RPKI Didn't Fix Routing.

We validated who is allowed to announce a prefix. We never validated how it gets there.

We validated who is allowed to announce a prefix.

We never validated how it gets there.

That's not a gap in deployment. That's a gap in the protocol. And after a decade of RPKI, 829,518 ROAs, and MANRS badges on every conference slide — route leaks are still normal.

// a titanium company carried cloudflare's traffic

June 2019. Allegheny Technologies — metals company, Pennsylvania — became transit for Cloudflare, Amazon, and Fastly. 20,000 routes through Verizon. Three hours.

Every route had a valid ROA.

RPKI looked at the origin. Origin was correct. Prefix was correct. RPKI said: looks good. Meanwhile, traffic for half the internet flowed through a company that makes titanium alloys.

The path was wrong. RPKI doesn't check the path.

// what rpki checks
who announced this prefix?yes
should this AS be in the path?no

// this keeps happening

Rostelecom, 2020. 8,800 prefixes rerouted through Russia. All ROAs valid.

Telekom Malaysia, 2015. 179,000 prefixes leaked. Global disruption. All origins correct.

Orange Espana, 2024. Attacker compromised their RIPE account — password was "ripeadmin", no 2FA — and flipped their ROAs. RPKI became the weapon.

Route leaks don't change the origin. That's why RPKI can't see them. That's why they keep happening.

// aspa

Autonomous System Provider Authorization. Each AS signs a statement: these are my upstream providers.

Routers check: does this path follow known provider-customer relationships? If an AS appears where it shouldn't — carrying traffic it has no business carrying — the path is invalid.

Allegheny transiting Cloudflare? Invalid. Rostelecom carrying Akamai? Invalid. Every major route leak in the last decade? Caught.

No per-hop cryptography. No protocol changes. No BGPsec fantasies. Just a signed list of providers and a simple path check.

// the numbers

// global rpki — today
ROAs (origin)829,518
ASPAs (path)1,554
BGPsec keys2

829,518 objects protecting origins. 1,554 protecting paths. Origins are rarely the problem. Paths are the problem every week.

BGPsec has two keys deployed globally. It's dead. ASPA is what's left.

// what's blocking it

Cisco, Juniper, Nokia, Arista — none ship ASPA filtering. Validators support it. Routers don't. That's the bottleneck.

ARIN still doesn't fully support ASPA object creation. Half the internet can't participate.

And the industry thinks the job is done because ROAs are deployed.

The job is half done.

// what to do

If you operate an AS: create an ASPA object. RIPE and APNIC support it. Five minutes. List your upstreams.

Then push your transit providers. Then push your router vendor.

1,554 out of 75,000 ASes. That's where we are.

We spent a decade protecting the origin. The path is still wide open.

Feedback and correction by Doug Madory:

"Minor correction in the Allegheny Technologies leak anecdote, the leaked Cloudflare routes were RPKI-invalid due to max-prefix-length violations, but Verizon wasn't dropping invalids at the time. Also the Orange Espana incident wasn't a leak of any kind."