The internet has no center, no master switch, and no single owner. It is tens of thousands of independently run networks, called autonomous systems, stitched together by agreements and one remarkably old protocol. That protocol is BGP, the Border Gateway Protocol, and every packet you have ever sent has relied on it to find its way.

BGP is often called the postal system of the internet. Understanding what it does, and why it trusts everyone by default, explains some of the strangest outages in internet history, including the day Facebook erased itself from the map.

What BGP actually does

Every device on the internet has an IP address, and addresses are handed out in blocks called prefixes. An autonomous system, or AS, is a network under one administrative control: your ISP is one, a university is one, a cloud provider operates several. Each AS gets its own autonomous system number, or ASN, as its identity.

BGP is the language ASes use to talk to each other about reachability. A network announces to its neighbors: I can deliver traffic to these IP prefixes, and here is the path I would take. Those announcements propagate from neighbor to neighbor until, within minutes, routers across the planet know how to reach nearly every address on the internet. When your ISP's router decides which direction to send your packet, it is consulting a routing table built from BGP announcements.

Think of it as road signs. Every major network puts up signs saying which destinations lie down its roads. Routers read the signs and pick the best route. The catch, and it is a big one, is that BGP has no mechanism to check whether a sign is telling the truth.

Announcements built on trust

Enjoying this story?

Get the five most important stories in tech, every morning. Free.

BGP was designed in the late 1980s and standardized in the 1990s, when the internet was a small club of research institutions that mostly trusted each other. Authentication was left out. Any operator of an AS can announce any prefix, including prefixes belonging to someone else, and neighbors will generally accept the announcement and relay it onward.

BGP runs on trust between tens of thousands of networks, and it has no built-in way to check whether a routing announcement is true.

BGP also has a simple tie-breaking rule: the most specific announcement wins. If one network announces a large block of addresses and another announces a smaller block inside it, routers prefer the smaller, more precise one. That rule is normally useful. It is also exactly what makes hijacks so effective, because an attacker only needs to announce a slightly more specific prefix to siphon traffic away from the legitimate owner.

Most incidents are not attacks at all. They are configuration mistakes, a mistyped command or a filter applied to the wrong router, amplified at internet speed to global scale. Two famous cases show how.

Two outages that broke the internet

RPKI adoption: share covered by Route Origin Authorizations (%)

Verified figures, 2026.

2023 prefixes with ROAs
33
2025 prefixes with ROAs
50
2023 traffic to ROA destinations
50
2025 traffic to ROA destinations
67

On October 4, 2021, Facebook, Instagram, and WhatsApp vanished from the internet for nearly six hours, locking out around 3.5 billion users. The cause was not a cyberattack. During routine backbone maintenance, a faulty configuration change on Facebook's backbone routers disconnected its data centers from each other. When the company's DNS servers lost contact with the data centers, they automatically withdrew their BGP route advertisements. In effect, Facebook told every router on earth to forget how to reach it, and the company disappeared from the internet's map. Recovery was slowed because Facebook's own internal tools ran on the same infrastructure, forcing engineers to fix things on site.

Thirteen years earlier, a smaller mistake produced a similar spectacle. On February 24, 2008, Pakistan Telecom tried to block YouTube inside Pakistan by announcing a black-hole route for YouTube's addresses to its own network. The announcement leaked to its upstream provider, PCCW in Hong Kong, which propagated it worldwide within about two minutes. Because Pakistan Telecom announced the more specific prefix 208.65.153.0/24 while YouTube announced the broader 208.65.152.0/22, routers everywhere preferred the bogus route. YouTube became unreachable for most of the world for roughly two hours, and the flood of misdirected traffic overwhelmed Pakistan Telecom's own network for days.

RPKI: the fix that is halfway deployed

BGP by the numbers

Duration of the 2021 Facebook outage
~6 hours

Faulty backbone router config, Oct 4 2021

People affected by the Facebook outage
~3.5 billion

Facebook, Instagram, WhatsApp users

IPv4 routes cryptographically validated by RPKI
~51%

Global average, 2025

Internet traffic to ROA-protected destinations
70%+

Per US ONCD / MANRS, 2025

End-user networks fully validating routes
6.5%

Cloudflare measurement, 261M users protected

The long-term answer to BGP's trust problem is called RPKI, the Resource Public Key Infrastructure. It lets the legitimate holder of an IP block publish a cryptographically signed statement, a Route Origin Authorization, declaring which autonomous system is allowed to announce it. Routers that perform Route Origin Validation check announcements against these statements and can drop the fakes.

Deployment has real momentum. About half of BGP routes now carry valid authorizations, and more than two-thirds of internet traffic by volume flows to destinations protected by them, according to industry measurements presented at APRICOT 2025. Misconfiguration incidents are measurably declining. But there is a gap between publishing authorizations and actually enforcing them: Cloudflare measured effective validation coverage at only 6.5 percent of end-user networks, protecting about 261 million users. Many large networks, including some in the United States, still have not signed their own address space.

Governments are now pushing. The White House published a BGP security roadmap calling for wider RPKI deployment, including a goal of covering 60 percent of federal government IP space with authorizations. RPKI stops the most common accidents and simple hijacks, though it does not validate the full path of a route, so a determined adversary with control of a legitimate network can still cause trouble.

BGP will probably never be replaced; it is too deeply embedded in how the internet works. Instead it is being slowly retrofitted with the authentication its designers never imagined it would need. Every new signed prefix makes the next Pakistan Telecom-style accident a little less likely, and that quiet, incremental hardening is how the internet's most important protocol is finally growing up.

References

Cloudflare blog on RPKI and route origin validation. MANRS and APRICOT 2025 routing security panel. Dark Reading on the White House BGP roadmap. Wikipedia on BGP hijacking. Network World on worst routing attacks. TechTarget on the 2021 Facebook outage.