HeadlinesBriefing favicon HeadlinesBriefing.com

BGP Security Test Reveals Widespread Partial Signing Among Major ISPs

Hacker News •
×

Over 100 ISPs and transit providers have been tested for BGP security, revealing a significant number operate with partially signed routes. The test, conducted by Lumentransit, shows critical infrastructure like Comcast, AT&T, and Verizon are partially signed, while others like Cogent and NTT Transit are fully signed. This partial signing means these networks can propagate route updates but lack the cryptographic verification to prevent route hijacking or accidental misrouting.

The test highlights a persistent vulnerability in the global internet's core routing protocol, exposing users to potential man-in-the-middle attacks or service outages. Network operators relying on partially signed BGP sessions face elevated risks, emphasizing the need for broader adoption of RPKI validation. The findings underscore a critical gap in securing the internet's backbone, demanding urgent action from both service providers and enterprise networks.