<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Maxlength on Wirez</title><link>https://wirez.top/tags/maxlength/</link><description>Recent content in Maxlength on Wirez</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 01 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://wirez.top/tags/maxlength/index.xml" rel="self" type="application/rss+xml"/><item><title>Validation errors break blackhole routes now</title><link>https://wirez.top/posts/validation-errors-break-blackhole-routes-now/</link><pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate><guid>https://wirez.top/posts/validation-errors-break-blackhole-routes-now/</guid><description>&lt;meta charset="utf-8">
&lt;!-- wp:paragraph {"className":"std-text"} -->
&lt;!-- /wp:paragraph -->
&lt;!-- wp:paragraph {"className":"std-text"} -->
&lt;p class="std-text">Bryton Herdes warns that relaxing &lt;strong>maxLength protections&lt;/strong> for blackhole routes creates a direct path for BGP hijacks.&lt;/p>
&lt;!-- /wp:paragraph -->
&lt;!-- wp:paragraph {"className":"std-text"} -->
&lt;p class="std-text">The central thesis is that networks must strictly pair &lt;strong>originAS-only validation&lt;/strong> with the mandatory presence of the &lt;strong>BLACKHOLE community&lt;/strong> to prevent security degradation. While the global network security market races toward USD 205.98 billion by 2031, basic BGP hygiene remains fragile without these specific constraints. Herdes, a Principal Network Engineer at Cloudflare, argues that vendors offering shortcut configurations for loose validation directly undermine RFC9319 standards. &lt;a href="https://blog.cloudflare.com/rpki-2020-fall-update/" target="_blank" rel="noopener noreferrer">Cloudflare&amp;#039;s rpki 2020 fall update&lt;/a>&lt;/p></description></item></channel></rss>