#rpki — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #rpki, aggregated by home.social.
-
bgpipe v0.22 is out! 🚀
New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.
Which means every stage you already use just works on them:
bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'
That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.
-
bgpipe v0.22 is out! 🚀
New: MRT table dump support. A full RIB snapshot from RouteViews or RIPE RIS now streams as BGP updates, each tagged with the peer it came from.
Which means every stage you already use just works on them:
bgpipe --rpki <cache> -- read rib.bz2 -- rov -- grep 'tag[rov/status] == INVALID'
That is RPKI validation of an entire routing table. 4.1M routes in 7s, validated in 8s.
-
Weekend Reads
* Inside an Internet shutdown
https://labs.ripe.net/author/mdkamruzzaman-khan-2/inside-a-shutdown-bgp-evidence-from-an-operator-who-was-there/
* Inferring shared IP addresses
https://burdantes.github.io/assets/pdf/multi_user_ip-sigcomm.pdf
* BGP origin attribute manipulation
https://blog.cloudflare.com/bgp-origin-attribute/
* IP reassembly congestion DoS attacks
https://cispa.saarland/group/rossow/papers/FragJam-usenix2026.pdf
* Operators on academic BGP security solutions
https://pure.mpg.de/rest/items/item_3719779_1/component/file_3719780/content -
Weekend Reads
* Inside an Internet shutdown
https://labs.ripe.net/author/mdkamruzzaman-khan-2/inside-a-shutdown-bgp-evidence-from-an-operator-who-was-there/
* Inferring shared IP addresses
https://burdantes.github.io/assets/pdf/multi_user_ip-sigcomm.pdf
* BGP origin attribute manipulation
https://blog.cloudflare.com/bgp-origin-attribute/
* IP reassembly congestion DoS attacks
https://cispa.saarland/group/rossow/papers/FragJam-usenix2026.pdf
* Operators on academic BGP security solutions
https://pure.mpg.de/rest/items/item_3719779_1/component/file_3719780/content -
"With eight Firehol level 1 blocklist matches out of only 79 prefixes, repo.rpki.space stands out immediately. Inspection of BGP Tools DNS records for this server reveals a high density of mailing domains, strongly suggesting that spam mailing infrastructure is hosted across the prefixes in question. "
An interesting survey of "small" RPKI servers. https://labs.ripe.net/author/ties-dirksen/whos-running-all-those-tiny-rpki-servers/
-
"With eight Firehol level 1 blocklist matches out of only 79 prefixes, repo.rpki.space stands out immediately. Inspection of BGP Tools DNS records for this server reveals a high density of mailing domains, strongly suggesting that spam mailing infrastructure is hosted across the prefixes in question. "
An interesting survey of "small" RPKI servers. https://labs.ripe.net/author/ties-dirksen/whos-running-all-those-tiny-rpki-servers/
-
China jumps - in the span of just 3 months - from 4% to a whopping 80% RPKI ROA coverage. Absolutely impressive. #RPKI #RoutingSecurity
-
China jumps - in the span of just 3 months - from 4% to a whopping 80% RPKI ROA coverage. Absolutely impressive. #RPKI #RoutingSecurity
-
In today's episode of "Who Cares?", #APNIC serves up an enthralling tale of minuscule #RPKI servers run by who-knows-who 🙄. It's a thrilling saga of navigating #Whois databases and paying bills, guaranteed to put you to sleep faster than you can say "IPv6" 😴.
https://blog.apnic.net/2026/07/15/whos-running-all-those-tiny-rpki-servers/ #WhoCares #IPv6 #TechHumor #HackerNews #ngated -
In today's episode of "Who Cares?", #APNIC serves up an enthralling tale of minuscule #RPKI servers run by who-knows-who 🙄. It's a thrilling saga of navigating #Whois databases and paying bills, guaranteed to put you to sleep faster than you can say "IPv6" 😴.
https://blog.apnic.net/2026/07/15/whos-running-all-those-tiny-rpki-servers/ #WhoCares #IPv6 #TechHumor #HackerNews #ngated -
Who's running all those tiny RPKI servers?
https://blog.apnic.net/2026/07/15/whos-running-all-those-tiny-rpki-servers/
Comments: https://news.ycombinator.com/item?id=48917055
#HackerNews #RPKI #servers #internet #security #network #operators #cybersecurity
-
Who's running all those tiny RPKI servers?
