Suresh Ramasubramanian wrote on 31/07/2026 13:55:
Never mind. A government person I know told me, back in the 2000s when
much the same arguments were going on, that if a national government
felt forced to step in to fix this situation, neither they nor the
community would like the results. It will be interesting when it
actually happens.
I don't doubt they said that. And we can all agree that there are
serious problems with online resource misuse and abuse; the issue is
what do to about it, and who needs to be responsible for the "doing" bit
of it.
The issue we have in the RIPE security wg, and before that, abuse-wg and
anti-spam-wg, is that the solutions being proposed involves changing the
nature of the RIPE NCC from a registry into an quasi-judicial and
enforcement body. Essentially the arguments are of the form which could
waspily be described as "politicians' logic":
https://youtu.be/trw1PbQt_Yo
"Something must be done; this is something; therefore we must do this."
In other words, registration of addresses is seen by some people as
leverage with which to force compliance into a particular set of rules.
If you don't comply with the rules of the registration organisation,
your resources are withdrawn and the problem is dealt with that way.
Well sorry but there is such a thing called reality which is applicable
to the RIPE NCC and the RIPE Community, which as I understand it, falls
roughly down the following lines:
- lack of legal competence: the RIPE NCC doesn't have the authority to
determine what is or isn't abuse or illegality because of its nature as
a number resource registry
- lack of jurisdiction: the RIPE NCC provides registration services in,
what, seventy-something countries, and it has no basis to start acting
as some supranational quasi-judicial body in any of these countries.
- lack of authority: there are no laws which give the RIPE NCC any of
these powers.
- insufficiency of contract law: Contract law is not an adequate legal
framework for handling any of this, and in particular contract law is
governed by concepts like liability and proportionality. So if a RIR
were to decide to mete out punitive measures like withdrawal of number
resources on the basis of alleged downstream misuse of resources, it may
open itself up to loss liability. Or let's say a LIR had a downstream
customer whose network resources were being abused for sending spam, and
the RIPE NCC chopped their services on that basis. What does the judge
say? "Wait, you did what? You put the company out of business and
caused serious business service loss to all their customers because they
had a single incompetent customer two contracts down the line?"
- generally not going to solve the problem: we've had fast flux abuse
for 25 years. Number resource withdrawal is a slow process.
- inappropriateness of the remedy for the problem at hand: the threat of
withdrawal of numbering resources is inappropriate to deal with online
abuse threats. In the situations where it might be possible to make some
form of a case, the egregious nature of the infringing actions would be
so severe that criminal law would probably be applicable anyway.
No doubt there are other things missing from this list, and I'm sure an
actual lawyer would be able to give you more - and better - reasons as
to why threatening resource withdrawal is not an appropriate solution to
the problem at hand.
The point is that the RIPE NCC is not a hammer, and not everything is a
nail. The problem of online abuse needs a bit better than what
security-wg is proposing in this situation, and it may well be that any
solution is outside, and possibly very far outside, the security-wg's
remit to address.
Nick
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/