SCION: Switzerland's Secure Alternative to BGP Routing Protocol

What SCION Actually Does Differently
SCION addresses BGP's fundamental security flaws through three interlocking mechanisms. First is multi-path routing - where today's internet offers a single path between two points, SCION establishes tens or even hundreds of parallel paths simultaneously. If one fails, the system reroutes within milliseconds. Perrig is precise about the threshold: "Human reaction time for auditory stimulus is roughly 150 milliseconds. We can reroute in less than that."
The second mechanism is cryptographic path validation. Every packet in a SCION network carries cryptographic proof that its route has been authorized by the networks along the path. This prevents route hijacks and leaks at the architectural level, rather than through add-ons like RPKI or BGPsec.
Current Deployment Status
SCION is already proven in banking and healthcare sectors but has been slow to spread everywhere else. The system has been operational in Switzerland's financial networks since 2016 and handles billions in daily transactions. Major Swiss banks use it for inter-bank transfers, and Swiss healthcare networks use it for patient data.
Adrian Perrig, professor of computer science at ETH Zürich and principal architect of SCION, launched the project in 2009 after gaining tenure. His core frustration was simple: the same vulnerabilities had been documented since the 1980s, and nobody had tried to fix them at the architectural level. "The best security companies in the world are still being exploited through them," he says. "There has not even been an attempt to address them properly."
Technical Architecture
SCION replaces BGP's trust-based routing with cryptographic path validation. Unlike BGP's incremental patches (RPKI, BGPsec, ROA), SCION redesigns the routing foundation entirely. Kevin Curran, a cybersecurity professor at Ulster University who has been teaching computer networks for 27 years, offers an independent assessment: "What we have had over 40 years is a series of Band-Aids. Nothing has come close to addressing the need for truly secure paths across an adversarial network."
The system's isolation properties allow networks to operate independently while still participating in global routing. This addresses BGP's lack of cryptographic chain of custody for packet journeys and its slow rerouting process that can take minutes during network failures.
📖 Read the full source: HN LLM Tools
👀 See Also

Testing Uncensored Qwen 3.5 35B Models for Cybersecurity Questions
A cybersecurity professional tested three uncensored Qwen 3.5 35B models on hacking and security bypass questions, finding significant differences in response quality compared to the original censored model. The uncensored models consistently provided answers where the original model refused or gave incomplete responses.

Claude Code source code reportedly leaked via NPM map file
A tweet reports that Claude Code's source code has been leaked through a map file in their NPM registry. The HN discussion has 93 points and 35 comments.

VulnHunter: Capital One's Agentic AI Code Security Tool Now Open Source
Capital One open-sourced VulnHunter, an agentic AI tool that simulates attacker entry points, falsifies findings to cut false positives, and generates targeted code fixes.

LiteLLM v1.82.8 Compromise Uses .pth File for Persistent Execution
LiteLLM v1.82.8 was compromised on PyPI and includes a .pth file that executes arbitrary code on every Python process startup, not just when the library is imported. The payload runs even if LiteLLM is installed as a transitive dependency and never used directly.