Dave:

> As of 17 Aug, 2026, 2,359 out of a total of 10,815 active APNIC accounts
(21.8%) had no validated IRT emails associated with their resources. APNIC
marks IRT emails as invalid 15 days after sending the validation request
and restricts MyAPNIC access if the validation is not completed in 30 days.

A better number might be: Of those accounts with not-validated IRT emails
as on 17-June (60 days prior), how many were still not validated on
17-August.

It is feasible (though unlikely) that all the 21.8% on 17-Aug quickly
validated on 18-Aug, which would mean the existing process works, and quite
well.

-- 
Sanjeev Gupta
+65 98551208   http://sg.linkedin.com/in/ghane


On Wed, Aug 26, 2026 at 5:50 PM Dave Phelan <[email protected]> wrote:

> Dear SIG Members,
>
> Please find below the Secretariat impact assessment for prop-172-v001: 
> Defining
> Internet Abuse through IP Addresses
>
>
>
> Dave Phelan
>
> Policy Manager and Senior Network Analyst
>
> --------
> 1. APNIC’s Understanding of the Proposed Policy
>
> APNIC understands this proposal as introducing a formal definition of
> ‘Internet Abuse through IP Addresses’ into APNIC policy.
>
> The proposal states that it does not create new enforcement powers,
> reporting requirements, or compliance mechanisms. However, the text also
> says APNIC retains responsibility for holding resource holders accountable
> for responding to and addressing abuse.
>
> APNIC Secretariat have noted that this overlaps with the current IRT
> policy, which already requires IRT contacts to be maintained and validated.
> 2. Impact of Proposed Policy on Registry and Addressing System
>
> No direct registry impact expected
> 3. Impact of Proposed Policy on APNIC Operation/Services
>
> APNIC Secretariat notes that the main issue is ambiguity about APNIC’s
> role.
> The proposal says APNIC does not have the power to adjudicate abuse, but
> also says APNIC retains responsibility for holding resource holders
> accountable for responding to and addressing abuse. It is unclear how both
> can be true without creatingn some form of operational enforcement role.
> APNIC is not currently resourced to perform this work, and the associated
> cost may not be something the membership would expect or support.
>
> As of 17 Aug, 2026, 2,359 out of a total of 10,815 active APNIC accounts
> (21.8%) had no validated IRT emails associated with their resources. APNIC
> marks IRT emails as invalid 15 days after sending the validation request
> and restricts MyAPNIC access if the validation is not completed in 30 days.
> This figure does not take into account those that will validate within the
> 30 day window, it is a point-in-time reference.
> 4. Legal Impact of Policy
>
> The proposal would define "Internet Abuse through IP Addresses" as the use
> of IP addresses in a way that causes technical harm to the security,
> stability, or trust of the Internet. It would also include facilitating
> unlawful conduct that the resource holder has the practical ability to
> address.
>
>  Although presented as a definition, the proposal also discusses
> responsibilities, how abuse is determined, and circumstances where a
> resource holder may be protected from further action. These elements appear
> to go beyond a simple definition and could be interpreted as introducing
> broader operational expectations. A number of legal and implementation
> issues may arise if the proposal is adopted.
>
>  The reference to "unlawful conduct" creates uncertainty because APNIC
> serves account holders operating across many different jurisdictions.
> Conduct that is unlawful in one jurisdiction may be lawful in another. In
> some cases, conduct that is unlawful in one jurisdiction may even be
> required by law in another. Resource holders may also be based in, and
> operate across multiple jurisdictions, so the legality of behaviour may
> differ between those different locations.
>
>  The proposal states that APNIC does not have the power to adjudicate
> abuse. However, it also states that APNIC has an existing responsibility to
> hold resource holders accountable for responding to and addressing abuse.
> We do not consider this to be an accurate reflection of current policy.
> Section 5.3.3 of the APNIC Internet Number Resource Policies requires
> resource holders to maintain responsive IRT contacts and requires APNIC to
> validate those contacts. It does not require APNIC to investigate alleged
> abuse, determine whether abuse has occurred, or assess whether a resource
> holder's response was adequate.
>
>  There also appears to be some conflict between these two statements.
> Determining whether abuse has been "addressed" would generally require
> first determining whether abuse occurred. This would place APNIC in an
> adjudication role, which the proposal expressly states APNIC does not
> have.  In any case, only a competent authority (e.g. – a court) is capable
> of determining whether conduct is unlawful.
>
>  It is also unclear what is meant by "fraudulently ... sub-allocating IP
> address resources" and how such conduct would occur in practice.
>
>  The policy objective states that the definition is intended to serve as a
> foundation for future policy proposals. While we would not normally comment
> on possible future proposals, it is worth noting that any future policy
> requiring APNIC to assess or enforce whether abuse has been addressed would
> represent a significant expansion of APNIC's current role. Historically,
> APNIC's responsibilities have focused on Internet number resource
> management and related technical matters rather than assessing conduct or
> content. Such a change would likely require additional resources,
> expertise, and risk management measures and should be considered expressly
> in advance of any such change.
>
>  If "unlawful conduct" remains part of the definition, several practical
> questions would remain unresolved. For example, when would a finding of
> unlawfulness be considered sufficiently final? Would all appeals need to be
> exhausted? How would conflicting decisions from different jurisdictions be
> handled? These issues could create substantial administrative complexity
> and may affect APNIC's neutrality.
>
>  The Secretariat notes that implementation may benefit from greater
> clarity about the intended scope of the definition. In particular, it may
> be helpful to confine matters to a technical definition of abuse without
> any operational or enforcement expectations that may arise from it. A
> definition based on established technical standards (such as those from
> IETF) may provide a more objective foundation than concepts based on
> lawfulness, although this would not resolve all implementation issues.
> Terms such as "facilitating", "hosting", "phishing", "fraud", "scam", and
> "impersonation" should also be carefully considered to ensure the
> definition does not unintentionally expand APNIC's role into determining
> questions of unlawful conduct or content.
> *5. Implementation*
>
> Until such point as the above clarifications are made, we are unable to
> make a determination on implementation process and time frames.
> _______________________________________________
> SIG-policy - https://mailman.apnic.net/[email protected]/
> To unsubscribe send an email to [email protected]
_______________________________________________
SIG-policy - https://mailman.apnic.net/[email protected]/
To unsubscribe send an email to [email protected]

Reply via email to