Summary
- npNOG’s official virtual-event record records a December 2020 online programme about routing security and RPKI and attributes attendance of more than 45 people to the event; this is npNOG’s first-party figure, not an independent attendance audit.
- Public measurement can show whether ROA publication or validation conditions changed, but it cannot identify npNOG as the cause without a dated participant-to-action chain.
The useful starting point is narrow. npNOG’s official virtual-event page records an online programme in December 2020 focused on routing security and RPKI. The organisation’s public record attributes participation by more than 45 people to the event; this is a first-party count, not an independent attendance audit. Those facts establish that npNOG held a public programme around a concrete operational problem.
They do not establish what happened after the screen went dark.
Creating a Route Origin Authorization is an action taken by, or with the authority of, a resource holder. Deploying route-origin validation is a separate operator decision involving policy, testing, failure handling and continuing maintenance. A panel can improve awareness without giving an engineer permission to change either production routing or registry data. It can also contribute to a later decision without being the only cause.
That distinction matters because the available measurements answer different questions. APNIC Labs’ measurement surfaces and its published method cover ROA publication and route-origin-validation behaviour. These can help construct a dated view of routing-security conditions. They cannot reveal who attended the npNOG session, what an employer authorized, whether a vendor or APNIC trainer intervened later, or why a specific network changed its configuration.
APNIC’s own analysis of whether training affects RPKI usage makes the causal problem explicit. Aggregate ROA figures can move after training, yet wider adoption, other training events and unrelated operational decisions remain plausible explanations. A before-and-after chart is therefore a signal for investigation, not a verdict on programme impact.
The strongest evidence would connect four dated elements: a participant or represented network; the knowledge or intended action recorded around the event; a later ROA, validator or routing-policy change; and testimony or documentation explaining the connection. Each link should survive alternative explanations. Where disclosure would expose sensitive routing practice, a privacy-safe aggregate or consented case study is preferable to naming engineers or configurations.
The public record reviewed here does not provide that chain. It also does not prove that no chain exists in private organisational records. The correct finding is not failure. It is that the operational follow-through remains unverified from public evidence.
That result still has practical value. npNOG can preserve future follow-through without turning training into surveillance: ask participants, with consent, whether they expect to create a ROA, test validation or brief colleagues; record the baseline date; follow up after a defined interval; and publish aggregate outcomes alongside drop-off and unknowns. Measurements should be paired with explanations from the networks that control the changes.
The official record establishes that the 2020 programme publicly addressed an operational problem. Whether anything changed afterwards depends on evidence after the event, not on an attributed attendance count alone.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