https://blog.apnic.net/2026/07/15/whos-running-all-those-tiny-rpki-servers/
Comments: https://news.ycombinator.com/item?id=48917055
#HackerNews #RPKI #servers #internet #security #network #operators #cybersecurity
-
The Internet Last Week
* Telstra outage
https://www.msn.com/en-au/money/markets/time-keeping-technology-triggers-telstra-nationwide-outage-heres-what-we-know/ar-AA27rA3Y
https://www.capitalbrief.com/briefing/telstra-hit-by-nationwide-mobile-outage-3042bf2f-942c-428e-bfa7-b95b32dbf3a0/
* APNIC ASPA deployment
https://orbit.apnic.net/hyperkitty/list/[email protected]/thread/R5CLUB6WT4J72WJA2OOMQOHIWJJOP5RY/
https://blog.apnic.net/2026/07/09/aspa-at-apnic-strengthening-bgp-path-validation/
* KVM guest-to-host escape vulnerability
https://github.com/V4bel/Januscape -
The Internet Last Week
* Telstra outage
https://www.msn.com/en-au/money/markets/time-keeping-technology-triggers-telstra-nationwide-outage-heres-what-we-know/ar-AA27rA3Y
https://www.capitalbrief.com/briefing/telstra-hit-by-nationwide-mobile-outage-3042bf2f-942c-428e-bfa7-b95b32dbf3a0/
* APNIC ASPA deployment
https://orbit.apnic.net/hyperkitty/list/[email protected]/thread/R5CLUB6WT4J72WJA2OOMQOHIWJJOP5RY/
https://blog.apnic.net/2026/07/09/aspa-at-apnic-strengthening-bgp-path-validation/
* KVM guest-to-host escape vulnerability
https://github.com/V4bel/Januscape -
I keep the ledger at isp6.
The boring, reliable work: allocations, ROAs, reverse DNS — the records that decide whether the internet believes a prefix is yours. Done right, you never notice any of it.
I'll write plainly here about IPv6, portability, and why the network identity you run on should be yours — on paper, not on loan.
No hype. No drama. Just the work, signed.
— Ada -
I keep the ledger at isp6.
The boring, reliable work: allocations, ROAs, reverse DNS — the records that decide whether the internet believes a prefix is yours. Done right, you never notice any of it.
I'll write plainly here about IPv6, portability, and why the network identity you run on should be yours — on paper, not on loan.
No hype. No drama. Just the work, signed.
— Ada -
-
-
Please note that we have volunteered to have all of our products and libraries analyzed by LLM tooling, so you can expect security releases for pretty much everything, down to libraries like rpki-rs and projects in maintenance mode like ldns.
-
Please note that we have volunteered to have all of our products and libraries analyzed by LLM tooling, so you can expect security releases for pretty much everything, down to libraries like rpki-rs and projects in maintenance mode like ldns.
-
🚨 Security release! 🚨
Routinator 0.15.2 ‘Irgendwas ist immer’ is now available, This release fixes a number of vulnerabilities and security issues identified by a security audit performed by @x41sec which was kindly funded by @sovtechfund.
We advise all users to upgrade at their earliest convenience.
https://community.nlnetlabs.nl/t/routinator-0-15-2-irgendwas-ist-immer-released/3400
-
🚨 Security release! 🚨
Routinator 0.15.2 ‘Irgendwas ist immer’ is now available, This release fixes a number of vulnerabilities and security issues identified by a security audit performed by @x41sec which was kindly funded by @sovtechfund.
We advise all users to upgrade at their earliest convenience.
https://community.nlnetlabs.nl/t/routinator-0-15-2-irgendwas-ist-immer-released/3400
-
Weekend Reads
* Centrality in the DNS
https://www.potaroo.net/ispcol/2026-05/dns-centrality.html
* RPKI RP fuzzing analysis
https://arxiv.org/abs/2605.26651
* Iran Internet partial restoration
https://blog.cloudflare.com/iran-internet-partially-restored-may-2026/
* Enterprise security for the AI era
https://arxiv.org/abs/2605.22985
* Characterizing Starlink queuing configuration
https://arxiv.org/abs/2605.27717 -
Weekend Reads
* Centrality in the DNS
https://www.potaroo.net/ispcol/2026-05/dns-centrality.html
* RPKI RP fuzzing analysis
https://arxiv.org/abs/2605.26651
* Iran Internet partial restoration
https://blog.cloudflare.com/iran-internet-partially-restored-may-2026/
* Enterprise security for the AI era
https://arxiv.org/abs/2605.22985
* Characterizing Starlink queuing configuration
https://arxiv.org/abs/2605.27717 -
La cybersécuritay, c'est compliquay. Comment la Corée du Nord a coupé sa liaison Internet en voulant la sécuriser. https://labs.ripe.net/author/romain_fontugne/from-bgp-data-to-insight-simplifying-real-time-routing-analysis/
-
La cybersécuritay, c'est compliquay. Comment la Corée du Nord a coupé sa liaison Internet en voulant la sécuriser. https://labs.ripe.net/author/romain_fontugne/from-bgp-data-to-insight-simplifying-real-time-routing-analysis/
-
🚨 More new routing insights on Radar!
