But he is right

every time we start this, the same people fine a gazzilion reasons not to do anything.

There is no perfect solution, and if we never try nothing is going to happen. The Status Qua is acceptable to the Nay Sayers, because they externalize the costs to victims.

Best
Serge

On 31/07/2026 17:30, Michele Neylon - Blacknight via Security-wg wrote:
Suresh
I’d like to see changes for sure but the reductionist arguments being proposed by some people on this list aren’t helpful.
Michele

Mr Michele Neylon
Blacknight Hosting & Domains
https://www.blacknight.com
@mneylon
Sent from mobile so typos and brevity are normal

On 31 Jul 2026, at 16:24, Suresh Ramasubramanian <[email protected]> wrote:



*[EXTERNAL EMAIL]* Please use caution when opening attachments from unrecognised sources.

Oh well. It’d be interesting if the security / trust and safety etc teams of various providers started attending ripe and other rir conferences a lot more regularly. Might even end up modifying this comfortable status quo consensus.

Short of that, not much here that’ll prevent déjà vu that has lasted since the 20+ years I’ve seen these various iterations of this wg.

--srs
------------------------------------------------------------------------
*From:* Michele Neylon - Blacknight <[email protected]>
*Sent:* Friday, 31 July 2026 19:42:59
*To:* Nick Hilliard <[email protected]>
*Cc:* Suresh Ramasubramanian <[email protected]>; denis walker <[email protected]>; [email protected] <[email protected]> *Subject:* Re: [Security-wg] Re: Abuse mailboxes are increasingly no longer monitored and are being replaced by (bad) forms
Nick
Thanks
I think you captured very well a lot of the concerns I had with what was being suggested.

Michele

Mr Michele Neylon
Blacknight Hosting & Domains
https://www.blacknight.com
@mneylon
Sent from mobile so typos and brevity are normal

> On 31 Jul 2026, at 15:41, Nick Hilliard <[email protected]> wrote:
>
> [EXTERNAL EMAIL] Please use caution when opening attachments from unrecognised sources.
>
> Suresh Ramasubramanian wrote on 31/07/2026 13:55:
>> Never mind.  A government person I know told me, back in the 2000s when
>> much the same arguments were going on, that if a national government
>> felt forced to step in to fix this situation, neither they nor the
>> community would like the results.  It will be interesting when it
>> actually happens.
>
> I don't doubt they said that. And we can all agree that there are
> serious problems with online resource misuse and abuse; the issue is
> what do to about it, and who needs to be responsible for the "doing" bit
> of it.
>
> The issue we have in the RIPE security wg, and before that, abuse-wg and > anti-spam-wg, is that the solutions being proposed involves changing the
> nature of the RIPE NCC from a registry into an quasi-judicial and
> enforcement body. Essentially the arguments are of the form which could
> waspily be described as "politicians' logic":
>
> https://youtu.be/trw1PbQt_Yo
>
> "Something must be done; this is something; therefore we must do this."
>
> In other words, registration of addresses is seen by some people as
> leverage with which to force compliance into a particular set of rules.
> If you don't comply with the rules of the registration organisation,
> your resources are withdrawn and the problem is dealt with that way.
>
> Well sorry but there is such a thing called reality which is applicable
> to the RIPE NCC and the RIPE Community, which as I understand it, falls
> roughly down the following lines:
>
> -  lack of legal competence: the RIPE NCC doesn't have the authority to
> determine what is or isn't abuse or illegality because of its nature as
> a number resource registry
>
> - lack of jurisdiction: the RIPE NCC provides registration services in,
> what, seventy-something countries, and it has no basis to start acting
> as some supranational quasi-judicial body in any of these countries.
>
> - lack of authority: there are no laws which give the RIPE NCC any of
> these powers.
>
> - insufficiency of contract law: Contract law is not an adequate legal
> framework for handling any of this, and in particular contract law is
> governed by concepts like liability and proportionality. So if a RIR
> were to decide to mete out punitive measures like withdrawal of number
> resources on the basis of alleged downstream misuse of resources, it may
> open itself up to loss liability. Or let's say a LIR had a downstream
> customer whose network resources were being abused for sending spam, and
> the RIPE NCC chopped their services on that basis. What does the judge
> say?  "Wait, you did what? You put the company out of business and
> caused serious business service loss to all their customers because they
> had a single incompetent customer two contracts down the line?"
>
> - generally not going to solve the problem: we've had fast flux abuse
> for 25 years. Number resource withdrawal is a slow process.
>
> - inappropriateness of the remedy for the problem at hand: the threat of
> withdrawal of numbering resources is inappropriate to deal with online
> abuse threats. In the situations where it might be possible to make some
> form of a case, the egregious nature of the infringing actions would be
> so severe that criminal law would probably be applicable anyway.
>
> No doubt there are other things missing from this list, and I'm sure an
> actual lawyer would be able to give you more - and better - reasons as
> to why threatening resource withdrawal is not an appropriate solution to
> the problem at hand.
>
> The point is that the RIPE NCC is not a hammer, and not everything is a
> nail. The problem of online abuse needs a bit better than what
> security-wg is proposing in this situation, and it may well be that any
> solution is outside, and possibly very far outside, the security-wg's
> remit to address.
>
> Nick
> -----
> To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ > As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. > More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

-----
To unsubscribe from this mailing list or change your subscription options, 
please visit:https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings.
More details at:https://www.ripe.net/membership/mail/mailman-3-migration/
-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to