Re: [sidr] BGPSec scaling (was RE: beacons and bgpsec)

Robert Raszuk <robert@raszuk.net> Wed, 07 September 2011 20:42 UTC

Return-Path: <robert@raszuk.net>
X-Original-To: sidr@ietfa.amsl.com
Delivered-To: sidr@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B40C21F8B6E for <sidr@ietfa.amsl.com>; Wed, 7 Sep 2011 13:42:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IWFQg6eaWd0K for <sidr@ietfa.amsl.com>; Wed, 7 Sep 2011 13:42:20 -0700 (PDT)
Received: from mail37.opentransfer.com (mail37.opentransfer.com [76.162.254.37]) by ietfa.amsl.com (Postfix) with SMTP id 4715621F8B5F for <sidr@ietf.org>; Wed, 7 Sep 2011 13:42:20 -0700 (PDT)
Received: (qmail 15816 invoked by uid 399); 7 Sep 2011 20:44:07 -0000
Received: from unknown (HELO ?216.69.69.180?) (216.69.69.180) by mail37.opentransfer.com with SMTP; 7 Sep 2011 20:44:07 -0000
Message-ID: <4E67D797.70105@raszuk.net>
Date: Wed, 07 Sep 2011 22:44:07 +0200
From: Robert Raszuk <robert@raszuk.net>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:6.0.1) Gecko/20110830 Thunderbird/6.0.1
MIME-Version: 1.0
To: sidr@ietf.org
References: <A37CADA4-F16D-4C01-8D9C-D01001C4EFE4@tcb.net> <21C19DA8-7BF3-4832-8C13-C9A45FE026FB@algebras.org> <87D9E106-2A37-4E1E-8C69-7084C199A3FE@tcb.net> <331AEFBD-6AE5-469E-A11E-E672DC61DCDC@pobox.com> <B92913D1-AB82-4D9F-B8A9-F8F4F99713D6@tcb.net> <p06240803ca685bff5443@[128.89.89.43]> <D6D12861-412E-4A65-B626-B627449981B8@tcb.net> <34E4F50CAFA10349A41E0756550084FB0C2ED5A4@PRVPEXVS04.corp.twcable.com> <7B321CF0-ABE6-4FCD-B755-8099BB63399A@rob.sh> <5E9BE75F-C0A6-4B48-B15F-7E0B80EFE981@ericsson.com> <B01905DA0C7CDC478F42870679DF0F1010B0E6F99A@qtdenexmbm24.AD.QINTRA.COM>
In-Reply-To: <B01905DA0C7CDC478F42870679DF0F1010B0E6F99A@qtdenexmbm24.AD.QINTRA.COM>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Subject: Re: [sidr] BGPSec scaling (was RE: beacons and bgpsec)
X-BeenThere: sidr@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: robert@raszuk.net
List-Id: Secure Interdomain Routing <sidr.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/sidr>, <mailto:sidr-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/sidr>
List-Post: <mailto:sidr@ietf.org>
List-Help: <mailto:sidr-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/sidr>, <mailto:sidr-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 07 Sep 2011 20:42:21 -0000

Hi,

Securing BGP really means transitioning from 100% distributed control of 
today's BGPv4 based Internet to new layer of Internet control to be 
build for BGPSec (for that matter for BGP Origin Validation too).

IMHO scaling aspects are serious, but are not the most serious reg 
discussion of acceptance of not for this new layer of control. And that 
is not something one can address by dedicated crypto engine processing 
or better PR CPU.

It would be IMHO very interesting to see more discussions in the 
community on the fundamental aspects of risks such new layer of control 
may bring or cause to the Internet as we know it today.

Rgs,
R.