Hi Alban + SIG, This is thoughtful and well written, and I support it in principle. I suggest that "unlawful" as a concept places too much faith in certain legal jurisdictions and would be best left out entirely. (This invites geopolitical issues into a technical process and we do not want that!) Abuse as defined by implementations like what is reported in DASH is going to create an ongoing debate on what constitutes abuse. You are best to define the baseline: what is considered by almost everyone to be undesirable behaviour by an ip address range, and holders thereof. We would definitely want to discourage scope creep here, for instance: would sending BGP routes for your own prefixes having NOT signed ROAs suddenly become abuse? Meanwhile, doing so for prefixes you have not got an allocation or LOA for is abuse. Overall, it also may be better to outline the outcomes and leave the technical processes and definitions to day to day technical problem solvers. Policy can't solve these issues by itself but at least you have highlighted the need for a shared understanding of the problems at the policy level. Good references for a baseline:
https://datatracker.ietf.org/doc/html/rfc4084 https://datatracker.ietf.org/doc/html/rfc4732 https://datatracker.ietf.org/doc/html/rfc4778* https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=cti *I included RFC 4778 here as it becomes a rebuttal for those who feel lack of security is not an invitation for abuse. Regards,Terry
_______________________________________________ SIG-policy - https://mailman.apnic.net/[email protected]/ To unsubscribe send an email to [email protected]
