Summary
- In 2010, Wendel advanced an ARIN customer-confidentiality proposal that tried to protect ISP customer lists while keeping underlying information available to the registry; a public tally recorded five in favour and seventy against, and the proposal was abandoned.
- In 2024, he joined three other originators of a rewrite of ARIN’s critical-infrastructure micro-allocation rules. The text reached recommended status, was returned to draft after a negative 2025 tally, and was abandoned in February 2026.
- The two outcomes show that operating experience gives a policy participant standing, not sovereignty. Wendel made real costs visible, but precise language, competing public interests and sustained support determined whether those costs became shared rules.
Two counts, two defeats
The first count came in Toronto in April 2010. ARIN had been considering Draft Policy 2010-3, Customer Confidentiality, a proposal controlled through the meeting by Aaron Wendel. The meeting chair eventually returned to a show of hands that had been omitted from the original discussion. Of 133 people counted in the room and remotely, five supported the proposal and seventy opposed it. Eight days later, ARIN’s Advisory Council abandoned the draft.
The second count came in October 2025. A rewrite of ARIN’s rules for IPv4 addresses reserved for critical Internet infrastructure had travelled much further. The proposal had four originators, including Wendel. It had been revised over many months, reviewed by staff and counsel, and promoted to Recommended Draft Policy. At ARIN 56, however, twenty-one participants supported the text as written and twenty-six did not.
The Advisory Council returned the text to draft status. In February 2026, after observing mostly negative support and little further mailing-list engagement, the Council unanimously abandoned it. The official record also preserved the possibility that narrower reforms could return later.
These are not parallel stories in every detail. The 2010 proposal concerned disclosure of ISP customer contact data. The later proposal concerned allocations for exchanges, DNS operators and other critical infrastructure. Wendel was the central petitioner in the first and one of four originators in the second. The process, language and affected interests differed.
What joins the episodes is a more useful leadership question than whether Wendel “won.” Both began with costs visible to network operators but easy for outsiders to discount. Both tried to convert those costs into registry policy. Both met objections from people who accepted parts of the problem but rejected the proposed settlement. In both cases, the institution retained the power to say no.
What the 2010 proposal actually sought
Draft Policy 2010-3 is sometimes easier to criticise than to describe accurately. It did not propose erasing every customer identity from ARIN’s records. Its text would have allowed an ISP to publish the customer’s name together with the ISP’s address and telephone number in reassignment or reallocation records, instead of publishing the customer’s own address and telephone number. The actual customer information would still have to be supplied to ARIN on request and held in confidence.
The proposal’s rationale was openly commercial. It described customer contact lists as proprietary and argued that mandatory publication through SWIP or RWHOIS invited competitors and others to solicit companies and individuals receiving address space from upstream providers. Wendel was not presenting privacy as an abstract civil liberty. He was describing a cost imposed on service providers that had to register downstream use.
That framing matters. A rule can support public accountability while also exposing information useful for private sales. An operator complying with reassignment requirements may see the public database as a map of customers. A competitor may see the same records as leads. An abuse investigator may see them as a way to identify the party responsible for a suspicious address. Law enforcement may see a starting point that avoids delay.
The proposal picked one balance: retain the customer’s name, substitute the provider’s contact details, and require the registry to keep the more complete information available privately. That balance protected part of the public attribution while reducing the exposure of a customer’s direct coordinates. It also moved more of the disclosure decision behind a request process.
The public record does not show that Wendel invented the underlying tension. Operators, security researchers, registry staff and governments had already argued about data accuracy, privacy, marketing misuse and investigative access. His significance was to force a particular remedy into ARIN’s formal policy process and to attach a provider’s business rationale to it.
The abuse-accountability objection
The strongest independent account of the controversy came from security journalist Brian Krebs. His reporting described opposition from anti-spam and security participants who feared that less visible customer contact information would slow work against spam and malicious software. The concern was not simply that investigators preferred more data. It was that public attribution could make a network’s downstream users answerable without first persuading an intermediary to disclose them.
Krebs also quoted Wendel explaining that competitors had harvested contact information and solicited his customers. That statement gave the proposal a concrete operating origin. It was not proof of the scale of the practice, but it clarified the incentive. The party asking for confidentiality was also a party competing for hosting and connectivity customers.
The same report complicated any simple privacy-versus-security morality. Wendel said his company employed a person to handle abuse complaints and disconnected customers responsible for spam complaints. He also acknowledged that inexpensive service could attract abusive operators because the cost of losing a server was lower. Those statements did not prove negligence or complicity. They showed why the provider sat on both sides of the accountability problem.
