Serge Droz via Security-wg wrote on 04/08/2026 13:30:
Nick: I'd appreciate if you could contribute more than just reasons for
why something doesn't work. Or is, what you are saying, that LACNIC and
APNIC just don't get it. I will now stop answering to your objections,
since this is not constructive.
Serge,
I replied to a suggestion that you made, and if I understand it
correctly, what LACNIC and APNIC are doing is substantially different to
what you were suggesting in your email.
Possibly this is one of the problems with this (recurrent) conversation
- different people are talking across each other about different
potential solutions to different problems in the same email thread.
Specifically what you suggested in your last email is fairly
fine-grained. Spam and residential proxies are a huge problem and a
noticeable percentage of subscriber accounts host compromised equipment
- TVs, fridges, IOT, malware-ridden POS units, laptops, etc. If your
proposal is effectively for individual subscriber-level stuff to be
handled by or escalated in some way another to the RIPE NCC, there's a
huge scaling problem right there. The RIPE NCC doesn't have the scope or
scale to become a clearinghouse for abuse complaints at that level of
granularity.
At the point that an organisation was so substantially involved with
online abuse that complete resource withdrawal could be considered
justified by some measure, then I'd be thinking that that would be
already well within the jurisdiction of civil authorities to handle.
Also, the RIPE NCC isn't set up to make judgement calls about this sort
of thing.
If you're talking about general abuse management, then the suggestion of
deregistration of resources is a pretty severe sanction. Put simply,
it's the sort of thing that could kill a business, and given the RIPE
NCC's position as a regional monopoly of registration services, they
would need to be pretty careful about applying this sort of sanction to
their members. Threatening to do something which would kill a business
is the sort of thing that's going to be legally unworkable unless it
falls into either breach of boilerplate contract terms (e.g. failure of
members to pay bills, bankruptcy, etc, i.e. stuff which is routine and
well-established in law) or stuff which was immediately identifiable as
critical to the continuity of the RIPE NCC's core mandate, which is to
ensure the correct registration of resources, e.g. continued failure of
ARC audits. These things are already in the standard service agreement.
Overall, the remedies being proposed are too slow and too coarse-grained
to deal with how resources are abused in real life, and too severe to
deal with anything other than systematically intentional abuse, in which
case it's by definition a legal problem for someone else to handle anyway.
You're right to ask for constructive ideas, but I genuinely don't see
any which involve the RIPE NCC that aren't fraught with serious and in
many cases, existential problems. Maybe the way to deal with this would
be to put a formal proposal together, as something that can be
discussed? Right now, there's nothing concrete to discuss.
Nick
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/