Cloudflare’s DNS Resolver Experiences BGP Hijack

Published:

spot_img

Cloudflare’s DNS Resolver Service Hit by BGP Hijacking Incident – Security Concerns Raised

Cloudflare, a prominent internet infrastructure service provider, recently experienced an unintentional BGP hijacking incident that caused temporary outages and slowdowns in its privacy-first public DNS resolver service. The incident, which occurred on June 27, affected less than 1% of internet traffic but raised concerns about the security of the aging internet routing protocol known as BGP.

The outage was a result of two simultaneous BGP issues that led to a routing hijack and route leak, effectively disrupting the Cloudflare DNS resolver service “1.1.1.1” for users in certain regions. The incident highlighted the vulnerabilities in the BGP protocol and the potential risks associated with improper routing announcements.

Cloudflare engineers explained that historical use of the IP address 1.1.1.1, which has been commonly used for testing purposes, contributed to the misrouting of traffic. The incident involved unauthorized announcements of routing information by specific Autonomous Systems, leading to traffic blackholing and slowdowns for Cloudflare’s users.

To address these issues and prevent future incidents, Cloudflare recommended the adoption of security measures such as RPKI, BGP best practices, and ASPA for BGP. They also expanded their route leak detection system to enhance their ability to respond to similar events promptly in the future.

Overall, the Cloudflare BGP hijacking incident serves as a reminder of the importance of securing internet routing protocols to prevent disruptions and ensure the reliability of online services. As internet infrastructure continues to evolve, proactive measures to enhance security and prevent unauthorized routing announcements will be essential to safeguarding the stability of the internet.

spot_img

Related articles

Recent articles

WhatsApp Launches Beta of Scam Alert Feature to Identify Suspicious Messages

WhatsApp has initiated a limited beta rollout of its Scam Alert feature, designed to identify suspicious messages from non-contacts using an on-device machine learning...

Ransomware Recovery Challenges: 34% of ANZ Organizations Still Opt to Pay Ransom Despite Uncertain Outcomes

Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom....

OpenAI Flags Astra Model for Critical Cybersecurity Risks, Halting Development

OpenAI has raised alarms regarding its forthcoming AI model, Astra, which may pose a ‘critical’ cybersecurity risk. This assessment has led the company to...

Redomiciling to Dubai does not exempt firms from MiCA obligations, warns Relm official

Insurance gaps in director liability, custody, and wallets often surface only after crypto firms relocate, warns Relm’s global distribution chief. Dubai has become a focal...