A hosting provider can be harmed when a public registry becomes a prospecting database. The same provider becomes an enforcement gate when a customer’s details are no longer directly visible. Its abuse desk, response speed and willingness to disconnect determine whether confidentiality protects legitimate customers or gives bad actors time. A policy that reduces public data therefore cannot be judged only by the provider’s privacy cost.
This was the distributional question beneath the text. Competitors might lose a source of leads. Customers might gain protection from unwanted contact. Investigators might lose immediate information. ARIN might assume more responsibility for confidential records and disclosure. Providers might gain both privacy protection and greater intermediary power. None of those consequences automatically invalidated the proposal, but all required a settlement broader than the originator’s business interest.
Rejection as an accountable result
The ARIN XXV tally was not a binding referendum. ARIN’s policy process uses meetings, mailing-list discussion, Advisory Council judgement and Board authority rather than a single vote. The five-to-seventy count was nevertheless an unusually clear signal. It told the Council that the text lacked broad support among the participants who chose to register a view.
The rejection also prevents an easy retrospective claim that a practical operator was defeated by people who did not understand operations. The objections were themselves operational. Anti-abuse participants described investigative dependency. Other contributors questioned data accuracy, access conditions and whether the proposed substitution protected the right interests. Law-enforcement representatives explained why registry information affected their work.
The process exposed competing operating systems. One was the commercial system in which providers acquired and retained customers. Another was the abuse-response system in which address records connected incidents to responsible parties. A third was the registry system that had to maintain reliable information. The proposal could not succeed merely by proving that the first system bore a cost.
For Wendel, the outcome established a pattern that would recur later. He could put a problem on the agenda, describe it from direct experience and survive criticism in public. He could not convert experience into authority by declaration. The formal process required other affected parties to accept the chosen wording or at least regard it as a tolerable compromise.
That is a more serious form of leadership than a sequence of uncontested victories. It includes the capacity to make a case and the discipline to remain in an institution that rejects it. The record gives no basis for claims about Wendel’s private reaction in 2010. It does show that he continued participating in ARIN discussions years later.
From customer records to exchange addresses
By 2023, Wendel’s public policy intervention concerned a different operating surface. At ARIN 52, he identified himself with Kansas City Internet Exchange and said he also operated exchanges in St. Louis, Houston, Sioux City, Des Moines and Springfield. The context was a proposal to change how much IPv4 space a new Internet exchange should receive from ARIN’s reserved critical-infrastructure pool.
The debate was about small prefixes, renumbering and conservation. A /24 offers 256 IPv4 addresses, before unusable or reserved details are considered. A /26 offers sixty-four. Supporters of smaller initial blocks argued that many young exchanges did not need a /24 and that the reserved pool should last longer. Opponents argued that smaller blocks created technical and adoption problems and that renumbering an exchange affected many independent networks.
Wendel supplied both sides of that scale problem from his own operations. He said an exchange in Sioux City would never use more than a /26, while Kansas City was renumbering from a /24 to a /23 and the process was extremely painful. He supported extending a proposed six-month transition to at least twelve months.
He also described a prospective demand shock. Federal broadband money had made peering attractive to development programmes, and he warned that organisations wanted exchanges in very small markets. He cited a list of roughly 140 prospective locations. Under a rule that could issue nothing smaller than a /24, one organisation rolling out hundreds of small exchanges might consume much of the reserved pool even if each site had few networks.
Those were not audited forecasts, and the later policy should not be treated as their automatic consequence. They were still valuable evidence. The same operator could see that small-market exchanges might waste addresses under a uniform minimum and that a growing exchange could endure painful renumbering. The problem was not “conserve” versus “waste.” It was how to allocate uncertainty between the registry and an exchange that might grow.
If ARIN assigned a small block first, the exchange carried more renumbering risk. If ARIN assigned a larger block, the shared reserve carried more conservation risk. If policy relied on forecasts, ARIN staff needed enforceable evidence. If the rule treated every exchange alike, it ignored the difference between Sioux City and Kansas City. Wendel’s testimony made the trade-off concrete without resolving it.
The 2024 rewrite
On 23 April 2024, ARIN published Proposal 333, Rewrite of NRPM Section 4.4 Micro-Allocation. Its originators were Randy Epstein, James Jun, Martin Hannigan and Aaron Wendel. The four-name record is important. Wendel brought direct exchange experience, but the proposal was not his alone.
The problem statement said the existing language had not aged well and had become difficult for ARIN staff to implement. It pointed to the growth and changing use of exchanges. It sought clearer, minimum and enforceable requirements, stronger conservation and attention to routability. The early text retained a /15 equivalent reserve for critical infrastructure.
