietf.org" <grow@ietf.org>, "grow-ads@tools.ietf.org" <grow-ads@tools.ietf.org>
Subject: Re: [GROW] WGLC: draft-ietf-grow-route-leak-problem-definition (ends: 8/24/2015 - Aug 24)
X-BeenThere: grow@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Grow Working Group Mailing List <grow.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/grow>, <mailto:grow-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/grow/>
List-Post: <mailto:grow@ietf.org>
List-Help: <mailto:grow-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/grow>, <mailto:grow-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 01 Nov 2015 23:39:11 -0000

oh well, since this conversation got re-ingnited..

On Sat, Oct 31, 2015 at 1:15 AM, Job Snijders <job@instituut.net> wrote:
> I think "type 5: U-Shaped Turn with More Specific Prefix" should be
> removed from the document.
>
> Given the description:
>
>     "A multi-homed AS learns a route from one upstream ISP and announces
>     a subprefix (subsumed in the prefix) to another upstream ISP."
>
> I'd classify this type of announcement a "hijack" or "attack", not a
> route leak.

this makes sense to me, this is the equivalent of several well known
instances of someone's 'internap' box leaking outside their span of
control. So, I agree this is a hijack, not a leak... though clearly
the subnets were 'leaked' outside the span of control, the effect is
really a hijack of the remote prefix.