I keep seeing RPKI stuff in my Hetzner panel?? It says invalid sometimes and my email blows up??
Is this actually helping small guys like me or just more stuff to break?? Feels like every time I touch it something goes wrong...
I keep seeing RPKI stuff in my Hetzner panel?? It says invalid sometimes and my email blows up??
Is this actually helping small guys like me or just more stuff to break?? Feels like every time I touch it something goes wrong...
Small networks without dedicated network operations staff must manage cryptographic objects with expiration dates, and the penalty for error is complete reachability loss. To my knowledge, no major transit provider has been depeered for missing ROAs, yet small networks face this risk daily. The GDPR angle is also relevant; the RIPE database already publishes enough for correlation attacks, and RPKI adds nothing to privacy protection.
¿why not make it simple brother. Is very confuse for me too. Jaja. My provider at RackNerd — https://www.racknerd.com — say I need ROA but the panel is very bad. I break everything.
The big guys have teams for this. We have sunday afternoon and hope!
Guys what margins you getting on RPKI compliance?? Any leads on panels that handle this auto?? My clients at Vultr dont wanna pay extra for something they dont understand but I got liability if they get hijacked
Recieved quote from one vendor and their pricing is crazy
Enterprise-grade RPKI deployment is standard across our redundant feeds. N+1 validation infrastructure ensures cryptographic integrity. Our sales team can discuss value-aligned solutions for your specific requirements. Location is North America, Europe, and APAC-adjacent. We do not disclose specific facilities for security reasons.
SNAPPED UP A /24 WITH VALID ROA FOR $12/YR ARE YOU KIDDING
RPKI DIDNT STOP THAT DEAL
But yeah for real the big incumbents love this stuff bc it keeps small competition out. Price history on CloudCone shows RPKI-ready blocks going for 3x now. RUN THE NUMBERS
The graphs do not lie. I track accidental invalidation through my own monitoring and through public RPKI repositories. In the last eighteen months, I have measured a 4.7 percent invalidation rate among networks with fewer than five prefixes, versus 0.3 percent for networks with more than one hundred. The cause is typically expired ROAs after personnel changes, or provider-managed RPKI where the provider rotated keys without notice. Small networks lack the alert infrastructure to catch these before they become outages. The data suggests the validation overhead is regressive by design, whether intentional or not.
Same, my provider also rotated keys without telling me
4.7 percent feels low if we're counting RackNerd customers
Following this thread. My Vultr in Singapore has RPKI toggle in panel but zero explanation what happens if I touch it.