The proposal entered the Advisory Council process and became Draft Policy ARIN-2024-5. It then changed repeatedly. Revisions appeared in December 2024, March 2025 and July 2025. The moving text reflected a basic difficulty: Section 4.4 covered more than one kind of infrastructure, and clarity for one use case could create unintended consequences for another.
Internet exchanges use addresses on peering fabrics that may not need to be globally routed in the same way as ordinary customer networks. DNS operators can have different reachability and continuity requirements. Generic top-level-domain operators, country-code operators, ARIN and IANA sit in different institutional positions. A rule that conserves addresses by narrowing eligibility or block size can affect these groups unevenly.
The later text changed the label from micro-allocation to Critical Internet Infrastructure allocations. It described eligible infrastructure, retained the reserve and specified evaluation for additional resources. ARIN staff concluded that the July 2025 version was implementable as written, estimated three months for implementation and found no material legal issue. Staff expected only minimal extra operational effort.
That review settled a mechanical question, not a political one. A rule can be possible to implement and still lack legitimacy. Staff can train, update procedures and review requests, yet participants can disagree about eligibility, routability, renumbering, conservation or the effects on new exchanges. “No material legal issue” does not mean “community settlement achieved.”
A policy that travelled far but not far enough
In September 2025, the Advisory Council unanimously moved the rewrite to Recommended Draft Policy status. That step meant the Council believed the text conformed with ARIN’s principles with a high likelihood. It did not make the text binding. Recommended status placed it before the community for a more final judgement.
The October meeting exposed the weakness. The public tally showed twenty-one in support and twenty-six against. The numbers were closer than in 2010, and they should not be inflated into a comprehensive electorate. They still contradicted any confident statement that consensus had formed around the text as written.
The Council’s minutes captured a crucial distinction. Participants often supported the intent while holding significant concerns about the language. That is not semantic evasion. In number-resource policy, wording determines which organisations qualify, which addresses can be routed, how much space may be obtained, what prior recipients must justify and when renumbering becomes compulsory.
An appealing problem statement cannot substitute for those decisions. “Modernise critical infrastructure policy” attracts broad assent. “Apply these eligibility, usage and return obligations to these recipients under these conditions” distributes costs. Consensus becomes real only at the second level.
On 31 October 2025, the Advisory Council unanimously returned the recommended policy to draft status. One recorded concern was the need for specialised input on ISP operations and DNS. The move kept the problem open while refusing to advance language that had not survived final scrutiny.
Further engagement did not materialise at the needed level. In December, the policy shepherd reported few responses to an effort to gather broader industry views. At the February 2026 meeting, the Council recorded that original authors appeared to have lost interest, that the rewrite required more scrutiny than ordinary changes, and that support was mostly negative.
The Council then abandoned the draft unanimously. It did not declare every concern about Section 4.4 false. The shepherd identified narrower issues that might justify later proposals, including routability, terminology and parts of the allocation framework. Abandonment separated the need for change from the acceptability of this package.
What the two failures have in common
Both policy episodes began with an asymmetry of attention. In 2010, providers felt the competitive cost of publishing customer contacts more directly than most registry participants. In 2023 and 2024, exchange operators felt the renumbering and address-sizing cost more directly than people who saw only aggregate reserve consumption.
Wendel’s contribution was to make those costs legible. He translated customer harvesting into proposed disclosure rules. He translated the contrast between a small-market exchange and Kansas City into an allocation problem. Without participants willing to expose operational friction, policy can be written around tidy abstractions.
The same proximity that produces insight also produces interest. An ISP may prefer confidentiality because it protects customers and because it protects revenue. An exchange operator may prefer allocation flexibility because it improves technical fit and because it reduces operating cost. Interest does not invalidate evidence. It tells the institution what else must be tested.
In both debates, the burden shifted when private cost became public rule. The proposal had to explain effects on investigators, customers, registry staff, other address holders, new entrants and future operators. It had to survive adversarial questions. The originator’s role was to propose and defend, not to decide.
This is the control surface of bottom-up policy. Authority is dispersed among proposal originators, list participants, meeting participants, Advisory Council members, staff, counsel and the Board. Different stages test scope, technical soundness, implementation, legal exposure and support. No single stage perfectly represents the community. Together they make unilateral capture harder.
The system can still fail. Mailing lists can be dominated by people with time and specialised vocabulary. Meeting tallies can underrepresent affected networks. Draft fatigue can drive away useful participants. Advisory Council judgement can over- or under-read weak signals. Experienced operators can coordinate language before less organised interests understand the consequence.
