Elias Rohrer [ARCHIVE] on Nostr: 📅 Original date posted:2022-06-10 📝 Original message:Hi alicexbt, Routing ...
📅 Original date posted:2022-06-10
📝 Original message:Hi alicexbt,
Routing attacks have actually been studied quite a bit in literature.
You may be interested in the research articles of Maria Apostolaki et al.[1,2], Muoi Tran et al.[3], and related works.
Best,
Elias
[1]:
https://arxiv.org/pdf/1605.07524.pdf[2]:
https://arxiv.org/pdf/1808.06254.pdf[3]:
https://allquantor.at/blockchainbib/pdf/tran2020stealthier.pdfOn 9 Jun 2022, at 20:24, alicexbt via bitcoin-dev wrote:
> Hi Bitcoin Developers,
>
> Based on this [answer][1] from 2014, bitcoin nodes are vulnerable to BGP hijacking. There was an incident in March 2022, twitter prefix was hijacked and details are shared in 2 blog posts:
>
>
https://isc.sans.edu/diary/rss/28488>
>
https://www.manrs.org/2022/03/lesson-learned-twitter-shored-up-its-routing-security/>
> 'nusenu' had written an article about Tor network being vulnerable to BGP hijacking attacks:
https://nusenu.medium.com/how-vulnerable-is-the-tor-network-to-bgp-hijacking-attacks-56d3b2ebfd92>
> After doing some research I found that RPKI ROA and BGP prefix length can help against BGP hijacking attacks. I checked BGP prefix length and RPKI ROA for first 10 IP addresses returned in `getnodeaddresses` in bitcoin core and it had vulnerable results.
>
>
>
> Has anyone written a detailed blog post or research article like nusenu? If not I would be interested to write one in next couple of weeks?
> Looking for some "technical" feedback, links if this was already discussed in past with some solutions.
>
> [1]:
https://bitcoin.stackexchange.com/a/30305/133407>
>
> /dev/fd0
>
> Sent with Proton Mail secure email.
> _______________________________________________
> bitcoin-dev mailing list
> bitcoin-dev at lists.linuxfoundation.org
>
https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-devPublished at
2023-06-07 23:10:24Event JSON
{
"id": "be0e576ba82d720ca35d3c06ea3ef389aad6c9ae74e8e59c5c6a5d110174bd53",
"pubkey": "532304c7124462d71b48a676af96ef5f13134ac4a05abe5f1f4f5c7a2b965e8c",
"created_at": 1686179424,
"kind": 1,
"tags": [
[
"e",
"9e3895533821079b793bcc454114fd3e3c2751a57fc62c3d38bb276ecddc10ef",
"",
"root"
],
[
"e",
"57de4e4382822d34263e7b9644b7deac2c791a31ebc8947a1594aa79ae410876",
"",
"reply"
],
[
"p",
"745e2723e72d7ded3f0dd293d710b706cd302ab8476983c292d4bdb7f9c5d366"
]
],
"content": "📅 Original date posted:2022-06-10\n📝 Original message:Hi alicexbt,\n\nRouting attacks have actually been studied quite a bit in literature.\n\nYou may be interested in the research articles of Maria Apostolaki et al.[1,2], Muoi Tran et al.[3], and related works.\n\nBest,\n\nElias\n\n[1]: https://arxiv.org/pdf/1605.07524.pdf\n[2]: https://arxiv.org/pdf/1808.06254.pdf\n[3]: https://allquantor.at/blockchainbib/pdf/tran2020stealthier.pdf\n\nOn 9 Jun 2022, at 20:24, alicexbt via bitcoin-dev wrote:\n\n\u003e Hi Bitcoin Developers,\n\u003e\n\u003e Based on this [answer][1] from 2014, bitcoin nodes are vulnerable to BGP hijacking. There was an incident in March 2022, twitter prefix was hijacked and details are shared in 2 blog posts:\n\u003e\n\u003e https://isc.sans.edu/diary/rss/28488\n\u003e\n\u003e https://www.manrs.org/2022/03/lesson-learned-twitter-shored-up-its-routing-security/\n\u003e\n\u003e 'nusenu' had written an article about Tor network being vulnerable to BGP hijacking attacks: https://nusenu.medium.com/how-vulnerable-is-the-tor-network-to-bgp-hijacking-attacks-56d3b2ebfd92\n\u003e\n\u003e After doing some research I found that RPKI ROA and BGP prefix length can help against BGP hijacking attacks. I checked BGP prefix length and RPKI ROA for first 10 IP addresses returned in `getnodeaddresses` in bitcoin core and it had vulnerable results.\n\u003e\n\u003e https://i.stack.imgur.com/KD7jH.png\n\u003e\n\u003e Has anyone written a detailed blog post or research article like nusenu? If not I would be interested to write one in next couple of weeks?\n\u003e Looking for some \"technical\" feedback, links if this was already discussed in past with some solutions.\n\u003e\n\u003e [1]: https://bitcoin.stackexchange.com/a/30305/133407\n\u003e\n\u003e\n\u003e /dev/fd0\n\u003e\n\u003e Sent with Proton Mail secure email.\n\u003e _______________________________________________\n\u003e bitcoin-dev mailing list\n\u003e bitcoin-dev at lists.linuxfoundation.org\n\u003e https://lists.linuxfoundation.org/mailman/listinfo/bitcoin-dev",
"sig": "385900fb9458b77ea299406a53b17b7558117565e96301634ac585bbf93c375b0969a99caa2e957f0727b601b5dc199b775b8b19d2db0dd88c3fdeac1b7bf123"
}