Build1 distinct publisher3 min readUpdated
Cloudflare says its RFC 9234 tracking found two large Tier-1 networks removing the Only to Customer attribute from routes they forward, blanking the leak signal for everyone behind them.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Cloudflare has described a method for measuring RFC 9234 uptake by watching which of its peer autonomous systems attach the Only to Customer (OTC) path attribute to the routes they send it, using its global peering presence as the vantage point [1]. In the course of that work it found something it says it did not expect: two large Tier-1 networks strip the OTC attribute from routes they forward [2].
The mechanism being measured is worth stating precisely, because it is a change in who does the work. BGP routing is driven by relationships between ASes, customer-provider and peer-peer, where customers pay providers for access to the rest of the Internet and peers exchange traffic settlement-free [3]. Those relationships imply a valley-free hierarchy: a route learned from a provider or a peer should be announced only downward to customers, never back up to another provider or peer [4]. The rules are asymmetric, and an AS may send upward or sideways only the routes it originates and those learned from its own customers [5]. RFC 7908 defines a route leak as the propagation of routing announcements beyond their intended scope [6], and the common shape is the hairpin turn, a customer announcing a route between two of its providers [7]. That is bad economics and bad capacity planning at once: the customer is not paid to carry traffic between its upstreams and may not be able to absorb it, producing added latency or drops [8].
Until now the enforcement has been manual. Existing defenses depend on prefix filters and IRR-derived policies, which require every AS to express its own relationships correctly, by hand, on every session [9], and Cloudflare characterises that per-network implementation as complex and error-prone [10]. RFC 9234, titled Route Leak Prevention and Detection Using Roles in UPDATE and OPEN Messages, moves the intent into the protocol [11]. It adds a BGP Role capability that requires two neighbours to agree on their relationship when the session comes up [12], and the OTC attribute, which marks routes that must not propagate beyond customers [13]. A router that understands OTC can reject a leaked route on its own, with no operator-written policy behind it [14]. Enforcement shifts from the correctness of the sender's configuration to a check at the receiver [15].
That shift only holds if the marking survives the middle of the path. An attribute that an intermediate network deletes stops protecting every AS beyond that network, which is why the Tier-1 behaviour matters more than a percentage figure would [16]. Cloudflare says it has been engaging with the two networks to allow OTC propagation, on the grounds that this is what makes leak prevention work for early adopters [17]. It also runs the Cloudflare Radar route leak detection system, which tracks routing anomalies continuously [18].
Read the adoption number, when you see it, as a floor rather than a census: the method counts peers that send OTC to Cloudflare, so sessions Cloudflare is not on are invisible to it [19]. Watch whether the two unnamed Tier-1s change their handling, and whether stripping turns out to be deliberate policy or a side effect of unknown-attribute treatment. Operators with Role support available should check both directions of their own sessions, since a correctly marked route is only useful if the neighbour agrees on the relationship it was marked under [12].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Cloudflare developed a method for tracking adoption of BGP Role configurations by monitoring which peer ASes send the OTC attribute to Cloudflare, relying on its global peering presence.
Cloudflare found something it did not expect: two large Tier-1 networks strip the OTC attribute from routes they forward.
BGP routing is driven by relationships between Autonomous Systems, customer-provider and peer-peer; customers pay providers for access to the rest of the Internet, while peers exchange traffic under a settlement-free arrangement where no money changes hands.
The relationship rules form a valley-free hierarchy: a route learned from a provider or a peer should be announced only downward to customers, never back up to another provider or peer.
The rules are asymmetric: routes propagate freely downward, while in the upward or sideways directions an AS may send only the routes it originates and those learned from its own customers.
RFC 7908 defines route leaks as the propagation of routing announcements beyond their intended scope, with the intended scope determined by AS relationships (provider-to-customer or peer-to-peer).
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
First-party measurement, standards-anchored but uncorroborated
The protocol mechanics rest on published standards (RFC 9234, RFC 7908) and are described precisely, which is verifiable. The novel findings - the OTC-receipt measurement method and the two OTC-stripping Tier-1s - come from a single vendor blog with no independent confirmation, no named ASNs, and no adoption figures in the supplied text, so the empirical half of the story is asserted rather than externally checkable.
Early partial deployment
Adoption is real but thin: Cloudflare sees OTC arriving from some peer ASes, yet it states strict mode is not yet realistic for most networks and that during partial deployment most sessions will carry a Role on one side only. Two large Tier-1s stripping OTC further limits practical reach. Precise deployment counts are not in the supplied excerpt, so this is a qualitative low reading rather than a computed share.
Mildly overstated framing, solid underlying finding
The write-up is technically restrained and even foregrounds the negative finding, but it frames its method as 'unique', presents protocol-level leak prevention as displacing operator burden while its own numbers show adoption too low for strict mode, and withholds the ASNs that would let operators act on the stripping report. That leaves a small positive gap between framing and what a reader can currently verify or use.
Vendor blog promoting its vantage point and tooling
Cloudflare has a commercial interest in showcasing its global peering presence as a measurement asset and in promoting Cloudflare Radar's route leak detection, and it positions itself as the party engaging Tier-1s on remediation. Those incentives are moderate rather than severe: the content is standards-advancing, largely mechanism-focused, and includes an unflattering finding about the ecosystem rather than a product pitch.
Moderate: standards facts firm, findings single-sourced
Confidence is split. The RFC 9234 / RFC 7908 mechanics and the operational hazard model are well established and internally consistent. The distinctive claims - adoption level and Tier-1 OTC stripping - depend entirely on one first-party account whose numbers are truncated in the supplied material and whose subjects are unnamed, so the assessment holds the mechanism firmly and the findings provisionally.
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
build
796 pages of semantic search with no vector database, and what it cost to skip one1 distinct publisher
build
Hybrid Post-Quantum TLS: Same Protocol, a 1,216-Byte Key Share1 distinct publisher
security
CDN Tsunami: the protocol translation you pay for is the amplifier1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026