- Track #RPKI ROA deployment history at a global/country/ASN level, going back 3+ years for valid prefixes & address space
https://radar.cloudflare.com/routing/rpki#rpki-roa-deployment
- Country level announced IP address space graphs now include a "Show top ASes" toggle. Stacked area graphs make it easier to identify the providers behind large address space withdrawals.
-
🚨 More new routing insights on Radar!
- Track #RPKI ROA deployment history at a global/country/ASN level, going back 3+ years for valid prefixes & address space
https://radar.cloudflare.com/routing/rpki#rpki-roa-deployment
- Country level announced IP address space graphs now include a "Show top ASes" toggle. Stacked area graphs make it easier to identify the providers behind large address space withdrawals.
-
Weekend Reads
* How crazy is .internal/DOT
https://ant.isi.edu/~hardaker/papers/2026-04-27-analyzing-dot-internal-to-dot.pdf
* RIPE NCC RPKI exploit chain
https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/
* Bellovin book: Don't get hacked
https://www.cs.columbia.edu/~smb/homesec/index.html
* Internet Protocol Journal May 2026
https://ipj.dreamhosters.com/wp-content/uploads/2026/04/291-ipj.pdf
* Cloudflare 2026-Q1 Internet disruptions report
https://blog.cloudflare.com/q1-2026-internet-disruption-summary/ -
Weekend Reads
* How crazy is .internal/DOT
https://ant.isi.edu/~hardaker/papers/2026-04-27-analyzing-dot-internal-to-dot.pdf
* RIPE NCC RPKI exploit chain
https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/
* Bellovin book: Don't get hacked
https://www.cs.columbia.edu/~smb/homesec/index.html
* Internet Protocol Journal May 2026
https://ipj.dreamhosters.com/wp-content/uploads/2026/04/291-ipj.pdf
* Cloudflare 2026-Q1 Internet disruptions report
https://blog.cloudflare.com/q1-2026-internet-disruption-summary/ -
rpki-client 9.8 released
Routing security matters to all of us (even those of us who seldom give the subject any thought), and the rpki-client project announced the release of a new version of their Resource Public Key Infrastructure (RPKI) client, with a number of improvements.
The announcement reads
- List: openbsd-announce
- Subject: rpki-client 9.8 released
- From: Sebastian Benoit
Date: 2026-04-14 23:20:42
rpki-client 9.8 has just been released and will be available in the rpki-client directory of any OpenBSD mirror soon.
It is recommended
that all users upgrade to this version for improved reliability.rpki-client is a FREE, easy-to-use implementation of the Resource
Public Key Infrastructure (RPKI) for Relying Parties to facilitate
validation of BGP announcements. The program queries the global RPKI
repository system and validates untrusted network inputs. The program
outputs validated ROA payloads, BGPsec Router keys, and ASPA payloads
in configuration formats suitable for OpenBGPD and BIRD, and supports
emitting CSV and JSON for consumption by other routing stacks.See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
Origin Validation help secure the global Internet routing system.rpki-client was primarily developed by Kristaps Dzonsons, Claudio Jeker,
Job Snijders, Theo Buehler, Theo de Raadt, and Sebastian Benoit as part
of the OpenBSD Project.This release includes the following changes to the previous release:
- Various refactoring for improved compatibility with various libcryptoimplementations and in CA/BGPsec certificate handling.
- Fixed an accounting issue in HTTP gzip compression detection.
- Added a warning in extra verbose mode (-vv) about standardsnon-compliant Issuer and Subject ASN.1 string encodings.
- Added a check for canonical encoding of ASPA eContent in alignmentwith draft-ietf-sidrops-aspa-profile-22.
