If a space is in an email oriented blocklist like say Spamhaus, it just gets 
used for some other kind of abuse ..  DDoS C2, account farming, host illegal 
content and so on.   Or if spam, then spam through some messaging or social 
media platform rather than through email.

From: Jeroen Massar <[email protected]>
Date: Monday, 3 August 2026 at 5:21 PM
To: Serge Droz <[email protected]>
Cc: Suresh Ramasubramanian <[email protected]>; denis walker 
<[email protected]>; [email protected] <[email protected]>; Gert 
Doering <[email protected]>
Subject: Re: [Security-wg] Abuse mailboxes are increasingly no longer monitored 
and are being replaced by (bad) forms



> On 3 Aug 2026, at 13:33, Serge Droz <[email protected]> wrote:
> [..]
> b: Complaints about missing action
> RIPE NCC solicitations feedback about failure to take action. This feedback 
> should only be admissible  for specific abuses, I would start small (spam, 
> maybe residential proxies, but that's already hard).
> If there are n (1, 2, ...) complains the RIPE NCC will send a warning to the 
> violating organisation.

TLDR:
 - Abuse mailbox response is meaningless if the customer gets recycled to 
another host
 - Blacklists make the ASN / address space useless as not more abuse can happen
 - ISPs that care will try to get themselves off blacklists
 - What is the problem to solve with 'reports'?
 - IMHO abuse-mailbox should be volunantary for those that want to take action, 
everybody else should be able to publish a 'do-not-care-won't-handle' as then 
folks know what the network is about.


A response means very very little.


Please note that there are a variety of 'enablers' that will happily answer all 
your abuse reports.

Some will acknowledge the report back to the report and directly forward the 
full email to the one who is using the IP addresses in question.

Some will "shutdown" that "customer". The 'customer' will then create a new 
account, re-setup resources on a different IP and continue doing what it did 
before.

Then the bigger fun: setup a whole bunch of companies, all entered in the trade 
register, paper work legit, all separate entities, heck, have random people act 
as CEO. One of these entities are then used for the LIR, one for one or more 
transit AS, some for datacenters/rack colocation and some others become 
customers of these other entities.

Voila: keep rotating a few of these elements. The reports are handled, 
customers are shutdown (they can even show the config changes, the billing etc) 
But all the reporting will not do anything as it will take time, effort (mostly 
on the side of the reporters and the RIRs) and then possibly some legal 
challenges in the mix to make it all even nastier.


And then the other fun:
 - Spam sources, can be because of compromised hosts, and given Wordpress that 
is easy; next to thousands of others of software with issues (and throw LLM 
analysis in the mix and ... fun)
 - Residential Proxies tend to be enabled not by the customer, but by a gadget 
they buy and plug into their networks.

And that is just two parts of the equation.



Hence the big question is more:

 - what is the exact type of problem you want to solve, and how much time do 
you have.



Noting: I have a long time given up on abuse reporting a long time ago (unless 
I know the entity will act). Hence shutting down, and trying KYC style helps a 
wee bit. But as noted, easy to setup new companies as RIPE NCC is well aware of 
with the many international/out-of-RIR-area customers they get with often 
rather shady setups. But due to the rules they accept them anyway.


I've seen hundreds of megabit flow for weeks, many millions of requests just 
coming in and going; reporting them does often not matter, as even if the 
provider shuts them down, the 'customer' will pop up in a new place. Provider 
takes money, service for a bit, shutdown, repeat....

For some ISPs it is even 'good' to have that kind of traffic, as then they 
might rebalance their network to be more equal in inbound/outbound traffic flow 
which means they can get cheaper/better transit....


Hence why many resort simply to blacklists, or even some cases whitelists. 
Blacklists act quicker and causes a ASN / Prefix to end up blocked. Does not 
matter if they rotate their 'customers' the resource becomes useless: and that 
costs them money.


Of course the fun with "cloud" and "hyperscalers" is that they have so many 
swaths of address space that they become unblockable, especially when the 
address space gets shared by many other inhabitants.

One sees that also with gmail/outlook/SES where much of the spam comes from: 
many customers, thus 1% spam is suddenly a lot.


Regards,
 Jeroen

-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to