The solution
In early April 2020, a Border Gateway Protocol mishap sent traffic bound for major sites like Google and Facebook on a detour through a Russian telecom for over an hour — no hack, just trust-based routing failing again. BGP leaks happen constantly by accident, but the protocol can also be hijacked for spying or interception; that same month, US agencies moved to block China Telecom over activity that included BGP attacks. Cloudflare gets blamed when anything breaks anywhere, and it could not fix the protocol itself — so CEO Matthew Prince said it was time to start naming and shaming.
The site it launched, Is BGP Safe Yet, tests the visitor's own connection: it offers a legitimate route and an invalid one and loads a page over each. An ISP that has deployed the cryptographic checks and route filters catches the bogus route and loads only the real page; an ISP that accepts both fails, visibly. Cloudflare estimated that about half the internet was already protected thanks to heavyweights like AT&T, Sweden's Telia and Japan's NTT — enough that even users on unprotected ISPs often keep working alternatives during an incident.
The design leans on two levers at once: consumers get a one-click way to check something they could never see, and industry players get an easy way to see and be seen. Cloudflare acknowledged limits — some router makers still lacked support for the protections — but hoped public pressure would move both.
Why it worked
BGP is a 40-plus-year-old trust-based protocol; no single participant, not even Cloudflare, can secure it alone — adoption has to be wide to matter.
Non-adopters were invisible: nothing told a consumer their ISP was the one accepting hijacked routes.
A per-connection test converts an abstract plumbing standard into a reputational verdict that names individual ISPs.
Security improves for everyone as coverage grows, so shaming laggards compounds the value of early adopters.
What can be applied
You cannot force interdependent adopters to secure a shared system, but you can make non-adoption visible to their customers.
Aftermath
The site went live on April 17, 2020, with Cloudflare crediting AT&T, Telia and NTT among those already filtering routes; backbone equipment vendors that had not built in support for the protections remained the other half of the lag.
FOLLOW THE EVIDENCE