14:42 < shane> I thought RPKI stuff was only source validation, not path validation?
14:43 < AlexBand> shane it is... path validation is being developed in the IETF now
14:44 < shane> Right, so RPKI won't solve hijacking, as it is straightforward to play games with AS paths. It will make it slightly harder, and at least avoid misconfigurations. (Or more likely, trade one kind of misconfiguration for another...)
14:45 < AlexBand> it'll solve most fat fingering now, which arguably is the most common problem
14:45 < robert_ripencc> it's very good at preventing fat fingering
14:45 < robert_ripencc> but indeed, path validation is the next step
14:45 < ripe504> in the ARIN region, when some /8's transferred space, the reverse DNS was changed so the old /8 reverse domain no longer held the /8 reverse domain and new delegations to the proper /16s were entered.
14:46 < ripe504> ok, so better said as "old /8 holder no longer held the /8 reverse domain"
14:46 < robert_ripencc> that's neat
14:48 < ripe504> seems that is the only way to do it so new holder of more specific does not have to depend on old holder of /8 to provide reverse domain name service.
14:58 < shane> Hm. I would sure be happy to know that my ISP was following the correct process, even if that didn't fix my Internet connection. 😛
15:09 < shane> Speaking to fellow engineers makes sense.
15:09 < shane> But we can all predict what lawyers will say.
15:09 < shane> "Don't do it."
15:09 < shane> And also, "you need more lawyers". 😉
