/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cloudflare says it is rolling out resource public key infrastructure to all of its customers to stop route leaks and route hijackings

Zack Whittaker / TechCrunch : Thanks: @thenicolenewby

TechCrunch Zack Whittaker

Context & Ripple Effects

Cloudflare has a track record of turning security features it built for itself into defaults for every customer: it made TLS 1.3 and automatic HTTPS rewrites standard across client sites back in 2016, and later followed with multipath domain control validation to protect HTTPS certificate issuance from BGP hijacking. Rolling out RPKI to all customers extends the same playbook from encryption and certificates down to the routing layer itself.

The move matters because route leaks and hijackings are an ISP-side problem that website operators historically could not fix on their own — which is why Cloudflare's next step in this arc was building Is BGP Safe Yet, a public checker that names and shames ISPs lacking filtering protections.

First-order effects

  • Every Cloudflare customer gets protection against route leaks and BGP hijackings without configuring anything themselves, shifting the burden of validating routes onto Cloudflare's network operations.

Second-order effects

  • ISPs and transit providers that do not implement RPKI filtering become the visible weak link in their customers' security chain, inviting the kind of public pressure Cloudflare later formalized with its ISP-checking site.
  • Rival CDN and cloud providers face pressure to match RPKI deployment as a baseline feature rather than an enterprise upsell.

Third-order effects

  • If platform providers keep absorbing routing- and certificate-layer defenses as free defaults, internet trust infrastructure consolidates around large networks while smaller hosts must either interconnect with them or replicate the validation work.
  • The pattern points toward cryptographic validation of internet routing becoming table stakes enforced by market pressure and public scorecards rather than regulation.

The trend: Core internet security controls are migrating from opt-in enterprise purchases to defaults baked into infrastructure platforms, with Cloudflare using free rollouts to set the baseline its rivals and upstream ISPs must meet.