My point has never been “we must use email only”, but “let’s make sure that we 
all use the same protocol” and nobody needs to develop something for each 
possible operator where abuse is taking place. I think XARF can do it, other 
ways are feasible, but the point is to ensure that if you get a report and 
ignore it, you’re accountable for it.


> El 30 jul 2026, a las 13:09, Michele Neylon - Blacknight 
> <[email protected]> escribió:
> 
> Not all alleged abuse can or should be treated the same way and if you want 
> companies to deal with it properly you need to facilitate them handling it 
> using the appropriate tools. Email is often not the best tool for handling 
> reports. 
> 
> 
> 
> --
> Mr Michele Neylon
> Blacknight Solutions
> Hosting, Colocation & Domains
> https://www.blacknight.com/
> https://blacknight.blog/
> Intl. +353 (0) 59  9183072 <tel:+353599183072>
> Direct Dial: +353 (0)59 9183090 <tel:+353599183090>
> Personal blog: https://michele.blog/
> Some thoughts: https://ceo.hosting/
> -------------------------------
> Blacknight Internet Solutions Ltd, Unit 12A,Barrowside Business Park,Sleaty 
> Road,Graiguecullen,Carlow,R93 X265,Ireland  Company No.: 370845
> I have sent this email at a time that is convenient for me. I do not expect 
> you to respond to it outside of your usual working hours.
> From: jordi.palet--- via Security-wg <[email protected]>
> Date: Thursday, 30 July 2026 at 12:06
> To: [email protected] <[email protected]>
> Subject: [Security-wg] Re: Abuse mailboxes are increasingly no longer 
> monitored and are being replaced by (bad) forms
> 
> [EXTERNAL EMAIL] Please use caution when opening attachments from 
> unrecognised sources.
> 
> We have been in this discussion several times.
> 
> The fact that a stronger abuse-c policy reached consensus and has been 
> implemented in APNIC and LACNIC (also in AFRINIC, but due to the situation 
> there not yet implemented), disallowing forms and enforcing a proper abuse 
> email validation, and that since they were implemented, spam and other abuses 
> have been going down constantly in those regions, shall mean something.
> 
> As I clearly suggested in my last versions of the proposal in RIPE 
> (https://www.ripe.net/community/policies/proposals/2019-04/), it will be fine 
> enforcing something like XARF for the reporting as it is also well supported 
> in open source tools for automatic reporting. Allowing forms, that are 
> different in each possible operator in the world is ridiculous, as it 
> enforces each other operator to develop their own tools for each reporting. 
> It is a clear way to be blind and allow criminals to stay in networks 
> forever, so in other ways, allows cooperating with criminals without any 
> responsibility. I guess we prefer regulators, sooner or later to impose their 
> own rules, instead of the community to openly discuss what is best for the 
> community itself.
> 
> Regards,
> Jordi
> 
> @jordipalet
> 
> El 30 jul 2026, a las 12:53, Suresh Ramasubramanian <[email protected]> 
> escribió:
> 
> Do note that criminals may NOT pay with a stolen card at all, if they are 
> convinced that they have a long and comfortable stay at a particular provider 
> who will be lax with abuse reports, but will understandably act quite fast 
> against them if they pay with stolen cards.
> 
> From: Jeroen Massar via Security-wg <[email protected]>
> Date: Thursday, 30 July 2026 at 2:15 PM
> To: Serge Droz <[email protected]>
> Cc: [email protected] <[email protected]>
> Subject: [Security-wg] Re: Abuse mailboxes are increasingly no longer 
> monitored and are being replaced by (bad) forms
> 
> 
> > On 30 Jul 2026, at 09:15, Serge Droz via Security-wg <[email protected]> 
> > wrote:
> >
> > I agree with all of you, we need to penalise orgs that don't act, small 
> > ones, but also the hyper scalars, which admittedly have a scale problem. 
> > But externalising these costs is not ok.
> 
> Especially the Hyper scalers, as they also make hyper money and have the 
> expertise and money to fix those issues.
> They just do not have a reason to as nobody's KPI are hit with that and 
> losing customers = losing money, even if those customers are not the best for 
> the Internet.
> 
> With setups like "APIs for LLMs to automatically setup domains/etc" that even 
> becomes worse as their 'customers' can just rotate through new accounts. "we 
> shut them down when we see, after we took the money from the stolen credit 
