> in which case MD5 passwords on your BGP sessions pretty much
> accomplishes the same thing with a lot less kerfuffle.
oh gosh, sorry I missed this in the previous conversation... for folk following along at home:
TCP-MD5 is really REALLY just: "better CRC(checksum)" on your BGP session, and is in no way related to which routes your bgp-peer should/could/will be sending you over that peering.
Please do not confuse/conflate BGP / TCP-MD5 with routing-security :( Steve Bellovin would be shocked and appalled at such conflation.