BGP Security Milestone: Most Major Internet Providers Now Signing Routes

2026-04-02T09:43:23.000Z·★ 80·2 min read
# BGP Security Milestone: Most Major Internet Providers Now Signing Routes Cloudflare's "Is BGP Safe Yet?" tracker reports a significant milestone in internet infrastructure security: the majority of

Cloudflare's "Is BGP Safe Yet?" tracker reports a significant milestone in internet infrastructure security: the majority of major transit providers and ISPs are now implementing both Route Origin Validation (ROV) and RPKI-based filtering, dramatically reducing the risk of BGP hijacking attacks.

What Is BGP Hijacking?

BGP (Border Gateway Protocol) is the routing protocol that holds the internet together. It's also famously insecure — any network operator can announce routes for IP addresses they don't own, potentially redirecting massive amounts of traffic. BGP hijacking has been used for:

The Current State

According to the tracker, major providers now marked as safe include:

ProviderTypeStatus
LumenTransit✅ Signed + Filtering
Arelion (Telia)Transit✅ Signed + Filtering
CogentTransit✅ Signed + Filtering
NTTTransit✅ Signed + Filtering
Hurricane ElectricTransit✅ Signed + Filtering
GTTTransit✅ Signed + Filtering
AT&TISP✅ Signed + Filtering
VerizonISP✅ Signed + Filtering
Deutsche TelekomISP✅ Signed + Filtering
ComcastISP✅ Signed + Filtering

What Changed?

The shift has been driven by several factors:

Remaining Gaps

While progress is encouraging, not all networks are protected. Some providers still lack full RPKI deployment, and the system relies on the weakest link — an unprotected network can still propagate hijacked routes to its peers.

Why This Matters

BGP security isn't just a technical issue — it's fundamental to internet trust. As more critical infrastructure moves online, the risks from BGP hijacking grow exponentially. This milestone represents years of coordinated effort by network operators, standards bodies, and security researchers.

Source: Cloudflare isbgpsafeyet.com

← Previous: 数据科学家的复仇:为什么 LLM 让传统数据技能变得更有价值Next: BGP 安全里程碑:大多数主要互联网提供商现已实现路由签名 →
Comments0