Hedge 306: RPKI Transport

Synchronizing information across the Internet, at an initial glance, looks like a fairly simple problem to solve. Just copy a file to a host and create a magic protocol, right? Not really. Each kind of data has a fairly unique set of requirements–and RPKI data, used to provide security information for BGP, is no different. Job Snijders joins Tom and Russ to talk about ERIK, a protocol developed to synchronize RPKI records.
 
For more information, check out Job’s web site and the IETF draft.
 

 
download

Worth Reading 052126


The Technocratic State represents a new invisible risk of the 21st century, as it does not present itself as a conventional political authority. It appears as a technical solution that seems inevitable.

 


Author and journalist Michael Pollan characterizes our era as the “Second Copernican Shock,” a civilizational turning point where the boundary between human empathy and algorithmic calculation is increasingly blurred.

 


It’s always difficult for ISPs to fully understand how changes in the economy might impact them. Folks in the industry see the usual statistics on unemployment and inflation, but those don’t really tell much about the future as it relates to broadband adoption.

 


Companies rushing to adopt AI and LLMs without a clear strategy may be creating new risks.

 


Power failures are to blame for the most impactful data center outages, while network issues are the most frequent culprits for IT service disruptions, according to Uptime Institute’s latest analysis.

Worth Reading 051826


We’ve all been in that meeting where someone pulls up a chart and says, “Our AI product boosted conversion by 15%.” Everyone nods. Nobody dares to ask: “What if conversions had risen anyway?”

 


The proposed repair is Running-Code Primacy: the number-resource layer should be interpreted only by reference to the minimum technical function running networks require—uniqueness, interoperability, proof of control, routing-adjacent security, and locally verifiable state.

 


You already know IPv6 is overdue. You’ve known for years. You’ve probably sat in a meeting where you laid out the case — address exhaustion, rising costs, growth constraints — and watched leadership nod politely before approving the budget for another batch of leased IPv4 addresses.

 


A key question was whether this reflected a breakthrough specific to one model, or part of a broader trend. Results from an early checkpoint of GPT-5.5 suggest the latter: a second model, from a different developer, now reaches a similar level of performance on our cyber evaluations.

 


The most mature U.S. small modular nuclear reactor vendor — NuScale Power — and a politically connected firm planning to build perhaps the largest reactor project in the U.S. to power an enormous Texas data center — Fermi America — have both suffered recent, major, possibly existential blows.

Worth Reading 051526


Given the trend of using generative AI tools like ChatGPT, Gemini, Copilot, and Claude for software development, many companies have decided that developers must use GenAI to succeed. I strongly disagree.

 


Here, through a series of randomized controlled trials on human-AI interactions (N = 1,222), we provide causal evidence for two key consequences of AI assistance: reduced persistence and impairment of unassisted performance. Across a variety of tasks, including mathematical reasoning and reading comprehension, we find that although AI assistance improves performance in the short-term, people perform significantly worse without AI and are more likely to give up.

 


Last month, market research company, Gartner, said that AI companies need close to “$2 trillion per year in revenue by 2029”, token consumption of between 50,000 and 100,000 times its current rate by 2030, and “a 10% profit margin per token.” With huge losses and small revenues, it is not likely that AI companies will achieve these goals on time.

 


He said that about 20% of all network traffic today, about 80 exabytes, comes from machine-to-machine traffic, and that alone is big news. Nokia is betting its future growth will come from meeting this growing demand.

 


For centuries, political power has repeatedly attempted to territorialize systems whose operational logic depended upon openness, circulation, and coordination beyond borders.

Worth Reading 051226


The screenshot feature has cultivated a wide range of impactful academic research across computing and social scientific fields.

 


When Motorola unveiled its Iridium global satellite-based mobile telephony service in the late 1990’s everything augured well for a revolution in the satellite communications market, only it didn’t happen.

 


While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk.

 


The analytic company IDC says the U.S. economy will be generating 394 trillion zettabytes of data annually by 2028 (a zettabyte is a trillion gigabytes).

 


Enterprise strategists need to worry about securing their environments against AI-powered attacks.

Worth Reading 050926


These milestones highlight the significance RPKI has gained over the past decade. Starting off as an experimental technology, it has become a central component of the Internet, affecting a large percentage of its networks.

 


More than 9.7 million third-party businesses sell goods on Amazon, and Amazon makes a lot of money charging those third parties to sell on its platform—$117.7 billion in 2022, representing 23% of Amazon’s total revenues.

 


For much of the history of computing, it was reasonably safe to assume that a machine was doing what you told it to do (and what its creators promised it would do), because its operations were local.

 


There is always the case that the unexpected happens, and X.509 certificates are no exception. There are circumstances where the certificate should be marked as unusable immediately, which is before the notAfter expiration time.

 


Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure.