AS prepending as traffic engineering, route leak detection, RPKI filtering absence, CANTV routing policies, Cloudflare Radar data interpretation, distinguishing misconfigurations from intentional attacks
← Back to There were BGP anomalies during the Venezuela blackout
While some observers suggest that CANTV’s BGP route leak was a targeted intelligence-gathering effort or a pre-kinetic mapping of critical infrastructure, many experts argue that the excessive AS path prepending points instead to routine traffic engineering or a common configuration error. The absence of RPKI filtering at major transit providers like Telecom Italia Sparkle complicates the situation, as it leaves the network vulnerable to the propagation of such anomalies whether they are accidental "stuck" routes or malicious hijacks. Although the timing relative to a major power outage raises suspicions of cyberwarfare, skeptics note that Cloudflare Radar data shows such routing fluctuations are frequent occurrences that often result from secondary effects like hardware failures or power disruptions. Ultimately, the discourse highlights the inherent insecurity of BGP, where the line between a routine "fat-finger" mistake and a sophisticated state-sponsored operation remains difficult to distinguish.
21 comments tagged with this topic