Hacker News new | ask | show | jobs
by tolien 2246 days ago
isbgpsafeyet.com only appeared at 4 p.m BST yesterday, a Friday [1]. It's the timing of that which I took the OP to be commenting on. The GGP mentioned that we're in a month of Friday afternoons, this page dropped literally towards the end of the working day on a Friday afternoon!

As you say, Cloudflare have been promoting RPKI for a couple of years now and it's disappointing that more of the big players haven't implemented it yet but is now the time?

1: https://blog.cloudflare.com/is-bgp-safe-yet-rpki-routing-sec...

> 17/04/2020, 4:00:00 pm BST

> Today, we are releasing isBGPSafeYet.com, a website to track deployments and filtering of invalid routes by the major networks.

3 comments

While I am not a fan of some of Cloudflares actions over the years, they have been positive in the RPKI space for the last several years. They've hosted multiple meetings in their offices with some of the largest networks in the world to discuss RPKI strategy and deployment. They've opened sourced software to lower the bar for entry. Their staff was accomdating to other network operators when they rolled out Origin Validation to not black hole parts of the Internet and reached out to networks to let them know of the error to get it fixed. They, like the network I support have been impacted by some of the same hijacks and I share their frustration when major carriers are not only slow to deploy RPKI or have no plan at all (or even a plan to properly filter their customers: see Verizon). They've been a part of the fight along with other folks who are silent (but those who know, know them).

RPKI is no surprise. People have been beating on their upstreams for it for well over a year. Almost all Internet Exchanges have enabled BGP Origin Validation on their route servers (thanks to the efforts of folks like Job from NTT). It's about time we have a site like this that highlights the overall status of it. That said, there's more we can be doing here to provide metrics on RPKI adoption on the Internet.

Maybe bad optics to do it right now but it needed to be released at some point. If they delayed it until we were at the tail end of the curve of Covid-19 infections, this blog could still rely on "we're still recovering from the pandemic" to support the "bad timing" argument.
For some, it's never the time they should do something. ISPs are notorious for dragging their feet and they'd just find new excuses if CF had delayed the publish.
I mean, the bigger ISPs will just ignore it like they've ignored IPv6 ¯\_(ツ)_/¯

On the other hand, AAISP started automatically assigning IPv6 addresses ~9 years ago, so you can hardly accuse them of dragging their feet. The OP was published on a Saturday, after all.

...and /48s at that too.