> card"... too big to fail...
> 
> 
> As I just wrote to NANOG (before I noticed this thread, while I mentioned 
> also about unmonitored abuse): 
> https://lists.nanog.org/archives/list/[email protected]/thread/XOZXIJCX6PPMXXO7MHWFOMQDMDMHIXK2/
> 
> We have for years (decades actually) had CIDR Reports send to NOG lists, but 
> no action are being taken about known unallocated and reserved prefixes and 
> ASNs and those that pass it on. And that is a very low hanging fruit.
> 
> One can grab those delegated files and verify them against your own BGP 
> tables and alert and reach out (not even asking to directly drop, though 
> would not be bad :) ) -- misconfigs/accidents happen, we should try to 
> minimize that.
> 
> Even likely "national interest" ones like DoD prefixes/ASNs are in there, but 
> also from so called big tech CDNs that are supposedly fighting the bad stuff 
> on the Internet with DDoS protection (and apparently also host the 
> booter/stresser services that cause that).
> 
> 
> At one point governments likely will want to regulate that like the banking 
> industry (not that that helps in the current political climate).
> 
> KYC (Know Your Customer) is a concept there, but for the Internet that is 
> apparently completely lost as long is money to be made.... and we have the 
> stats, and the logs and all the information, just cannot cannot find the 
> contact for the other party to resolve it, and if one has a contact it often 
> is a black hole with no action.
> 
> > I'd fully support Denis' proposal, but aas Suresh says, we're really good 
> > here at not doing anything.
> 
> Same.
> 
> I wish the world was a bit better with it all, but it is unlikely to change 
> as long as money keeps flowing into pockets of the folks doing so.
> 
> Regards,
>  Jeroen
> 
> 
> -----
> To unsubscribe from this mailing list or change your subscription options, 
> please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
> As we have migrated to Mailman 3, you will need to create an account with the 
> email matching your subscription before you can change your settings.
> More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
> -----
> To unsubscribe from this mailing list or change your subscription options, 
> please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
> As we have migrated to Mailman 3, you will need to create an account with the 
> email matching your subscription before you can change your settings.
> More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
> 
> 
> **********************************************
> IPv4 is over
> Are you ready for the new Internet ?
> http://www.theipv6company.com
> The IPv6 Company
> 
> This electronic message contains information which may be privileged or 
> confidential. The information is intended to be for the exclusive use of the 
> individual(s) named above and further non-explicilty authorized disclosure, 
> copying, distribution or use of the contents of this information, even if 
> partially, including attached files, is strictly prohibited and will be 
> considered a criminal offense. If you are not the intended recipient be aware 
> that any disclosure, copying, distribution or use of the contents of this 
> information, even if partially, including attached files, is strictly 
> prohibited, will be considered a criminal offense, so you must reply to the 
> original sender to inform about this communication and delete it.
> 



**********************************************
IPv4 is over
Are you ready for the new Internet ?
http://www.theipv6company.com
The IPv6 Company

This electronic message contains information which may be privileged or 
confidential. The information is intended to be for the exclusive use of the 
individual(s) named above and further non-explicilty authorized disclosure, 
copying, distribution or use of the contents of this information, even if 
partially, including attached files, is strictly prohibited and will be 
considered a criminal offense. If you are not the intended recipient be aware 
that any disclosure, copying, distribution or use of the contents of this 
information, even if partially, including attached files, is strictly 
prohibited, will be considered a criminal offense, so you must reply to the 
original sender to inform about this communication and delete it.

-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to