Summary

  • Prop-171 would make an upstream holder responsible for a reliable path from the registered abuse contact to the downstream party able to investigate and resolve a report; it addresses delivery, not the substance of the allegation.
  • Prop-172 would define categories of IP-address abuse and let the resource holder adjudicate first, while saying APNIC cannot adjudicate abuse yet retains responsibility to hold holders accountable for responding and addressing it.
  • Comments filed on 16 and 21 August already challenge the use of jurisdiction-dependent conduct, missing categories and the lack of legal and impact analysis. The safe common layer is contact accuracy and routing; any substantive consequence needs a named decision-maker, evidence test, cure and review.

Two proposals created one sequence

An abuse report has to pass two gates before it can produce a defensible operational outcome. It must reach someone capable of investigating the relevant network use. Then somebody must decide whether the facts fit a rule, whether the notice is credible and whether the response is adequate.

APNIC's Policy SIG is now being asked to discuss those gates together. On 9 August, the chairs circulated prop-171, Operational Accountability for Abuse Contacts in Sub-Allocated Address Space, and prop-172, Defining Internet Abuse through IP Addresses. Both are scheduled for the Open Policy Meeting at APNIC 62 on 10 September.

The pairing is visible beyond APNIC's own pages. An independent RIR proposal index lists both as To be discussed at APNIC 62, last changed on 10 August. A TWNIC notice places them among seven proposals in the 09:30–13:00 Policy SIG session in Mumbai and schedules a local online discussion for 25 August.

Neither proposal is adopted policy. Their proximity on the agenda nevertheless exposes a design problem that is easier to miss when each text is read alone. Prop-171 builds a route for the report. Prop-172 supplies a vocabulary for the allegation. The unresolved question is what happens when the route works but the parties disagree about the vocabulary.

The first gate is delivery

Prop-171 begins with a practical distinction. A registered abuse contact can be valid and reachable while still being operationally useless.

APNIC's existing IRT validation can establish that a mailbox receives a challenge. It cannot establish that the person behind it knows which downstream customer used an address at a particular time, can access the relevant logs or has authority to mitigate the conduct. In a sub-allocation chain, a message may land at an upstream provider, a centralized group mailbox or an intermediary several layers away from the network in question.

The proposal would put responsibility on the upstream holder responsible for the registry record. That holder would have to ensure a reliable operational path from the registered contact to the party able to investigate and resolve reports for the address space. A downstream desk could be registered directly. An upstream desk could triage and forward reports. Another arrangement could qualify if legitimate reports reach the operationally responsible party without undue delay.

This is more specific than the old convention that an abuse address should exist. RFC 2142 made ABUSE@domain a standard mailbox name in 1997. A mailbox name reduces search cost. Prop-171 is trying to reduce the next cost: the dead end between the public address and the private operating chain.

The text is also careful about some limits. It does not require public disclosure of every downstream customer contact. It says it creates no new audit or compliance mechanism and does not prescribe one operating model. Secretariat guidance would explain how the principle applies across different tiers.

Those limits matter because the proposal still uses loaded terms. Which reports are legitimate? How much delay is undue? What demonstrates a reliable path? Those questions can be answered operationally — acknowledgements, ticket routing, escalation records and time-bounded tests — or substantively, by judging the allegation. The first approach verifies delivery. The second quietly moves into the next gate.

The second gate is classification

Prop-172 addresses what current contact rules avoid: a definition of Internet abuse through IP addresses.

Its draft includes distributing or hosting malware; originating, amplifying or reflecting DDoS traffic; deliberate or grossly negligent routing-layer abuse; fraudulent acquisition, transfer or sub-allocation of address resources to facilitate covered conduct; and infrastructure used for phishing, fraud, scams or impersonation. It excludes good-faith mistakes that are promptly corrected, including inadvertent routing misconfiguration. It also excludes third-party unlawful conduct where a holder addresses it promptly after notice.

The proposal attempts to keep its own reach narrow. It says it creates no new obligation, reporting requirement or compliance mechanism. It leaves first-instance adjudication with the resource holder when a reporter has a legitimate basis and the holder has the practical ability to act. An isolated delayed or imperfect response would not itself be abuse. Good-faith reliance on a substantiated notice receives a safe harbor.

Then the text reaches its hardest sentence. APNIC, it says, does not have power to adjudicate abuse. In the next breath, it says APNIC retains its existing responsibility to hold resource holders accountable for responding to and addressing abuse.

Those statements can coexist only if accountable is given a bounded meaning. APNIC could check whether the registered route for a notice works, whether the holder acknowledges receipt or whether a record is accurate. It cannot determine that a holder failed to address abuse without deciding something about the allegation, the evidence, the holder's practical ability, the response and the governing law. A registry cannot review an answer while claiming never to judge the question.

