{"version":"1.0","type":"rich","provider_name":"Acast","provider_url":"https://acast.com","height":250,"width":700,"html":"<iframe src=\"https://embed.acast.com/$/6230b87ec3fb6c0013f156c6/6707b3e514b366c8979df217?\" frameBorder=\"0\" width=\"700\" height=\"250\"></iframe>","title":"Patching Internet Vulnerabilities with RPKI","thumbnail_width":200,"thumbnail_height":200,"thumbnail_url":"https://open-images.acast.com/shows/6230b87ec3fb6c0013f156c6/1728557872498-af28456b-fd43-41bc-ae12-50b0e2f1c097.jpeg?height=200","description":"<p>The White House recently announced plans to boost Internet routing security in the US through better RPKI coverage. So how does RPKI help secure BGP? How easy is it to boost coverage on a national level? And what's the future potential of the infrastructure? Our guest Tim Bruijnzeels shares his views.</p><p><br></p><p>Tim is Principal Software Engineer for RPKI at the RIPE NCC and has worked in standards development and software implementation around RPKI for well over a decade. He talked to us about where RPKI is at today, how governments can and have aided its adoption, and how work being done on ASPA and BGPsec promise a more secure future for the Internet.</p><p><br></p><p><strong>Show notes:</strong></p><p>02:40 - The <a href=\"https://www.ietf.org/proceedings/72/\" rel=\"noopener noreferrer\" target=\"_blank\">Dublin IETF meeting back in 2008</a>.</p><p>03:17 - Tim has contributed to <a href=\"https://datatracker.ietf.org/person/tbruijnzeels@ripe.net\" rel=\"noopener noreferrer\" target=\"_blank\">a number of RFCs over the years</a>.</p><p>03:40 - <a href=\"https://www.nlnetlabs.nl/\" rel=\"noopener noreferrer\" target=\"_blank\">NLnet Labs</a> develops free, liberally licensed, open-source software for DNS and BGP routing.</p><p>03:50 - <a href=\"https://www.nlnetlabs.nl/projects/routing/krill/\" rel=\"noopener noreferrer\" target=\"_blank\">Krill</a> is a free, open source RPKI Certificate Authority developed by NLnet Labs that lets you run delegated RPKI under one or multiple RIRs.</p><p>07:24 - You can read more on <a href=\"/author/emileaben/does-the-internet-route-around-damage-edition-2023/\" rel=\"noopener noreferrer\" target=\"_blank\">how the Internet routes around damage</a> on RIPE Labs.</p><p>10:47 - Get more information on <a href=\"https://www.ripe.net/manage-ips-and-asns/resource-management/rpki/resource-certification-roa-management/\" rel=\"noopener noreferrer\" target=\"_blank\">how to manage ROAs through the RPKI Dashboard</a>.</p><p>11:36 - Check out the RIPE NCC's <a href=\"https://www.ripe.net/analyse/internet-measurements/routing-information-service-ris/\" rel=\"noopener noreferrer\" target=\"_blank\">Routing Information Service (RIS)</a>.</p><p>12:17 - Alex Band's <a href=\"/author/alexband/local-certification-service-launched/\" rel=\"noopener noreferrer\" target=\"_blank\">article on the launch of the RIPE NCC Resource Certification Service back in 2011</a>.</p><p>13:51 - There are a number of RPKI validators to choose from, including <a href=\"https://www.nlnetlabs.nl/projects/routing/routinator/\" rel=\"noopener noreferrer\" target=\"_blank\"><em>Routinator</em></a> from NLnet Labs.</p><p>17:32 - Here's a nice <a href=\"https://rfc.hashnode.dev/aspa-path-verification-explained\" rel=\"noopener noreferrer\" target=\"_blank\">explainer article on ASPA</a>.</p><p>22:07 - <a href=\"https://www.ripe.net/manage-ips-and-asns/resource-management/rpki/rpki-planning-and-roadmap/\" rel=\"noopener noreferrer\" target=\"_blank\">Plans to support ASPA and BGPsec router certificates in RIPE NCC Quarterly Planning</a>.</p><p>24:42 - <a href=\"https://www.whitehouse.gov/oncd/briefing-room/2024/09/03/press-release-white-house-office-of-the-national-cyber-director-releases-roadmap-to-enhance-internet-routing-security/\" rel=\"noopener noreferrer\" target=\"_blank\">Press Release: White House Office of the National Cyber Director Releases Roadmap to Enhance Internet Routing Security</a>.</p><p>26:47 - More on <a href=\"https://www.forumstandaardisatie.nl/nieuws/secured-internet-routing-dutch-government-end-2024\" rel=\"noopener noreferrer\" target=\"_blank\">Dutch government measures for ensuring RPKI coverage</a>.</p>","author_name":"RIPE Labs Editor"}