cloudflare / cloudflare/isbgpsafeyet.com

Amazon/AWS should be listed as partially safe

Open
#758 2 comments 0 reactions 0 assignees View on GitHub
status: pending response
Dominant language
HTML
Stars
329
Forks
349
Avg merge
1d 3h
Merged PRs (30d)
4

Description

[This article](https://chair6.net/lets-encrypt-renewal-failures-and-aws-traffic-hijacking.html) from a couple weeks ago highlights a case of inadvertent hijacking of outbound traffic from AWS to a Direct Connect Public VIF due to a typoed third octet in an advertised /26.

To quote from AWS’s response brought in said article:

> In the instance you reported, there was an issue with our process for validating the ownership of the IP prefix, which led to the traffic being sent to an unintended destination. We have since improved the process by expanding the checks being performed.

> AWS has adopted Resource Public Key Infrastructure (RPKI) in its public peering and transit facing infrastructure [3]. However, RPKI had not yet been adopted in DirectConnect due to the increased burden RPKI would put on DirectConnect users. We are actively investigating improvements to the customer experience by adopting more streamlined mechanisms to verify prefix ownership, similar to the Bring your own IP address (BYOIP) features used with EC2 and Amazon Global Accelerator [4].

So there _is_ supposed to be validation everywhere, and in some places they use RPKI, but it seems they use different forms of fallible (human error-susceptible?) validation on one of the entry points by which customers can inject routes that pull AWS-origin outbound traffic globally. In fact, this seems to be the worst place to not validate, because it’s a connection point that allows — by design — for any customer to inject routes, as opposed to only transit providers or other large network operators that meet the [requirements for public peering](https://aws.amazon.com/peering/policy/).

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the issue’s linked article and AWS response to understand the Direct Connect validation limitation. Find where Amazon/AWS is represented in the site’s safety classifications, update it to partially safe with this caveat, and verify the rendered entry or relevant content checks if available.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws
Domain
networking, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.