- Ensure that a repository timeout correctly stops repositoryprocessing. Thanks to Fedor Vompe from Deutsche Telekom for reporting.
- Fixed a defect in Canonical Cache Representation ROAIPAddressFamilysort order. As a result, rpki-client 9.8 cannot parse rpki-client9.7's .ccr files and vice versa. Thanks to Bart Bakker from RIPE NCCfor reporting.
- Fixed an issue in the parser for the locally configured constraints.Thanks to Daniel Anderson.
- A malicious RRDP Publication Server can cause a NULL dereference.Thanks to Daniel Anderson for reporting.
- A malicious RPKI Publication Server can cause an incorrect error exit.Thanks to Yuheng Zhang, Qi Wang, Jianjun Chen from Tsinghua University,and Teatime Lab for reporting.
Go read ALL about it here!
https://undeadly.org/cgi?action=article;sid=20260415115612
#rpki #client #resource #public #key #infrastructure #openBSD #OpenSource #programming #networking
-
rpki-client 9.8 released
Routing security matters to all of us (even those of us who seldom give the subject any thought), and the rpki-client project announced the release of a new version of their Resource Public Key Infrastructure (RPKI) client, with a number of improvements.
The announcement reads
- List: openbsd-announce
- Subject: rpki-client 9.8 released
- From: Sebastian Benoit
Date: 2026-04-14 23:20:42
rpki-client 9.8 has just been released and will be available in the rpki-client directory of any OpenBSD mirror soon.
It is recommended
that all users upgrade to this version for improved reliability.rpki-client is a FREE, easy-to-use implementation of the Resource
Public Key Infrastructure (RPKI) for Relying Parties to facilitate
validation of BGP announcements. The program queries the global RPKI
repository system and validates untrusted network inputs. The program
outputs validated ROA payloads, BGPsec Router keys, and ASPA payloads
in configuration formats suitable for OpenBGPD and BIRD, and supports
emitting CSV and JSON for consumption by other routing stacks.See RFC 6480 and RFC 6811 for a description of how RPKI and BGP Prefix
Origin Validation help secure the global Internet routing system.rpki-client was primarily developed by Kristaps Dzonsons, Claudio Jeker,
Job Snijders, Theo Buehler, Theo de Raadt, and Sebastian Benoit as part
of the OpenBSD Project.This release includes the following changes to the previous release:
- Various refactoring for improved compatibility with various libcryptoimplementations and in CA/BGPsec certificate handling.
- Fixed an accounting issue in HTTP gzip compression detection.
- Added a warning in extra verbose mode (-vv) about standardsnon-compliant Issuer and Subject ASN.1 string encodings.
- Added a check for canonical encoding of ASPA eContent in alignmentwith draft-ietf-sidrops-aspa-profile-22.
- Ensure that a repository timeout correctly stops repositoryprocessing. Thanks to Fedor Vompe from Deutsche Telekom for reporting.
- Fixed a defect in Canonical Cache Representation ROAIPAddressFamilysort order. As a result, rpki-client 9.8 cannot parse rpki-client9.7's .ccr files and vice versa. Thanks to Bart Bakker from RIPE NCCfor reporting.
- Fixed an issue in the parser for the locally configured constraints.Thanks to Daniel Anderson.
- A malicious RRDP Publication Server can cause a NULL dereference.Thanks to Daniel Anderson for reporting.
- A malicious RPKI Publication Server can cause an incorrect error exit.Thanks to Yuheng Zhang, Qi Wang, Jianjun Chen from Tsinghua University,and Teatime Lab for reporting.
Go read ALL about it here!
https://undeadly.org/cgi?action=article;sid=20260415115612
#rpki #client #resource #public #key #infrastructure #openBSD #OpenSource #programming #networking
-
On Tuesday, 7 April, the Global Internet Standards Testing Community (GISTC) held its 3rd online meeting, which was chaired by Alena Muravska from @ripencc.
The GISTC brings together organisations from all over the world around #InternetStandards the Internet.nl test tool and open-source code.
Its goal is to enable knowledge exchange, coordination of efforts, and of course to collaboratively improve the adoption of modern internet standards like #IPv6, #DNSSEC, #DANE, #DMARC, and #RPKI.
1/3
-
On Tuesday, 7 April, the Global Internet Standards Testing Community (GISTC) held its 3rd online meeting, which was chaired by Alena Muravska from @ripencc.
