Cloudflare debuts Is BGP Safe Yet, a site that checks if ISPs have added security protections and filtering that make Border Gateway Protocol less vulnerable
Lily Hay Newman / Wired :
Context & Ripple Effects
Cloudflare has spent years trying to fix Border Gateway Protocol from its own side of the table: it rolled out resource public key infrastructure to all customers in 2018 to stop route leaks and hijackings, then built multipath domain control validation so HTTPS certificates survive BGP attacks. Is BGP Safe Yet flips the pressure outward — a public check on whether individual ISPs have done their half of the work.
The timing matters because BGP itself hasn't changed: it remains the trust-based protocol designed in 1989 that still directs most internet traffic, and outages traceable to it keep recurring. The site turns an abstract protocol debate into a per-ISP scorecard, prefiguring the collective approach later formalized by MANRS and the eventual White House roadmap for shoring up routing security.
First-order effects
- ISPs without RPKI validation or route filtering are now publicly identifiable by any customer who visits the site — reputational exposure lands on network operators the same day the tool ships.
Second-order effects
- Peers like Google, already invested in MANRS-style safeguards, gain a ready-made benchmark to push laggard networks toward filtering, turning routing security into a competitive and peering-negotiation lever rather than a goodwill gesture.
Third-order effects
- If naming-and-shaming measurably lifts adoption, expect the pattern to harden into policy: the later White House roadmap shows governments stepping in where voluntary vendor pressure stalls, moving BGP security from best-effort to baseline expectation.
The trend: Internet routing is shifting from a decades-old trust-based protocol toward verifiable, filtered paths, with vendors like Cloudflare applying public pressure ahead of formal government intervention.