Is BGP Safe Yet? No. But we are tracking it carefully
Border Gateway Protocol (BGP) has been a vital part of the internet since the 1980s, but its security features have not kept up with the evolving threats. Resource Public Key Infrastructure (RPKI), a security framework for routing, is considered mature enough for widespread use and can help prevent route leaks and hijacks. Major network operators need to deploy RPKI to make the internet safer. Cloudflare has released isBGPSafeYet.com, a website that tracks RPKI deployment and filtering of invalid routes by major networks. The source code for this website is available on GitHub, and users can test their ISP's implementation of RPKI using two bad prefixes announced from Cloudflare's data centers and Internet Exchange Points (IXPs). By encouraging more networks to deploy RPKI, the internet can become safer and reduce the impact of route leaks.
Company
Cloudflare
Date published
April 17, 2020
Author(s)
Louis Poinsignon
Word count
743
Hacker News points
None found.
Language
English