Yet a process that can abandon years of work is displaying a form of power restraint. Sunk effort did not compel adoption. Recommended status did not become a one-way door. Staff implementability did not override contested legitimacy. Those are institutional results, not empty delay.
Who bore the costs, and who might have benefited
The 2010 proposal would have reduced the public exposure of some customer contact details. Legitimate customers could have benefited from less direct solicitation. Providers could have protected a commercially valuable relationship map. ARIN would have borne responsibility for receiving and safeguarding information supplied privately.
Investigators and abuse responders might have faced extra steps to identify downstream users. Providers would have become more important gatekeepers. The quality of the result would have depended on accurate private data and responsive disclosure. The public record did not establish that every provider could meet that standard equally.
The later rewrite distributed a different set of costs. Smaller initial allocations could conserve the shared reserve, but a growing exchange might have to renumber. Larger allocations could reduce operational disruption, but they could reserve more addresses for projects that never reached scale. Clearer usage rules could deter speculative requests, but overly rigid proof could disadvantage new exchanges without a long operating history.
Wendel’s own exchange footprint gave him reason to care about both ends. Small markets could function with fewer addresses. A large fabric could outgrow a /24. That experience made his evidence relevant. It also meant that allocation rules affected organisations with which he identified publicly.
There is no evidence in the reviewed record that Wendel or his companies would have received a specific direct financial gain from either proposal. It would be irresponsible to invent one. The more defensible conclusion is structural: participants often bring overlapping public and private incentives to policy, and disclosure plus contestability are how the institution manages that reality.
The counterfactuals
If the 2010 proposal had been adopted, ARIN’s public reassignment data could have exposed fewer direct customer coordinates. Some solicitation might have become harder. Abuse and investigative work might have relied more heavily on provider response. The balance could have proved workable, or it could have produced delays and uneven accountability. The public evidence does not let us know.
If ARIN-2024-5 had been adopted, Section 4.4 would have used more explicit critical-infrastructure language and clearer requirements. Staff believed implementation was practical. The unresolved risk was whether the combined text fit all covered infrastructure and had enough support to remain stable after adoption.
If neither problem is revisited, costs remain. Customer data still sits between transparency and misuse. Critical-infrastructure address policy can still contain ageing or ambiguous language. Abandonment protects against a weak settlement; it does not repair the underlying system by itself.
The better counterfactual is therefore not “Wendel wins.” It is a narrower sequence of proposals that isolates one problem at a time, states who bears the cost and tests operational claims against multiple classes of affected party. The 2026 abandonment statement itself pointed towards narrower follow-up work.
A different measure of operator leadership
Wendel’s existing public profile is easy to tell through physical infrastructure: exchange switches, facilities, carrier partnerships and deployments around Kansas City. The policy record reveals another role. He repeatedly entered arenas where operators try to turn experience into shared rules.
That role is neither disinterested expert nor lobbyist by default. It is policy entrepreneur. The entrepreneur notices a recurring cost, frames it as a collective problem, proposes text and recruits enough attention for the institution to act. The quality of the leadership depends on the accuracy of the evidence, the candour of the interest, the precision of the remedy and the willingness to accept revision or defeat.
On those measures, the record is mixed in a productive way. Wendel identified real operational tensions. The 2010 remedy attracted overwhelming opposition. The later rewrite gathered more institutional support and survived extensive revision, but still failed to secure final acceptance. In both cases, his participation produced a clearer public record of the problem than silence would have.
The defeats also protect the analysis from biography by celebration. There is no need to claim that Wendel transformed ARIN policy. He did not. There is no basis to portray rejection as persecution by an establishment. The available records show open discussion, identifiable objections, formal tallies and Council decisions.
Nor should the abandoned outcomes erase influence. A failed proposal can change vocabulary, reveal implementation gaps and supply material for narrower successors. Participants who oppose text may still adopt its diagnosis. Staff and Council records preserve the questions for later use.
The durable result is therefore an accountability lesson. Operator knowledge becomes legitimate policy authority only after it survives institutions designed to hear other operators, investigators, users and stewards of the shared pool. Wendel had standing because he ran networks and exchanges. He did not have sovereignty over the answer.
That distinction matters beyond ARIN. Internet governance often invokes community and consensus as if the words guarantee representation. This record shows the harder version. Consensus must be able to stop a proposal with a credible problem statement, experienced originators, years of work and an implementable text when the settlement remains unconvincing.
Two failed proposals do not make Aaron Wendel a failed operator. They make him a useful case study in bounded influence. He brought costs from the operating edge into the room. Others exposed costs beyond his frame. The institution chose not to impose either settlement.
