So here is what I propose. I'm not a lawyer, so maybe this needs to be
phrased differently. But the idea is
a: Make sure poeple read their abuse e-mails
b: Possibly, take further acction if they read it bud don't act.
a: Abuse mailbox tests:
The RIPE NCC cunducts bi-annual communications checks to the abuse
handles. It is expected that these are replied to within [X hours/days/...]
If no replies is received this will be escalated through other contacts.
If no reply is received on may as well assume the org no longer exists
and take appropriate action. LACNIC blocks access.
b: Complaints about missing action
RIPE NCC solicitations feedback about failure to take action. This
feedback should only be admissible for specific abuses, I would start
small (spam, maybe residential proxies, but that's already hard).
If there are n (1, 2, ...) complains the RIPE NCC will send a warning to
the violating organisation.
Here we have to talk about sanctions and time lines. If push comes to
shove I suggest arbitration under Dutch jurisdiction.
This is assuming:
Most people that don't react will react if there is just a slight
incentive to do so. This is the experience I had from abuse fighting
here in Switzerland.
There is much to be discussed, and that's the discussion I'd like to see.
1. Can we make these ideas clerere?
Timelines?
Should we start with a and later follow up with b.
I specifically ask for constructive ideas. If they tunr out not to be
feasible, we have tried.
Best
Serge
On 03/08/2026 02:47, Suresh Ramasubramanian wrote:
As for the closure option, look at one of the first such, and most
prominent such, cases in the ICANN world - Estdomains.
Set up as a criminal front. Very high number of criminal domains.
It went through ICANN’s entire process and they deregistered it.
The few legitimate domains that happened to be on it were transferred
to another registrar (Directi) so that service to those would not be
disrupted.
—srs
*From: *denis walker <[email protected]>
*Date: *Monday, 3 August 2026 at 2:29 AM
*To: *Jeroen Massar <[email protected]>
*Cc: *Serge Droz <[email protected]>; [email protected]
<[email protected]>; Gert Doering <[email protected]>
*Subject: *[Security-wg] Re: Abuse mailboxes are increasingly no
longer monitored and are being replaced by (bad) forms
On Sun, 2 Aug 2026, 22:28 Jeroen Massar, <[email protected]> wrote:
> On 2 Aug 2026, at 16:51, denis walker <[email protected]> wrote:
> [..]
> As things stand there is no accountability, no penalty. It's
either full closure or untouchable. We need a rethink and a reset.
This is what I am working on....
Reverse DNS is needed to spam properly.
IRR / RPKI / ASPA is needed to route (though RPKI/ASPA becomes
'unknown' which is the majority of prefixes today)
So yes, if a RIR does not delegate then a prefix becomes a lot
less useable.
Can this be done using a commercial routing registry like RADb?
Thus marking a LIR as 'under investigation' or similar and then at
non-response closing it can be a means to stop the abuse.
But we are back to the closure option. As I said, closure or
untouchable. If the registry has thousands of legitimate business
customers is the RIPE NCC going to close it?
But, it becomes really tricky if an LIR is saying one thing and a
pile of others are saying another (they did abuse etc)
And I do not think RIRs have the resources (unless membership fees
go insane) to resolve that.
Even if a RIR gives out an 'advise' that the resources are
'tainted' or 'likely abuse' a legal proceeding can cause a whole
lot of problems for the RIR.
By the time that advise goes out on a particular set of numbers, they
probably aren't connected with the abuser any more.
Cheers
Denis
Same for blacklists of course, as the folks from the original MAPS
and nowadays Spamhaus and similar setups can attest to, the legal
issues are the biggest problem there. (and for some on the wrong
side, people claim that the *good* people from Spamhaus do not
respond to the delisting requests etc... )
Regards,
Jeroen
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the
email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/