Thank you Jon, Terry, and Aftab for your replies — this is exactly the
conversation I hope the community can have.
On "unlawful/illegal" as a defining concept (re: Jon, Terry)
We intended to remove "unlawful" from the list of examples in the last revision
and missed a reference — apologies for the confusion. We'll issue an amendment
(v2) to correct this.
To be explicit: we don't think "illegal" is a good word to use here either, for
the same underlying reasons — both terms tie the definition to national law,
which varies by jurisdiction and creates exactly the ambiguity Jon and Terry
raised. We recognize the concerns about using either term as a defining
concept. We included "unlawful" originally because it reflects how many
existing abuse mitigation frameworks already operate in practice — for example,
the concept was introduced into this space by civil society, including the
Manila Principles (https://manilaprinciples.org/) — not because we think it's
the ideal formulation for this policy. We're genuinely open to the community
proposing an alternative term or structure that avoids this dependency on
national legal status altogether.
One related point worth surfacing for discussion: a number of jurisdictions
already impose content-removal obligations directly on hosting providers, and
some are extending this toward CDNs (e.g. Italy). Australia, India, Indonesia,
China, and Japan all have relevant regulations in this space. This is already
placing more than a technical or operational burden on parts of our community,
independent of anything this policy does. Terry's broader scope-creep concern
is worth keeping in mind here too — if the community doesn't converge on its
own definition, national regulatory definitions may end up filling that vacuum
by default.
@Jon, noted your suggestion about "to conduct or facilitate activity that
causes, attempts to cause, or creates a material risk of technical harm." May
i suggest some modification: "Internet Abuse through IP Addresses" means the
use of an IP address, or set of IP addresses, registered to or held by an APNIC
account holder, to conduct or facilitate activity that causes, attempts to
cause, or creates a material risk of technical harm to the security, stability,
or trust of the Internet.
With that change, the security/stability/trust clause alone should already
capture our listed examples (malware, DDoS, BGP hijacking, phishing, fraud)
without needing the separate "facilitating unlawful conduct" sentence at all —
since "trust" covers the kind of harm phishing and fraud actually cause. That
would let us drop "unlawful" from the operative definition entirely, which
addresses Jon and Terry's concern directly, while jurisdiction-dependent
conduct (like the gambling example Aftab raised) stays where it already sits —
in the "Note for further discussion" section, left for later community
discussion rather than folded into this definition.
I think a possible next step for the community is to define the different types
of resource holders and their respective responsibilities — a resource holder
using IP space for CDN should reasonably take different action than a hosting
service provider. I think this is best done as a community-led "best practice"
guideline rather than a policy. If those guidelines prove useful, we'd then
have a basis for consensus to formalize them into policy later.
On enforcement authority and cross-jurisdiction adjudication (re: Aftab)
Enforcement mechanics are out of scope for this proposal, but since it's
directly relevant to how the definition would be used, I'll offer my own view
so the community knows where I stand.
I don't support giving APNIC or any Internet organization the authority to
determine whether a particular case is or isn't abuse. That would concentrate
too much power and too broad an authority in an organization that isn't set up
to adjudicate it. The model we're aiming for is: the resource holder acts in
good faith, using the definition as a clearer basis for their own
decision-making, and APNIC's role is limited to ensuring no one abuses their
stewardship responsibility — for example, by ignoring legitimate abuse reports
in bad faith.
This is also where the cross-jurisdiction question Aftab raised (using the
illegal gambling example) fits: when a resource holder considers whether
content like illegal gambling is abusive, my ideal position is that they're
encouraged — as a matter of best practice, not mandatory policy — to weigh both
the jurisdiction where the activity is hosted and the jurisdiction of the
target audience. But the final decision should rest with the resource holder,
not with APNIC. This leaves an open item for subsequent discussion: whether
APNIC should convene a working group to develop best-practice guidance for the
community on this.
I'd also note that the proposal includes a concept of indemnity or immunity
from liability, at least within APNIC policy. The design intent is that if a
resource holder acted in good faith and was responsive, they should not be held
liable to APNIC — even in a case where they ultimately disagreed with the abuse
report. This does not override any national law that may hold the resource
holder liable; it's an additional protection under APNIC policy, layered on top
of — not replacing — whatever exposure or protection already exists at the
national level.
I'd acknowledge this leaves some enforcement questions unresolved — the aim
isn't to solve every abuse case, but to establish a clearer foundation the
community can keep refining in subsequent PDPs. There are relevant concepts
from other Internet governance communities that address adjudication without
giving that power to a central body: the ICANN community's Trusted Notifier
concept, the EU's Trusted Flagger concept, and the Domain Trust project led by
the Global Cyber Alliance to establish baseline best practice. These operate at
the content layer rather than the numbers layer, so the analogy isn't perfect —
but the underlying model of bottom-up, distributed adjudication rather than
centralized authority is the piece I think is transferable here. My current
position is that these practical adjudication issues are best addressed not at
the policy level, but bottom-up, through various forms of cooperation.
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]