Serge Droz via Security-wg wrote on 31/07/2026 16:36:
But he is right
every time we start this, the same people fine a gazzilion reasons not
to do anything.
Serge,
the various proposals which have been put forward over the years haven't
failed because "the same people fine a gazzilion reasons not to do
anything". They've failed because the proposals were unworkable, or
would cause harm in other areas, or were not going to fix the problem at
hand, or a combination of all three.
Rather than venting at people, it would be more productive to deal with
the issues that have been brought up, of which there's no shortage - and
in all honesty many of them are really serious and fundamental
structural problems.
For example, how would the RIPE NCC deal with the sort of liability
issues that would come up if they deregistered an organisation's address
space because a downstream last-mile provider had customers whose TVs
and IOT devices were persistently partaking in botnets and were being
used to execute criminal damage against someone else? What legal basis
would the RIPE NCC have for doing this in the Netherlands vs the UK vs
Russia vs Saudi Arabia? What splash damage would happen? What would the
RIPE NCC's obligations and policies be in terms of deciding whether some
form of networking abuse was serious enough to merit deregistration?
Would these be legally sound in all of the jurisdictions where the RIPE
NCC operates. If they were brought to court, how would the RIPE NCC
tell a judge that their behaviour would be justified within a particular
legal system, and that it wasn't anti-competitive behaviour from a
monopoly provider (i.e. criminal behaviour in many jurisdictions). How
does the RIPE NCC handle legal differences? e.g. someone in one
jurisdiction does something which is entirely legal in one, but a very
serious crime in another? Think: blasphemy (capital punishment in
several RIPE NCC service area countries, but absolutely acceptable in
plenty of others), pornography (e.g.with age of consent differences in
different jurisdictions), etc. How does the RIPE NCC handle resist
scope creep? You've created a mechanism for enforcing policy, so how do
you stop that from being used by people pushing for their own interests?
How should the RIPE NCC react, for example, if someone's religious
organisation were to start covertly pushing the edge on abuse to cover
things that they would consider abuse, but which were specific to their
religion? Or same for political?
It's unhelpful to repeatedly dismiss those who disagree with you as
nay-sayers or that the problem is that people won't get out of their
"comfort zone". What's needed is to actually deal with the substance of
the concerns that are brought up, i.e. create cogent, legally sound and
workable proposals for dealing with these and the other problems which
have been raised over the years.
Nick
-----
To unsubscribe from this mailing list or change your subscription options,
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the
email matching your subscription before you can change your settings.
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/