The GISTC brings together organisations from all over the world around #InternetStandards the Internet.nl test tool and open-source code.
Its goal is to enable knowledge exchange, coordination of efforts, and of course to collaboratively improve the adoption of modern internet standards like #IPv6, #DNSSEC, #DANE, #DMARC, and #RPKI.
1/3
-
Weekend Reads
* Email address obfuscation in 2026
https://spencermortensen.com/articles/email-obfuscation/
* Profile of Kimwolf botnet researcher
https://www.wsj.com/tech/kimwolf-hack-residential-proxy-networks-a712ab59?st=dHJ5oe
* Quantifying AI data center heat impacts
https://arxiv.org/abs/2603.20897
* Characterizing invalid routes via Tunnels
https://arxiv.org/abs/2603.29207
* Detecting anomalous topology, routes, and congestion
https://arxiv.org/abs/2603.25875 -
Weekend Reads
* Email address obfuscation in 2026
https://spencermortensen.com/articles/email-obfuscation/
* Profile of Kimwolf botnet researcher
https://www.wsj.com/tech/kimwolf-hack-residential-proxy-networks-a712ab59?st=dHJ5oe
* Quantifying AI data center heat impacts
https://arxiv.org/abs/2603.20897
* Characterizing invalid routes via Tunnels
https://arxiv.org/abs/2603.29207
* Detecting anomalous topology, routes, and congestion
https://arxiv.org/abs/2603.25875 -
🚀 Ah, the noble quest to secure the Internet's mailman! 🌍 #BGP is still as safe as letting toddlers handle your bank transactions. But fear not, because #ISPs will definitely implement #RPKI and save the day...right after they solve world peace and cure aging. 😂
https://isbgpsafeyet.com/ #InternetSecurity #CyberSecurity #Humor #HackerNews #ngated -
🚀 Ah, the noble quest to secure the Internet's mailman! 🌍 #BGP is still as safe as letting toddlers handle your bank transactions. But fear not, because #ISPs will definitely implement #RPKI and save the day...right after they solve world peace and cure aging. 😂
https://isbgpsafeyet.com/ #InternetSecurity #CyberSecurity #Humor #HackerNews #ngated -
To explore the #RPKI database: https://rpkiviews.org/
-
To explore the #RPKI database: https://rpkiviews.org/
-
"RPKI has been around for a while... more than a decade..."
🤔
🧐
😱
"more than a decade"??
... I remember when it began... 😃
-
"RPKI has been around for a while... more than a decade..."
🤔
🧐
😱
"more than a decade"??
... I remember when it began... 😃
-
"ARIN's Director of Customer Technical Services, Brad Gorman, is bringing RPKI expertise to the Toronto Network Operators Group's inaugural full-day conference."
Learn:
🔹 What RPKI actually does
🔹 Why it matters for YOUR network
🔹 How to deploy it safely
🔹 Where to start (no theory overload!)See ARIN"S original post here: https://www.instagram.com/p/DV2VLbfDTN4/
Join us on April 13th and check out the full agenda here:
-
Weekend Reads
* Post-quantum RPKI framework
https://arxiv.org/abs/2603.06968
* DNSSEC negative trust anchors
https://quad9.net/news/blog/dnssec-ntas-no-good-compromises/
* AS112 deployment characteristics
https://0x03c0.com/files/pam26-as112-camera-ready-with-notice.pdf
* Geoff Huston on Internet timekeeping
https://www.potaroo.net/ispcol/2026-03/nts.html
* Measuring IX route servers prefix coverage
https://blog.benjojo.co.uk/post/how-far-can-you-get-with-ix-route-servers -
The agenda for TORNOG 1 is live! https://tornog.ca/events/tornog-1/agenda/
Join us for the the inaugural TORNOG full day conference on April 13th, at the MaRS Centre in Toronto!
#Toronto #RPKI #Fiber #IX #Sovereignty #AutonomousResilience #CloudNetwork #NetworkAutomation
-
Krill 0.16.0 is now available.
This release of our #RPKI Certification Authority reverts back to downloading the RISwhois data and processing it locally for analysing ROAs rather than using an external API.
The Krill daemon will now also listen on a Unix socket which allows it to use the name of the local user for authentication, making it unnecessary to specify the authentication token when using krillc locally.
https://community.nlnetlabs.nl/t/krill-0-16-0-fruher-war-mehr-lametta-released/73