On 31 Jul 2026, at 16:24, Suresh Ramasubramanian
<[email protected]> wrote:
*[EXTERNAL EMAIL]* Please use caution when opening attachments from
unrecognised sources.
Oh well. It’d be interesting if the security / trust and safety etc
teams of various providers started attending ripe and other rir
conferences a lot more regularly. Might even end up modifying this
comfortable status quo consensus.
Short of that, not much here that’ll prevent déjà vu that has lasted
since the 20+ years I’ve seen these various iterations of this wg.
--srs
------------------------------------------------------------------------
*From:* Michele Neylon - Blacknight <[email protected]>
*Sent:* Friday, 31 July 2026 19:42:59
*To:* Nick Hilliard <[email protected]>
*Cc:* Suresh Ramasubramanian <[email protected]>; denis walker
<[email protected]>; [email protected] <[email protected]>
*Subject:* Re: [Security-wg] Re: Abuse mailboxes are increasingly no
longer monitored and are being replaced by (bad) forms
Nick
Thanks
I think you captured very well a lot of the concerns I had with what
was being suggested.
Michele
Mr Michele Neylon
Blacknight Hosting & Domains
https://www.blacknight.com
@mneylon
Sent from mobile so typos and brevity are normal
> On 31 Jul 2026, at 15:41, Nick Hilliard <[email protected]> wrote:
>
> [EXTERNAL EMAIL] Please use caution when opening attachments from
unrecognised sources.
>
> Suresh Ramasubramanian wrote on 31/07/2026 13:55:
>> Never mind. A government person I know told me, back in the 2000s
when
>> much the same arguments were going on, that if a national government
>> felt forced to step in to fix this situation, neither they nor the
>> community would like the results. It will be interesting when it
>> actually happens.
>
> I don't doubt they said that. And we can all agree that there are
> serious problems with online resource misuse and abuse; the issue is
> what do to about it, and who needs to be responsible for the
"doing" bit
> of it.
>
> The issue we have in the RIPE security wg, and before that,
abuse-wg and
> anti-spam-wg, is that the solutions being proposed involves
changing the
> nature of the RIPE NCC from a registry into an quasi-judicial and
> enforcement body. Essentially the arguments are of the form which could
> waspily be described as "politicians' logic":
>
> https://youtu.be/trw1PbQt_Yo
>
> "Something must be done; this is something; therefore we must do this."
>
> In other words, registration of addresses is seen by some people as
> leverage with which to force compliance into a particular set of rules.
> If you don't comply with the rules of the registration organisation,
> your resources are withdrawn and the problem is dealt with that way.
>
> Well sorry but there is such a thing called reality which is applicable
> to the RIPE NCC and the RIPE Community, which as I understand it, falls
> roughly down the following lines:
>
> - lack of legal competence: the RIPE NCC doesn't have the authority to
> determine what is or isn't abuse or illegality because of its nature as
> a number resource registry
>
> - lack of jurisdiction: the RIPE NCC provides registration services in,
> what, seventy-something countries, and it has no basis to start acting
> as some supranational quasi-judicial body in any of these countries.
>
> - lack of authority: there are no laws which give the RIPE NCC any of
> these powers.
>
> - insufficiency of contract law: Contract law is not an adequate legal
> framework for handling any of this, and in particular contract law is
> governed by concepts like liability and proportionality. So if a RIR
> were to decide to mete out punitive measures like withdrawal of number
> resources on the basis of alleged downstream misuse of resources,
it may
> open itself up to loss liability. Or let's say a LIR had a downstream
> customer whose network resources were being abused for sending
spam, and
> the RIPE NCC chopped their services on that basis. What does the judge
> say? "Wait, you did what? You put the company out of business and
> caused serious business service loss to all their customers because
they
> had a single incompetent customer two contracts down the line?"
>
> - generally not going to solve the problem: we've had fast flux abuse
> for 25 years. Number resource withdrawal is a slow process.
>
> - inappropriateness of the remedy for the problem at hand: the
threat of
> withdrawal of numbering resources is inappropriate to deal with online
> abuse threats. In the situations where it might be possible to make
some
> form of a case, the egregious nature of the infringing actions would be
> so severe that criminal law would probably be applicable anyway.
>
> No doubt there are other things missing from this list, and I'm sure an
> actual lawyer would be able to give you more - and better - reasons as
> to why threatening resource withdrawal is not an appropriate
solution to
> the problem at hand.
>
> The point is that the RIPE NCC is not a hammer, and not everything is a
> nail. The problem of online abuse needs a bit better than what
> security-wg is proposing in this situation, and it may well be that any
> solution is outside, and possibly very far outside, the security-wg's
> remit to address.
>
> Nick
> -----
> To unsubscribe from this mailing list or change your subscription
options, please visit:
https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
> As we have migrated to Mailman 3, you will need to create an
account with the email matching your subscription before you can
change your settings.
> More details at:
https://www.ripe.net/membership/mail/mailman-3-migration/