Hi Gert,
*Not* announcing the /32 globally when there is a valid ROA opens a huge door for everybody and their dog to spoof that /32.
The funny thing here is; * Any RTBH provider today is taking your route(6) objects, which are for say a /24, and building a prefix filter for up to /32 (or /128). * Then applying logic similar to the following: "if RTBH community is attached, and prefix size is /32, and prefix matches prefix filter -> then allow". * This happens for all prefixes of all customers all the way down their AS-SET tree. * The customer (or customer's customer, etc) get's no say in this prefix length expansion (the up to /32 and up to /128). * As we know, anyone can add anything they want to their AS-SET. So for networks which don't use / don't want RTBH, somewhere upstream of them, a provider, without their approval, is allowing more specifics than what that networks announces and has defined in IRR. And they're relying on the non-existing security of AS-SETs. (I should know, we do it!) If you moved that into ROA maxLength you would actually improve on the status quo because only networks that want to use RTBH need to increase their maxLength (stopping providers from doing it without asking you, and proving you with a way to opt out). With kind regards, James Bensley (he/him) ________________________________________ From: Gert Doering Sent: Monday, August 24, 2026 19:21 To: James Bensley Cc: Salvador Bertenbreiter; routing-wg@ripe.net Subject: Re: [routing-wg] Re: RTBH and RPKI Hi, On Mon, Aug 24, 2026 at 03:21:57PM +0000, James Bensley wrote:
One option would be to extend the ROA to /32 or /128, but I???m not fully comfortable with that since it would also make other more-specifics valid.
Why not? That is the most optimal solution for secure RTBH filtering in my opinion. Increase your maxLength, plus implement RFC9234 to validate the peer role, and ASPA to validate the path. I think this is the path we as an industry should be going down, not ignoring maxLength or relying on IRR derived prefix filters.
I don't want to announce my prefixes as a /32 all the time, just because I might want to get an upstream to accept the /32 when I need it for RTBH (or "please wash DDoS") purposes. Also, I do not want the /32 to be visible world wide. *Not* announcing the /32 globally when there is a valid ROA opens a huge door for everybody and their dog to spoof that /32. Nah. Gert Doering -- NetMaster -- have you enabled IPv6 on something today...? SpaceNet AG Vorstand: Sebastian v. Bomhard, Karin Schuler, Sebastian Cler Joseph-Dollinger-Bogen 14 Aufsichtsratsvors.: Dr. Frank Thiäner D-80807 Muenchen HRB: 136055 (AG Muenchen) Tel: +49 (0)89/32356-444 USt-IdNr.: DE813185279 [CompanySignature] Inter..link GmbH | Boxhagener Straße 80, 10245 Berlin, Germany | Managing Directors: Marc Korthaus, Theo Voss | Commercial Register: Amtsgericht Charlottenburg, HRB 138876 | VAT ID: DE281288887 | Email: hello@inter.link<mailto:hello@inter.link> | Web: inter.link<https://inter.link>