> On 3 Aug 2026, at 15:10, Suresh Ramasubramanian <[email protected]> wrote:
> 
> Rather than hand IP space out to bad actors like candy with minimal to no 
> verification and then have no alternative but to null route it locally, use 
> DROP or whatever, it’d be so much better if the allocation was not made at 
> all by the “not the internet police”.

Full agree, that would definitely be a great goal, if that could be achieved.

But checking many LIR details with fun addresses in Panama or the Seychelles 
and other such constructs but claiming to then operate elsewhere, and being 
uncontactable.... well, apparently answering to the RIR but the bad stuff keeps 
on flowing... let alone WHOIS entry details being pertinently false...

And then, with the current situation around the world, there are countries 
where it might be hard to actually do a legit business setup, if one wanted to 
start out.


Thus yes, maybe "LIR scoring" might be an approach that is needed.

But abuse reports go to /dev/zero with most large 
corporations/hyperscalers/clouds for whom spam is a <1% of their traffic thing 
and where DDoS does not get noticed as it is only a tiny bit of their total 
volume.

As such, abuse reports is not likely to scale in making such a rating happen.

And as noted, setting up a new LIR with a new company is very easy depending on 
the locality that it happens, and often completely anonymous and more 
importantly, not verifable by a RIR (and noting RIR, not just RIPE NCC, as it 
is a global issue and RIPE NCC gets LIR requests from "companies" in the 
countries above for instance...).

The concept of RIR though was to make it easier to verify per region, as they 
should have proper contacts with authorities and to 

And no, NIR does not work either, as we can see with Indonesia where their RPKI 
systems are effectively offline and who as a NIR are effectively unreachable 
too. And letting APNIC cut off a whole country is also something, when in that 
case the ISPs are only harmed by non-service). Or heck, AFRINIC with their 
problems...


The question is then of course 'who gets to claim a LIR/ISP/country/etc' is 
bad. Especially as that is regarding international laws, and international 
situations. The Internet is supposed to be open and welcoming to new players 
(who already lose out with IPv4 availability). More rules/verifications will 
restrict bad folks getting new footing, but if properly funded (and as long as 
they make money they will be) will find a way. New smaller entrants who want to 
do something 'good' (definition depends on which side one is on... are the 
almost not-existing Sith gone because others wiped them out?)

> Right now a common argument is “IPv4 is done with, IPv6 has so much space, 
> even if bad actors corner large chunks of it, there’s still unlimited space 
> left”.
> 
> We will probably, with 20/20 hindsight, realize that this argument will go 
> the way of that apocryphal Bill Gates quote about 640k should be enough for 
> anybody.

2000::/3 will then be considered 'rotten'.

Somebody will use one of the other /3s to start allocating from.

That was also the argument for "we can give everybody a /32" which is now 
turning into "you get a /29 and you get a /29" .....

But there are indeed quite a few of those to burn through, the block lists just 
might get very very long. Fortunately we are routing 128-bits space in /48 
chunks with 32-bits numbers thus there is kinda a limit.

Regards,
 Jeroen


(and noting all this to Suresh of all who has been on the battlefield of all 
this for longer than most have had internet access in the first place....)


-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to