Yes, if the cloud operator has an office somewhere else, it becomes
complicated. But RIPE doesn't it's 100% pure dutch.
So Dutch la applies. I think in this case the jurisdiction stuff is
simple. In addition to that. I don't think we should go down a route
where we need to think too much about this. We should look at the no
brainers, otherwise we never make progress. We can solve the more
complicated cases later.
Sorry if I created the confusion.
Best
Serge
On 02/08/2026 16:42, Suresh Ramasubramanian wrote:
Now consider where
1.
The user has residency in a country and the country’s law applies
2.
The cloud provider themselves may have a local office in that
country - even if the actual service is ring fenced from other
country jurisdiction, the local subsidiary is a locally
incorporated company etc
The correct answer is that “it is complex”
--srs
------------------------------------------------------------------------
*From:* denis walker <[email protected]>
*Sent:* Sunday, 02 August 2026 20:01:51
*To:* Serge Droz <[email protected]>
*Cc:* [email protected] <[email protected]>
*Subject:* [Security-wg] Re: Abuse mailboxes are increasingly no longer
monitored and are being replaced by (bad) forms
On Sun, 2 Aug 2026 at 14:12, Serge Droz via Security-wg <security-
[email protected] <mailto:[email protected]>> wrote:
In the day and age of cloud services there are hundreds of examples
of services provided to different jurisdictions. Usually the law of
your legal residence applies.
That is not true. If your cloud service has it's data centres in the USA
then US law applies to your data, regardless of your residence.
cheers
denis
Furthermore, APnic and Lacnic do such things, and they cover
multiple jurisdictions,a fact you seem to ignore. At least let us
know what makes them different from us,in away that cannot be changed.
And your cutlery vendor analogy doesn't cut it: Once the knife is
sold, the vendor doesn't control it anymore. That is different from
ip addresses.
Best
Serge
On 2 August 2026 10:26:01 UTC, Nick Hilliard <[email protected]
<mailto:[email protected]>> wrote:
Suresh Ramasubramanian wrote on 01/08/2026 16:31:
That suggests that some capacity building is in order. They
have what is effectively a fiduciary duty to IP space.
So they can no more not develop competence in this than a
bank manager can disclaim all competence in assessing
whether a loan that they disburse is going to be repaid or
not, used for illegal activity or not etc.
Suresh,
the RIPE NCC has a fiduciary duty to registration of IP space.
How those number resources are used is an issue for the courts
and the law.
Your comparison with the bank manager is inapplicable for a lot
of reasons, the main ones being that a bank is not a
registration authority and - unlike money - an IP address isn't
at risk of disappearing into thin air when the holder walks out
the front door.
If you want to claim that the bank manager is still on the hook
to do some due diligence to ensure that it's not obviously being
used for illegal activity, there's no problem pulling out
another somewhat inapplicable comparison and say that road /
motorway operators don't seem to be bound by any sort of due
diligence for use of their resources, and knowingly allow their
roads to be used for all sorts of crimes, many heinous. There
are plenty of situations in society where abuse of a resource or
a registration can cause harm and where we don't require any
sort of due diligence: cutlery vendors don't check their
customer out if someone walks in to buy a carving knife; the
IEEE isn't on the hook if their MAC addresses are used in NICs
which are used for network abuse, and so forth.
The point is not that that you can't invoke comparisons of
dubious comparative value with other organisations or societal
structures, it's that the RIPE NCC is in something of a unique
position, being a registration organisation for a large number
of countries for numbers which are used for international
communications. We don't have a direct analogue anywhere else.
Nick
--
Dr. Serge Droz
Director, Forum of Incident Response and Security Teams
https://first.org <https://first.org>
-----
To unsubscribe from this mailing list or change your subscription
options, please visit: https://mailman.ripe.net/mailman3/lists/
security-wg.ripe.net/ <https://mailman.ripe.net/mailman3/lists/
security-wg.ripe.net/>
As we have migrated to Mailman 3, you will need to create an account
with the email matching your subscription before you can change your
settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-
migration/ <https://www.ripe.net/membership/mail/mailman-3-migration/>
--
Dr. Serge Droz
Director, Forum of Incident Response and Security Teams (FIRST)
[email protected] | https://www.first.org
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/