As someone new to the list I can naturally take the village idiot role, without
the burden of considering the outcomes of past discussions :-)
On 3. Aug 2026, at 14.33, Serge Droz via Security-wg <[email protected]
<mailto:[email protected]>> wrote:
> So here is what I propose. I'm not a lawyer, so maybe this needs to be
> phrased differently. But the idea is
>
> a: Make sure poeple read their abuse e-mails
>
> b: Possibly, take further acction if they read it bud don't act.
>
> a: Abuse mailbox tests:
>
> The RIPE NCC cunducts bi-annual communications checks to the abuse handles.
> It is expected that these are replied to within [X hours/days/...]
>
> If no replies is received this will be escalated through other contacts.
>
> If no reply is received on may as well assume the org no longer exists and
> take appropriate action. LACNIC blocks access.
>
> b: Complaints about missing action
>
It very much sounds like the b) part of this proposal is where the objections
come from, so would it be helpful to just focus on the a) part?
One parallel I’d like to draw is RPKI, where the RIRs have put in place
infrastructure to detect unauthorized route advertisements, but don’t really
mandate specific action operators should take with them. Rather it’s just
information the operators’ own policies can consider.
To me this reads like a) can be implemented essentially the same way. Checks
are added to enforce the already existing requirement of a valid abuse contact;
results of those checks are published in the database.
This creates compliance pressure without any specific threats of further
action. Not processing abuse emails results in a signal that third parties are
free to interpret in a way that might be harmful towards the reputation and
thus value of the number resources that refer to that specific abuse-c.
And I think crucially, this does not require a RIPE policy to argue what the
signal means (like some sort of LIR score would), it’s just there for anyone to
interpret as they wish.
Of course, the counterargument is the one Jeroen just made, that just
responding to emails is not worth much. Sure. But a setup like this would at
least help folks keep their abuse-c working, and I’m sure there are tons of
cases where they’re inoperable not because of malice, but because nobody
thought to make sure they worked.
Marko
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the
email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/