Thank you Jon, Terry, and Aftab for your replies — this is exactly the 
conversation I hope the community can have.
On "unlawful/illegal" as a defining concept (re: Jon, Terry)
We intended to remove "unlawful" from the list of examples in the last revision 
and missed a reference — apologies for the confusion. We'll issue an amendment 
(v2) to correct this.
To be explicit: we don't think "illegal" is a good word to use here either, for 
the same underlying reasons — both terms tie the definition to national law, 
which varies by jurisdiction and creates exactly the ambiguity Jon and Terry 
raised. We recognize the concerns about using either term as a defining 
concept. We included "unlawful" originally because it reflects how many 
existing abuse mitigation frameworks already operate in practice — for example, 
the concept was introduced into this space by civil society, including the 
Manila Principles (https://manilaprinciples.org/) — not because we think it's 
the ideal formulation for this policy. We're genuinely open to the community 
proposing an alternative term or structure that avoids this dependency on 
national legal status altogether.
One related point worth surfacing for discussion: a number of jurisdictions 
already impose content-removal obligations directly on hosting providers, and 
some are extending this toward CDNs (e.g. Italy). Australia, India, Indonesia, 
China, and Japan all have relevant regulations in this space. This is already 
placing more than a technical or operational burden on parts of our community, 
independent of anything this policy does. Terry's broader scope-creep concern 
is worth keeping in mind here too — if the community doesn't converge on its 
own definition, national regulatory definitions may end up filling that vacuum 
by default.
@Jon, noted your suggestion about "to conduct or facilitate activity that 
causes, attempts to cause, or creates a material risk of technical harm."  May 
i suggest some modification:  "Internet Abuse through IP Addresses" means the 
use of an IP address, or set of IP addresses, registered to or held by an APNIC 
account holder, to conduct or facilitate activity that causes, attempts to 
cause, or creates a material risk of technical harm to the security, stability, 
or trust of the Internet.
With that change, the security/stability/trust clause alone should already 
capture our listed examples (malware, DDoS, BGP hijacking, phishing, fraud) 
without needing the separate "facilitating unlawful conduct" sentence at all — 
since "trust" covers the kind of harm phishing and fraud actually cause. That 
would let us drop "unlawful" from the operative definition entirely, which 
addresses Jon and Terry's concern directly, while jurisdiction-dependent 
conduct (like the gambling example Aftab raised) stays where it already sits — 
in the "Note for further discussion" section, left for later community 
discussion rather than folded into this definition.
I think a possible next step for the community is to define the different types 
of resource holders and their respective responsibilities — a resource holder 
using IP space for CDN should reasonably take different action than a hosting 
service provider. I think this is best done as a community-led "best practice" 
guideline rather than a policy. If those guidelines prove useful, we'd then 
have a basis for consensus to formalize them into policy later.
On enforcement authority and cross-jurisdiction adjudication (re: Aftab)
Enforcement mechanics are out of scope for this proposal, but since it's 
directly relevant to how the definition would be used, I'll offer my own view 
so the community knows where I stand.
I don't support giving APNIC or any Internet organization the authority to 
determine whether a particular case is or isn't abuse. That would concentrate 
too much power and too broad an authority in an organization that isn't set up 
to adjudicate it. The model we're aiming for is: the resource holder acts in 
good faith, using the definition as a clearer basis for their own 
decision-making, and APNIC's role is limited to ensuring no one abuses their 
stewardship responsibility — for example, by ignoring legitimate abuse reports 
in bad faith.
This is also where the cross-jurisdiction question Aftab raised (using the 
illegal gambling example) fits: when a resource holder considers whether 
content like illegal gambling is abusive, my ideal position is that they're 
encouraged — as a matter of best practice, not mandatory policy — to weigh both 
the jurisdiction where the activity is hosted and the jurisdiction of the 
target audience. But the final decision should rest with the resource holder, 
not with APNIC. This leaves an open item for subsequent discussion: whether 
APNIC should convene a working group to develop best-practice guidance for the 
community on this.
I'd also note that the proposal includes a concept of indemnity or immunity 
from liability, at least within APNIC policy. The design intent is that if a 
resource holder acted in good faith and was responsive, they should not be held 
liable to APNIC — even in a case where they ultimately disagreed with the abuse 
report. This does not override any national law that may hold the resource 
holder liable; it's an additional protection under APNIC policy, layered on top 
of — not replacing — whatever exposure or protection already exists at the 
national level.
 
I'd acknowledge this leaves some enforcement questions unresolved — the aim 
isn't to solve every abuse case, but to establish a clearer foundation the 
community can keep refining in subsequent PDPs. There are relevant concepts 
from other Internet governance communities that address adjudication without 
giving that power to a central body: the ICANN community's Trusted Notifier 
concept, the EU's Trusted Flagger concept, and the Domain Trust project led by 
the Global Cyber Alliance to establish baseline best practice. These operate at 
the content layer rather than the numbers layer, so the analogy isn't perfect — 
but the underlying model of bottom-up, distributed adjudication rather than 
centralized authority is the piece I think is transferable here. My current 
position is that these practical adjudication issues are best addressed not at 
the policy level, but bottom-up, through various forms of cooperation.
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to