Providers that are incompetent at abuse management can be handled in one way or the other. The question before the house is the other kind of provider that acquires IP space solely for abusive purposes or, to pick a recent example, for abusive purposes as well as sanctions avoidance.
The activity hosted on such providers tends to eventually get the provider raided by law enforcement and shut down. It’d be very interesting if part of such an investigation spilled into just why such groups or individuals, were given number resources. --srs ________________________________ From: Michael Richardson <[email protected]> Sent: Tuesday, 04 August 2026 20:43:40 To: Nick Hilliard <[email protected]>; [email protected] <[email protected]> Subject: [Security-wg] Re: Abuse mailboxes are increasingly no longer monitored and are being replaced by (bad) forms Nick Hilliard <[email protected]> wrote: > Possibly this is one of the problems with this (recurrent) conversation > - different people are talking across each other about different > potential solutions to different problems in the same email thread. Agreed. > Specifically what you suggested in your last email is fairly > fine-grained. Spam and residential proxies are a huge problem and a > noticeable percentage of subscriber accounts host compromised equipment > - TVs, fridges, IOT, malware-ridden POS units, laptops, etc. If your > proposal is effectively for individual subscriber-level stuff to be > handled by or escalated in some way another to the RIPE NCC, there's a > huge scaling problem right there. The RIPE NCC doesn't have the scope > or scale to become a clearinghouse for abuse complaints at that level > of granularity. A question is: who is that wants to report such things, and to whom? (It's a real question) I think that at least a few ISPs actually operate fake subscriber systems as canaries, and I'm sure it's annoying to them to get reports about them :-) I'm told that there was/is some system where I could dial another NOC using a SIP phone, and their phone number was their ASN. I think that kind of between operator reporting is way way different than random emails from random people. I can see why abuse@ does not get the attention it deserves, as beyond the literal spam problem, are the endless useless/incomplete reports. > If you're talking about general abuse management, then the suggestion > of deregistration of resources is a pretty severe sanction. Agreed. Still: the ol' Usenet penalty was useful. RIPE should limit itself to dealing with unresponsive registrants, and it's the unresponsiveness that is the concern. With many levels of escalation. (At some point: if they are universally unresponsive, they won't pay their bill) > Overall, the remedies being proposed are too slow and too > coarse-grained to deal with how resources are abused in real life, and > too severe to deal with anything other than systematically intentional > abuse, in which case it's by definition a legal problem for someone > else to handle anyway. Agreed. What I would like to see is more cross-training between CERTs at various levels and RIPE, including some process that educates operators to elevate their abilities. I didn't know about XARF before this thread, and I do now, and I wish that it was more used, although I don't understand how that org operates. {I used to get periodic emails from Canada's CSIS/CVE about how my Cisco routers were insecure based upon some very confused scan of BGP ports. They never actually told me what IP they had looked at, and... I had no Cisco equipment. They stopped a few years ago. I wish they hadn't stopped, but rather gotten more clue. They also didn't use abuse@ } -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide ** My working hours and your working hours may be different. ** ** Please do not feel obligated to reply outside your normal working hours **
----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
