Let’s talk malformed AS_PATHs. Unless you’re enforcing the “First AS” of received routes, you’re vulnerable to hijacks that not even ASPA validation can prevent.
Read more here, and enforce the First AS in BGP.
https://blog.cloudflare.com/enforce-first-as-bgp/
Remote
Bryton Herdes
@next_hopself@mastodon.social
Father of 2 | Principal Network Troublemaker at Cloudflare | JNCIE-SP #3023 | Views are my own
30 Followers
40 Following
4 Posts
Joined January 05, 2026
Open post
ASPA object typo?
Saw this in a path w/ @mingwei@infosec.exchange
🇨🇭AS8298 ↔️ 🇨🇭AS58299 ↔️ 🇺🇸AS13335
AS relationship is inferred as peer-peer between 8298 and 58299.
ASPA object for AS8298 defines AS52899 as a provider, thinking that's meant to be AS58299 🙂
https://radar.cloudflare.com/routing/rpki/as8298#rpki-aspa-providers
2
0
3
0
Open post
Our research suggests Internet routing would be better off without influence by the ORIGIN attribute. In modern BGP, it doesn’t really make sense to have.
Read more in our post
https://blog.cloudflare.com/bgp-origin-attribute/
1
0
0
0
Open post
@mingwei@infosec.exchange and I wrote about how ASPA is going to make routing security better, and some new Cloudflare Radar features that'll help track adoption.
3
0
6
0