> On 3 Aug 2026, at 15:10, Suresh Ramasubramanian <[email protected]> wrote: > > Rather than hand IP space out to bad actors like candy with minimal to no > verification and then have no alternative but to null route it locally, use > DROP or whatever, it’d be so much better if the allocation was not made at > all by the “not the internet police”.
Full agree, that would definitely be a great goal, if that could be achieved. But checking many LIR details with fun addresses in Panama or the Seychelles and other such constructs but claiming to then operate elsewhere, and being uncontactable.... well, apparently answering to the RIR but the bad stuff keeps on flowing... let alone WHOIS entry details being pertinently false... And then, with the current situation around the world, there are countries where it might be hard to actually do a legit business setup, if one wanted to start out. Thus yes, maybe "LIR scoring" might be an approach that is needed. But abuse reports go to /dev/zero with most large corporations/hyperscalers/clouds for whom spam is a <1% of their traffic thing and where DDoS does not get noticed as it is only a tiny bit of their total volume. As such, abuse reports is not likely to scale in making such a rating happen. And as noted, setting up a new LIR with a new company is very easy depending on the locality that it happens, and often completely anonymous and more importantly, not verifable by a RIR (and noting RIR, not just RIPE NCC, as it is a global issue and RIPE NCC gets LIR requests from "companies" in the countries above for instance...). The concept of RIR though was to make it easier to verify per region, as they should have proper contacts with authorities and to And no, NIR does not work either, as we can see with Indonesia where their RPKI systems are effectively offline and who as a NIR are effectively unreachable too. And letting APNIC cut off a whole country is also something, when in that case the ISPs are only harmed by non-service). Or heck, AFRINIC with their problems... The question is then of course 'who gets to claim a LIR/ISP/country/etc' is bad. Especially as that is regarding international laws, and international situations. The Internet is supposed to be open and welcoming to new players (who already lose out with IPv4 availability). More rules/verifications will restrict bad folks getting new footing, but if properly funded (and as long as they make money they will be) will find a way. New smaller entrants who want to do something 'good' (definition depends on which side one is on... are the almost not-existing Sith gone because others wiped them out?) > Right now a common argument is “IPv4 is done with, IPv6 has so much space, > even if bad actors corner large chunks of it, there’s still unlimited space > left”. > > We will probably, with 20/20 hindsight, realize that this argument will go > the way of that apocryphal Bill Gates quote about 640k should be enough for > anybody. 2000::/3 will then be considered 'rotten'. Somebody will use one of the other /3s to start allocating from. That was also the argument for "we can give everybody a /32" which is now turning into "you get a /29 and you get a /29" ..... But there are indeed quite a few of those to burn through, the block lists just might get very very long. Fortunately we are routing 128-bits space in /48 chunks with 32-bits numbers thus there is kinda a limit. Regards, Jeroen (and noting all this to Suresh of all who has been on the battlefield of all this for longer than most have had internet access in the first place....) ----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
