Summary

  • ARIN said on 5 August that its database contains roughly 17,000 legacy networks and that about half have no Point of Contact or one it has not been able to verify.
  • The same post says only 11% have a currently validated contact and an additional 20% have incomplete contact information. It then compares those network figures with a 76% validated rate for organizations whose resources are under an ARIN agreement.
  • Those statements do not prove a contradiction. They do leave the reader without an exact data date, group counts, denominator definitions or a rule saying which statuses overlap.
  • ARIN can close the gap without exposing personal records: publish a versioned aggregate table that distinguishes networks, organizations and POCs and gives a count, denominator and rule for every category.

A sharp warning arrived without its ledger

ARIN's 5 August post is more specific than the usual reminder to keep registry data current. It says there are roughly 17,000 legacy networks in the database. About half, it says, have no Point of Contact or a POC ARIN has not been able to verify. Only 11% have a contact record that is currently validated; an additional 20% have a contact on file with incomplete information.

The post then turns to a comparison group: organizations whose resources are under an ARIN agreement. It says 76% of that group have a validated contact record and none have incomplete contact information. ARIN does not attribute the difference to the paperwork itself. It says the difference is that someone reviews the information and updates it when necessary, and it explicitly tells legacy holders they can do the same without entering an agreement.

That is a useful operational message. Stale contacts can make a resource look neglected, slow a legitimate transfer or recovery, and give an impersonator a weak point to probe. The percentages give the warning scale.

But percentages are not yet a status ledger. The page does not publish the data cut behind the numbers, the exact population counts, the rounding method, or a table that assigns every record to a defined state. A reader can repeat the prose. A reader cannot reproduce the snapshot.

The denominator changes halfway through the comparison

The first disclosed unit is a network. The comparison unit is an organization. The policy process underneath both works on POC records.

Those are not interchangeable objects. One organization may be associated with several networks. A network can have contacts attached directly to the resource and contacts inherited through its organization. One POC can appear on more than one organization or resource. ARIN's current POC guidance describes Admin, Tech, NOC and Abuse roles, not a one-contact-per-network model.

The distinction also appears in ARIN's Data Accuracy Improvement Program. There, an organization is Complete when required organization fields and at least one associated POC contain required data. It is Correct when the organization has been vetted and at least one POC validated. It is Current when both things happened within the past five years. Those are organization-level compound tests.

The 5 August post does not say that its 11% legacy-network figure uses those three tests. Nor does it say that the 76% agreement-covered organization rate can be compared one-for-one with the roughly 17,000 networks. The comparison may be methodologically appropriate inside ARIN. Its public form does not carry the crosswalk.

This is the sort of difference that disappears in a chart label and becomes decisive in an audit. If the numerator counts networks with at least one valid inherited POC, the rate answers one question. If it counts every POC record and asks how many are current, it answers another. If the agreement group is counted by organization while the legacy group is counted by network, the two percentages describe different populations even when both are accurately calculated.

Eleven plus twenty does not classify the remainder

The phrase an additional 20 percent makes it reasonable to read the incomplete bucket as separate from the 11% currently validated bucket. Applied to an approximate population of 17,000, the two shares would represent about 1,870 and 3,400 networks. Those are illustrations, not ARIN-published counts: roughly 17,000 is not an exact denominator.

The two shares add to 31%. That does not authorize a label for the remaining 69%.

The preceding sentence says about half have no POC or one ARIN has not been able to verify. It does not state whether an incomplete contact is also counted as unverifiable, whether no POC and unverified POC are published as separate categories, or whether the remaining records are awaiting annual validation, stale under another rule, indirectly covered by an organization contact, or in another status altogether.

It would be wrong to subtract 11 from 100 and announce that 89% of legacy networks have invalid contacts. Currently validated, not currently validated, incomplete, unverified, invalid and absent are not synonyms. The current NRPM gives invalid an operational meaning tied to a POC record and its response or legitimacy. The blog uses a broader public explanation.

The bounded finding is therefore not arithmetic failure. It is category non-closure. ARIN has given enough numbers to invite a calculation, but not enough definitions to make that calculation authoritative.

The rule is clearer at the POC level

NRPM 3.6 says ARIN will verify specified public Whois POCs annually. Admin, Tech, NOC and Abuse contacts are covered, including both organization and resource POCs. Each has up to 60 days after notification to confirm that its information is correct and complete or to submit corrections.

The consequence is also bounded. An invalid POC is restricted to payment and contact-update functions in ARIN Online. An organization with no valid POCs cannot use further functions until at least one Admin or Tech POC validates or corrects a record. Under section 3.7, a receiving organization without a validated POC cannot complete a reallocation or detailed reassignment request.

None of that makes the number resource itself invalid. A network does not become revoked, abandoned or available for someone else merely because a contact failed validation. Contact status affects account authority, service access and the strength of the public evidence. It is not title, routing control or a transfer decision.

That distinction matters because ARIN's blog describes real attack mechanics. It says hijackers look for records that appear abandoned and may try to impersonate the organization on file, take over an Org ID or POCs, and then persuade providers to route the resources. The claim supports vigilance. It does not report that every unvalidated record has been attacked or that validation alone proves the lawful controller.

ARIN already has a report, but it is not this public receipt

ARIN documents a report of resources with no valid POCs. Its rule is specific: the report contains Networks and ASNs with no POCs associated directly or through the resource's organization, or with all associated POCs invalid.

That report shows that ARIN can calculate a resource-level status from direct and indirect associations. It does not automatically reproduce the blog figures. It combines Networks and ASNs, while the blog names legacy networks. Its page says access is subject to an approved request under the Bulk Whois Acceptable Use Policy and prohibits redistribution. It is a controlled operational dataset, not a ready-made public aggregate history.

The right transparency request is therefore not “publish every stale email address.” Raw contact records carry privacy and misuse risks. The missing object is a small aggregate receipt: no names, no addresses, no telephone numbers, no per-prefix accusations.

For each snapshot, ARIN could publish the exact cut-off time, population definition and count. It could identify whether the unit is network, ASN, organization or POC; separate direct from inherited contacts; define each status; say whether buckets overlap; and show both numerator and denominator. A rounding rule and correction history would make later updates comparable.

One additional field could map the blog categories to the no-valid-POC report and the Complete/Correct/Current program. If the populations differ, the field should say so. A difference that is explicit is not a defect.

Good aggregate evidence strengthens the thin registry

ARIN does not need to become a universal investigator of every company behind every prefix. Its essential job here is narrower: maintain a unique, usable registration record; give authorized holders a correction path; and let operators understand what a public status does and does not prove.

A reproducible aggregate table helps that limited role. It lets legacy holders see the scale of the maintenance problem without treating them as a homogeneous suspect class. It lets network operators distinguish absence from failed validation. It lets researchers track whether outreach changes the population. It lets ARIN correct a category or method later without silently rewriting history.

The 5 August post has already supplied the hard part: a concrete population and a reason to act. Publishing the measurement receipt would not weaken the warning. It would give the warning an audit trail.

Sources