{Having not yet read the thread}

It seems like a use for:

1) signed emails: if only we could agree on openpgp vs pkix/SMIME, and we
   could anchor it back to RIRs, like RPKI, but not the same anchor.

2) Structured Email replies that point to forms/issue trackers in a way
   that would accomodate incremental automation.

This only works for providers reporting to other providers, and your
proposal:

Max Grobecker <[email protected]> wrote:
    > So I'm wondering: Would there be a benefit for building some
    > standardized HTTP API with an authentication system, that would allow
    > providers to automatically send authenticated abuse reports to other
    > providers?  That could work in a similar way like DKIM does: The
    > sending provider needs to publish a private key somewhere in the RIPE
    > database, signs the report, and the receiving provider would be able to
    > immediately verify that signature.  And if you get a ton of false
    > reports or even spam from a specific provider you can still filter
    > these out based on the sender information in the signature.

is essentially going to have to be restricted to provider to provider
reports.   abuse@ is intended to receive complaints from end-users, but it
would be also nice if such a system could allow providers to aggregate
reports from their customers.

    > I would like to hear your opinion on this, or maybe there already *are*
    > solutions I just don't know about yet (besides from manually reporting
    > 20-30 phishing mails a day over 30 different forms).

There is a stunted ecosystem around ROLIE, DOTS (IETF), MILE (IETF), STIX,
MISP-project.  CVE/Mitre has never been great, but now we have to replace it,
and there is the GVIP-project.org.  There is a certain software focus among
some, but it ought to be also be about operational concerns.

I tried to engage about this at RIPE79 about IoT reporting:
  
https://www.sandelman.ca/SSW/talks/ripe-iot-unquarantine2019/RIPE79-IoT-Unquarantine-expanded.pdf
(slide 11 onwards)

The CERTs were not even close to ready seven years ago.
I doubt it's better now, as this is totally a tragedy of the commons.
A team of ~12 people (including marketing, communications!) with long-term
funding could make a serious impact via creation and promotion of tools and
methods.   That ought to be CERTs, but somehow it never is.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        | network architect  [
]     [email protected]  http://www.sandelman.ca/        |   ruby on rails    [




--
Michael Richardson <[email protected]>, Sandelman Software Works
 -= IPv6 IoT consulting =-                      *I*LIKE*TRAINS*



Attachment: signature.asc
Description: PGP signature

-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to