{Having not yet read the thread}
It seems like a use for:1) signed emails: if only we could agree on openpgp vs pkix/SMIME, and we could anchor it back to RIRs, like RPKI, but not the same anchor. 2) Structured Email replies that point to forms/issue trackers in a way that would accomodate incremental automation. This only works for providers reporting to other providers, and your proposal: Max Grobecker <[email protected]> wrote: > So I'm wondering: Would there be a benefit for building some > standardized HTTP API with an authentication system, that would allow > providers to automatically send authenticated abuse reports to other > providers? That could work in a similar way like DKIM does: The > sending provider needs to publish a private key somewhere in the RIPE > database, signs the report, and the receiving provider would be able to > immediately verify that signature. And if you get a ton of false > reports or even spam from a specific provider you can still filter > these out based on the sender information in the signature. is essentially going to have to be restricted to provider to provider reports. abuse@ is intended to receive complaints from end-users, but it would be also nice if such a system could allow providers to aggregate reports from their customers. > I would like to hear your opinion on this, or maybe there already *are* > solutions I just don't know about yet (besides from manually reporting > 20-30 phishing mails a day over 30 different forms). There is a stunted ecosystem around ROLIE, DOTS (IETF), MILE (IETF), STIX, MISP-project. CVE/Mitre has never been great, but now we have to replace it, and there is the GVIP-project.org. There is a certain software focus among some, but it ought to be also be about operational concerns. I tried to engage about this at RIPE79 about IoT reporting: https://www.sandelman.ca/SSW/talks/ripe-iot-unquarantine2019/RIPE79-IoT-Unquarantine-expanded.pdf (slide 11 onwards) The CERTs were not even close to ready seven years ago. I doubt it's better now, as this is totally a tragedy of the commons. A team of ~12 people (including marketing, communications!) with long-term funding could make a serious impact via creation and promotion of tools and methods. That ought to be CERTs, but somehow it never is. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works | network architect [ ] [email protected] http://www.sandelman.ca/ | ruby on rails [ -- Michael Richardson <[email protected]>, Sandelman Software Works -= IPv6 IoT consulting =- *I*LIKE*TRAINS*
signature.asc
Description: PGP signature
----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
