Rolling the root key
The root key of the DNS is scheduled to roll on 11 October. How many DNSSEC-validating recursive resolvers have learned of KSK-2024 and incorporated it into their TA sets?
View ArticlePeeringDB product update: April to September 2026
Guest Post: PeeringDB has expanded Advanced Search with API query generation and interactive facility maps, making it easier to move between manual research and automation. The latest update also...
View ArticleIs RPKI becoming harmful to BGP stability?
Guest Post: Could the growing deployment of RPKI become a threat to routing stability? This study analyses more than 11 years of RPKI and BGP data, measuring how much routing activity can be associated...
View Article[Podcast] The October 2026 root KSK roll
In this episode of PING, Verisign's Duane Wessels discusses the transition to the third DNS root KSK key pair, which is scheduled to begin signing the root zone on 11 October 2026.
View ArticleOpinion: The economics of AI
As spending on data centres, power, and computing capacity surges, the question is no longer whether AI delivers value, but who will ultimately pay for it.
View ArticleAI-driven networking and infrastructure design at APNIC 62
Presenters at APNIC 62 explored how AI is reshaping network design and operations, from next-generation optical architectures to autonomous management systems, highlighting scale challenges and...
View ArticleThou shall not pass: Gatekeeping outbound TLS connections
Guest Post: To quantify how closely guideline recommendations align with real-world TLS deployments, we collected over 50 million TLS handshakes during two weeks from our research institution.
View ArticleIP geolocation at APNIC 62: Challenges, geofeeds, and data quality perspectives
At APNIC 62, panellists explored how geofeeds, RIR data, and third-party geolocation providers work together, and why improving accuracy while protecting user privacy is becoming increasingly important.
View ArticleUnderstanding ASPA: The next step in routing security
Join this APNIC Academy webinar to understand how ASPAs work, how they complement ROAs, and how you can begin monitoring and deploying them in your network.
View ArticleLatest BGP hijack targets hosting software vendor
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
View ArticleAPNIC 62: Updates in DNS, DHCP, certificate security, and BGP routing resilience
APNIC 62 Technical Session 1 — Internet Operations highlighted major developments across Internet infrastructure, including new management capabilities for Kea DHCP and BIND DNS, preparations for the...
View ArticlePresto: A match-action TCP stack for the terabit era
Guest Post: Presto is built on the RMT architecture that underlies programmable switches, and addresses RMT's main constraints.
View Article[Podcast] ‘Just say no’ isn’t as simple as you think
A continuation of the discussion on surplus DNS queries seen at APNIC Labs, the implications of how you say 'no', and the transport used for the DNS.
View ArticleThe case for open-weight models and why we can’t trust frontier labs
Guest Post: A frontier API can refuse, change, or vanish out from under you. Open weights keep the model you depend on yours.
View ArticleOne or two nameservers?
Do multiple dual-stack nameservers increase or decrease repeat DNS queries? The results of this experiment were a complete surprise.
View ArticleBuilding resilient self hosted services is not always easy
Resiliency through more redundancy is important no matter the scenario.
View ArticleWelcome to APNIC 62
APNIC welcomes you to Mumbai, India for APNIC 62. Here is what you can look forward to over the coming days.
View ArticleWhat part of ‘No!’ is so hard for the DNS understand?
At APNIC Labs we've been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.
View Article[Podcast] Measuring the impact of locally served root zone
An analysis of the traffic impacts of locally served root zones, by Ilyas Rahimi at UvA.
View ArticleBeeline: Enforcing application-layer policies in eBPF
Guest Post: While many L7 protocols are complex to parse, the logic needed to enforce L7 policies tends to be simple. For the vast majority (89%) of L7 policies in the wild, Beeline can eliminate the...
View Article