Three decisions remain unassigned

The gap can be described without inventing a tribunal that the drafts do not create.

The first decision concerns notice. Who decides that a reporter has a legitimate basis and that the notice is substantiated? A security team can reject a malformed ticket, a competitor's harassment or an unauthenticated complaint without deciding the underlying conduct. Yet if rejecting the ticket later counts against the holder, notice validity needs evidence criteria.

The second concerns classification. Prop-172 gives the holder the first answer. That is operationally sensible: the holder or its customer is more likely to possess logs and context. It is also structurally incomplete. A party accused of failing to respond cannot be the final reviewer of its own decision if the policy is ever connected to consequences.

The third concerns review and remedy. If APNIC cannot adjudicate, who decides a contested case? A national court can apply public law, but Asia-Pacific networks, reporters, customers and infrastructure can span several jurisdictions. A contract can allocate responsibility between an upstream and downstream network, but it cannot create public authority over a third party. Secretariat guidance can explain ticket flows, but guidance should not become an unapproved substantive code.

The missing items are therefore concrete: a decision-maker, evidence standard, jurisdiction rule, response test, cure period, proportionate remedy and appeal or independent review. Prop-172 says future proposals may address obligations. That sequencing should be preserved. A definition should not acquire enforcement effects through implementation guidance before those effects have gone through their own policy debate.

The mailing list found the fault line quickly

The initial comments do not show a settled opposition to addressing abuse. They show disagreement about where technical description ends and legal judgment begins.

On 16 August, Jonathan Brewer supported prop-172 but asked to remove unlawful because law depends on jurisdiction. He proposed covering attempts at harm and adding scanning, probing and intrusion. Terry Sweetser raised the same jurisdiction concern, warned about scope creep and asked whether announcing one's own prefixes without signed ROAs might be pulled into the definition. He pointed to RFC 4732, which itself notes that a sufficiently subtle DoS attack can be indistinguishable in principle from a flash crowd.

On 21 August, Jordi Palet commented on both proposals. For prop-171, he asked for the Secretariat impact analysis and questioned whether the text added anything if the upstream holder was already responsible when a downstream mailbox failed. Seven minutes later, his prop-172 comment asked whether a definition would work in Australian or other national courts, requested legal analysis and identified spam, scanning and intrusion attempts as omissions.

These comments also demonstrate why a list of examples cannot finish the policy. Add scanning and research needs a consent rule. Add unlawful and the policy needs a jurisdiction rule. Add a catch-all and the definition becomes less predictable. Remove every contested category and it may cease to help the abuse desks it was written for.

The thin rule remains valuable

The choice is not between ignoring abuse and turning APNIC into an abuse court.

A narrow registry layer can do useful work. It can require an accurate role contact, test objective reachability, show validation status, map the contact to the correct resource record and let a holder record how a sub-allocation reaches its responsible desk. It can give a cure period for stale data and distinguish public contact fields from confidential customer records. These acts improve the ledger and make reports deliverable.

Lu Heng's Policy Mirror calls this the thin rule. The thick rule begins when contact verification is used to judge the substance, speed, adequacy or legal sufficiency of a response, especially if a registry service or a holder's recognized control could be affected. In that formulation, the registry should publish the door, not police what happens inside the building.

An NRS explainer on APNIC makes the same remit distinction in plainer operational terms: an APNIC reference in a Whois result identifies the delegation chain; it does not mean APNIC originated the abusive traffic, and APNIC does not have authority to prevent it.

Prop-171 can remain close to that thin layer if reliable path is implemented as verifiable ticket routing rather than a duty to reach a preferred outcome. Prop-172 can remain a vocabulary exercise only if later consequences are not smuggled into the meanings of respond, address or accountable.

What the September meeting must separate

The 10 September discussion does not need to solve every form of online harm. It needs to decide which question each proposal is competent to answer.

For prop-171, the useful test is operational: does a report sent to the public contact receive an acknowledgement, acquire a traceable ticket and reach the party with the relevant logs and authority? A Secretariat impact analysis should identify costs across NIRs, upstream providers, resellers, hosts and customer networks without assuming that the top-level holder handles every incident itself.

For prop-172, the first test is constitutional before it is taxonomic. Is APNIC creating common vocabulary, interpreting an existing duty or preparing a basis for future sanctions? Who reviews the holder's first-instance decision? Which legal system governs unlawful conduct? How are research scanning, mistakes, disputed routing events and incomplete evidence treated? What part remains outside number-registry competence?

The immediate news is that these questions are now live, not that their answers are settled. Two proposals have usefully separated a report's route from its meaning. APNIC 62 should preserve that separation. A mailbox can be tested. A forwarding path can be audited. A contested verdict requires authority and due process that a contact record cannot supply.

Sources