Re: [sidr] SIDR ReCharter - to capture/cover path validation work

2011-02-22 Thread Sandra Murphy
Randy, please do not indulge in ad-hominem attacks. It does nothing to help in finding the right answer. --Sandy On Tue, 22 Feb 2011, Randy Bush wrote: |So the only security problem anyone faces, currently, is people cheating |on the AS Path length? I thougth my previous post (as well as ot

Re: [sidr] SIDR ReCharter - to capture/cover path validation work

2011-02-22 Thread Andrew Lange
To divert the discussion a bit back into the realm of requirements. What is the current "diameter" of the Internet? From my recollections it was converging toward about 4 ASes in diameter. This would mean that for most paths we have: AS_A <--> AS_B <--> AS_C <--> AS_D If we have already auth

Re: [sidr] SIDR ReCharter - to capture/cover path validation work

2011-02-22 Thread Randy Bush
> What is the current "diameter" of the Internet? From my recollections > it was converging toward about 4 ASes in diameter. that was the mean, not the diameter. not counting prepends and other kink, the effective diameter is considerably larger. randy __

Re: [sidr] SIDR ReCharter - to capture/cover path validation work

2011-02-22 Thread Randy Bush
> If we have already authenticated the route origin, with either offline > or online enforcement depending on your preference, we have > cryptographically bound a route object to an aut num. btw, the sidr work to date has not formally bound the route origin. it is informal, and easily spoofed. t