The next test is whether the process can retain the operational insight without reproducing the rejected package. If narrower changes emerge, their legitimacy will depend on the same discipline: name the beneficiaries, show the burden, expose the language to adversarial review and preserve the community’s right to say no.
Why the language, not merely the idea, decided the outcome
The later proposal is especially useful because its official record separates sympathy for an objective from consent to a rule. ARIN staff and counsel found the text clear enough to implement and identified no material legal risk. That cleared two important tests. It did not settle whether the allocation rule expressed the right balance, whether its definitions covered the right institutions, or whether participants had supplied enough evidence to make the balance durable.
That distinction is easy to lose in accounts of technical governance. A proposal may be executable without being accepted. It may be legally unobjectionable without being distributively fair. It may solve a documented problem for one class of network while creating a less visible problem for another. An implementation assessment answers what the registry would have to do. Community review asks whether the registry should do it and under which conditions.
Wendel’s evidence at ARIN 52 showed why a smaller allocation could be expensive. An exchange fabric is shared infrastructure. Renumbering is not a matter of changing one router and closing a ticket. Members have configurations, filters, documentation and maintenance windows of their own. A change coordinated across independent networks can become a long programme whose risk is out of proportion to the number of addresses conserved. His account of KCIX moving from a /24 to a /23 gave the argument operational weight.
The same evidence also revealed the limits of analogy. A mature exchange that has already outgrown a /24 is not identical to a new exchange with a small participant base. A grant-supported project intended to improve regional connectivity is not identical to an established commercial fabric. A DNS operator has different address-use characteristics again. If one section groups several kinds of critical infrastructure together, every eligibility term and initial-allocation rule has to survive those differences.
The Advisory Council’s October 2025 minutes recorded support for the intent alongside concern about the language. That is not bureaucratic evasion. In policy, language is the mechanism that decides who receives a resource, how much, on which evidence and with what precedent. Agreement that exchanges should avoid disruptive renumbering does not determine whether every new exchange should receive the same initial block. Agreement that critical infrastructure deserves special treatment does not determine the boundary of criticality.
The 2010 case contained the same problem in another form. Many participants could recognise that public registration data might be mined for sales leads. Recognition did not answer whether the customer’s address and telephone number should disappear from public view, who would obtain the confidential version, how quickly it would be supplied, or how investigators would preserve accountability. The policy text had to allocate those rights and burdens. A general appeal to confidentiality could not do that work by itself.
This is why counting support is informative but incomplete. The five-to-seventy result in 2010 showed overwhelming opposition among counted participants. The twenty-one-to-twenty-six result in 2025 showed a narrower but still negative judgment. Neither tally explains every objection, and neither substitutes for Council responsibility. Read beside transcripts, staff assessments and minutes, however, the numbers show when a plausible operator concern failed to become acceptable shared language.
The two records also resist a heroic reading of persistence. Returning after a defeat is valuable when it brings a new problem, better evidence or more precise terms. Persistence is not itself proof that a community ought eventually to yield. The policy entrepreneur remains responsible for testing whether the next draft answers other participants rather than merely restating the originating cost.
Wendel’s public role matters precisely because it is bounded. He could use lived experience to identify failure modes before they became visible in aggregate data. He could propose text and answer criticism in the room. He could not make the registry treat his estimate of operational burden as the only relevant knowledge. The open process turned his expertise into evidence that others could accept, qualify or reject.
For readers evaluating future proposals, the lesson is practical. Ask first whether the originating operator has described a repeatable problem rather than a singular inconvenience. Ask next which costs the proposed rule moves to parties absent from the room. Then examine whether definitions, thresholds, review rights and evidence requirements make those transfers visible. Finally, distinguish support for the goal from support for the actual language. That sequence gives expertise full weight without granting it unchecked authority.
The outcome is not anti-operator. A registry policy made without operators would be brittle because it would miss coordination costs, deployment constraints and the consequences of renumbering. A policy made only from operator testimony would be brittle for the opposite reason: it would understate public accountability, resource conservation and the interests of networks with different scale or business models. The institution earns legitimacy by keeping both kinds of knowledge contestable until the words are ready—or by abandoning them when they are not.
Sources
- ARIN archive: Draft Policy 2010-3, Customer Confidentiality
- ARIN XXV public-policy meeting transcript
- Krebs on Security: ISP Privacy Proposal Draws Fire
- ARIN 52 day-one transcript
- ARIN Proposal 333
- ARIN archive: Draft Policy ARIN-2024-5
- ARIN 56 rough transcript
- ARIN Advisory Council minutes, 31 October 2025
- ARIN Advisory Council minutes, 19 February 2026
- Existing BTW profile used only for editorial-deduplication comparison
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
