> On 30 Jul 2026, at 09:15, Serge Droz via Security-wg <[email protected]> > wrote: > > I agree with all of you, we need to penalise orgs that don't act, small ones, > but also the hyper scalars, which admittedly have a scale problem. But > externalising these costs is not ok.
Especially the Hyper scalers, as they also make hyper money and have the expertise and money to fix those issues. They just do not have a reason to as nobody's KPI are hit with that and losing customers = losing money, even if those customers are not the best for the Internet. With setups like "APIs for LLMs to automatically setup domains/etc" that even becomes worse as their 'customers' can just rotate through new accounts. "we shut them down when we see, after we took the money from the stolen credit card"... too big to fail... As I just wrote to NANOG (before I noticed this thread, while I mentioned also about unmonitored abuse): https://lists.nanog.org/archives/list/[email protected]/thread/XOZXIJCX6PPMXXO7MHWFOMQDMDMHIXK2/ We have for years (decades actually) had CIDR Reports send to NOG lists, but no action are being taken about known unallocated and reserved prefixes and ASNs and those that pass it on. And that is a very low hanging fruit. One can grab those delegated files and verify them against your own BGP tables and alert and reach out (not even asking to directly drop, though would not be bad :) ) -- misconfigs/accidents happen, we should try to minimize that. Even likely "national interest" ones like DoD prefixes/ASNs are in there, but also from so called big tech CDNs that are supposedly fighting the bad stuff on the Internet with DDoS protection (and apparently also host the booter/stresser services that cause that). At one point governments likely will want to regulate that like the banking industry (not that that helps in the current political climate). KYC (Know Your Customer) is a concept there, but for the Internet that is apparently completely lost as long is money to be made.... and we have the stats, and the logs and all the information, just cannot cannot find the contact for the other party to resolve it, and if one has a contact it often is a black hole with no action. > I'd fully support Denis' proposal, but aas Suresh says, we're really good > here at not doing anything. Same. I wish the world was a bit better with it all, but it is unlikely to change as long as money keeps flowing into pockets of the folks doing so. Regards, Jeroen ----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
