As someone new to the list I can naturally take the village idiot role, without 
the burden of considering the outcomes of past discussions :-)

On 3. Aug 2026, at 14.33, Serge Droz via Security-wg <[email protected] 
<mailto:[email protected]>> wrote:
> So here is what I propose. I'm not a lawyer, so maybe this needs to be 
> phrased differently. But the idea is  
> 
> a: Make sure poeple read their abuse e-mails 
> 
> b: Possibly, take further acction if they read it bud don't act. 
> 
> a: Abuse mailbox tests:
> 
> The RIPE NCC cunducts bi-annual communications checks to the abuse handles. 
> It is expected that these are replied to within [X hours/days/...]
> 
> If no replies is received this will be escalated through other contacts.  
> 
> If no reply is received on may as well assume the org no longer exists and 
> take appropriate action. LACNIC blocks access. 
> 
> b: Complaints about missing action
> 

It very much sounds like the b) part of this proposal is where the objections 
come from, so would it be helpful to just focus on the a) part?

One parallel I’d like to draw is RPKI, where the RIRs have put in place 
infrastructure to detect unauthorized route advertisements, but don’t really 
mandate specific action operators should take with them. Rather it’s just 
information the operators’ own policies can consider.

To me this reads like a) can be implemented essentially the same way. Checks 
are added to enforce the already existing requirement of a valid abuse contact; 
results of those checks are published in the database.

This creates compliance pressure without any specific threats of further 
action. Not processing abuse emails results in a signal that third parties are 
free to interpret in a way that might be harmful towards the reputation and 
thus value of the number resources that refer to that specific abuse-c.

And I think crucially, this does not require a RIPE policy to argue what the 
signal means (like some sort of LIR score would), it’s just there for anyone to 
interpret as they wish.

Of course, the counterargument is the one Jeroen just made, that just 
responding to emails is not worth much. Sure. But a setup like this would at 
least help folks keep their abuse-c working, and I’m sure there are tons of 
cases where they’re inoperable not because of malice, but because nobody 
thought to make sure they worked.

Marko
-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to