RPKI validates route origins, not the whole path
RPKI lets a network cryptographically state which operators may announce its addresses, and lets others check.
It closes the most common hijack. It does not validate the rest of the path, so a route that originates correctly and then travels somewhere unexpected is not caught. It is a genuine improvement, adopted unevenly, and worth understanding as partial rather than complete.
More on Internet routing
- BGP announces reachability, not truthA claim, not a proof
- BGP hijacking can redirect traffic before applications see itThe points move under the train
- Route leaks can be accidental and disruptiveThe whole motorway down a side lane
- More specific Internet routes usually winThe narrower claim takes it
- Anycast sends one address to multiple placesOne address, many doorsteps
- Route filtering is Internet hygieneWe all drink from the same main
