Summary

  • RIPE NCC’s October 2026 guide says both voting emails come from Assembly Voting: one carries a unique link with pre-filled Voting Code 1, while the other carries Voting Code 2, identical to the GM Registration Number.
  • RIPE NCC’s 2022 launch materials described the registration number as arriving from RIPE NCC and a separate link-and-code message as arriving from Assembly Voting. The public description changed; the reviewed record does not explain what control changed with it.
  • This is not evidence that the platform is insecure or that an election was compromised. It is evidence that two labels and two messages are not enough to audit factor independence, recovery authority or the boundary between voter identity and ballot secrecy.
  • A versioned credential map can disclose purpose, issuer, channel, activation, resend, revocation, unlinking and observer scope without publishing secret values or exploit-relevant internals.

Two messages are visible; the trust boundary is not

The most consequential sentence on RIPE NCC’s current voting page is not a cryptographic claim. It is a delivery instruction. For the General Meeting scheduled for 28–30 October 2026, registered eligible voters are told that Assembly Voting will send two emails. One contains a unique link to the voting platform and Voting Code 1, already filled in. The other contains Voting Code 2. The second code is identical to the voter’s General Meeting Registration Number. Both messages are described as coming from the same Assembly Voting sender address identified in the guide.

The workflow is easy to picture. A voter opens a personal link, reaches a page after voting has opened, supplies the other code and casts a ballot. RIPE NCC also publishes practical boundaries: the link is inactive before the vote; the recipient’s mail server needs TLS 1.2; Safari may fail to display the pre-filled code correctly; and a voter who does not receive the messages should contact the General Meeting team.

This is better than the instruction “log in securely.” It identifies the platform, tells voters what to retain and acknowledges ordinary delivery failure. Yet it leaves an important ambiguity. Are the two codes independent credentials, two references to one eligibility record, or a bearer link plus a lookup value? Which system creates each value? Can either be derived from information available elsewhere? What does a resend invalidate? Which actor can substitute an address? At what point is the identity used to establish eligibility detached from the ballot that must remain secret?

The public guide does not answer those questions. That does not mean RIPE NCC or Assembly Voting lacks answers. It means the answer is not in the public control record.

The public architecture was described differently in 2022

RIPE NCC introduced Assembly Voting in October 2022 with a much richer security story. Its launch article described end-to-end verifiability, encrypted votes, a digital bulletin board and opening and closing key ceremonies involving Assembly Voting, RIPE NCC and an independent observer. It also described two-factor authentication in operational terms: one email would come from RIPE NCC with the member’s registration number; Assembly Voting would send a separate email with the platform link and the other code.

The contemporaneous voting guide used the same separation. A registered voter would receive the registration number from RIPE NCC and a personal auto-sign-in link from Assembly Voting. A downloadable receipt and bulletin-board verification were part of the published journey. The point is not that this arrangement was necessarily stronger. Two different institutional senders can still terminate at one mailbox. A forwarded message can collapse channels. A compromised mailbox can expose both. Operational independence requires more evidence than different “From” lines.

The comparison matters for a narrower reason. By 2026, the public instruction says both messages arrive from Assembly Voting. The May 2026 procedure slides identify the same vendor address for the emails. The signed voting report calls the login “2 factor” and records a first email with Code 1 and the platform link, followed by a second email with Code 2. It does not explain whether the registration number is imported from RIPE NCC, transformed by the voting system, placed in a separate store, or protected by a different authorization path.

What changed is therefore the visible description, not a proven security property. The honest finding is that the public record no longer lets a member reconstruct why the two inputs deserve to be treated as two factors. A label carried forward from a platform design is not a substitute for a current dependency map.

Registration 2FA is a separate control

The October registration page supplies another layer. A prospective voter signs into the LIR Portal, selects the organisation represented, chooses whether to vote and receives a confirmation message containing a registration number. RIPE NCC says two-factor authentication is mandatory for RIPE NCC Access account holders.

That is a material defence. The General Meeting registration number is not handed to an entirely unverified person. It follows an account login and an eligibility process. One person per eligible member organisation may register to vote; the organisation must satisfy membership conditions; the voter must be an appropriate contact or otherwise authorized under the Articles.

But account 2FA and ballot login should not be merged rhetorically. The first proves something at registration time: that an account holder who presented RIPE NCC Access factors completed a member-facing action. The later voting flow proves something else: that a person possessing the delivered link and registration-linked code can enter the ballot platform during the voting window. The reviewed public pages do not say that the original LIR Portal factor is challenged again, cryptographically bound to the voting session or required during recovery.

That separation may be intentional. Requiring the LIR Portal during every ballot session could create a new dependency and repeat the registration gate at the most sensitive moment. A decoupled election platform can improve availability. But decoupling creates a duty to explain the handoff. The question is not whether every voter should authenticate twice to every system. It is which proof is relied on at each boundary and which failure can be recovered without silently changing the electorate.

Recovery is where authority becomes visible

The May 2026 voting report records 27 requests for assistance. It adds a particularly important sentence: when an alternative email address was provided to staff, voting emails were resent through the voting system using the new address.

Nothing in that sentence establishes wrongdoing. A voter can lose access to a corporate mailbox, encounter filtering, discover a TLS incompatibility or need a legitimate correction. A working recovery path protects participation. The report deserves credit for recording the number of requests and the fact of resends.

Recovery nevertheless reveals the real authority structure. Who is allowed to propose a replacement address? Which staff role verifies the request? Against which member or contact record? Does approval require a second reviewer? Are old links and codes revoked automatically? Can a resend go to both addresses? Does the voting system record the reason and approver? Can the independent observer inspect an exceptions ledger? Are support cases reconciled against successful ballots without exposing voter choices?

These questions are not a request to publish personal addresses or help-desk transcripts. A privacy-safe receipt can state that, for example, 27 cases were opened, a defined number involved delivery, a defined number resulted in address substitution under a named authorization class, all superseded credentials were revoked, no unresolved eligible-voter case remained at close, and the observer examined the exception log. If any of those propositions is untrue, the receipt should say what exception remained.

The decisive control is often not the normal login. It is the person who can change the normal login when it fails. In governance, recovery power is electoral power. It should be designed generously enough to restore an eligible member and narrowly enough that staff cannot create a new voter by convenience.

The credential map should follow the full chain

A useful map begins before either email. It starts with the member register and the authorized natural person. It then follows the LIR Portal session, the choice to vote, the registration-number record, export or handoff to the vendor, generation of the unique link, delivery events, activation, failed attempts, support intervention, credential replacement, ballot login and final closure.

Each element needs a type. “Voting Code 1” could be a pre-filled identifier, a secret, a token embedded in a URL or an opaque reference to protected state. “Voting Code 2” could be a separately delivered secret, an imported registration identifier or a value known to more than one system. The article does not infer which. The map should say.

The map also needs a privacy boundary. Eligibility requires identity. Ballot secrecy requires that the recorded choice not be attributable to that identity. End-to-end verifiability requires a voter to confirm inclusion or correct processing without turning the receipt into proof of how the person voted for a third party. Those properties can coexist, but only if the system records the transition explicitly: identity verified here; voting entitlement issued here; ballot credential redeemed here; identity link discarded, blinded or otherwise protected here; encrypted ballot posted or accounted for here; observer verifies these steps here.

RIPE NCC’s 2022 material offered pieces of this picture: encryption, the bulletin board, a receipt, key ceremonies and an external observer. The 2026 voter guide understandably focuses on what a member must click. The missing object is the bridge between the two. A usability guide is not a threat model, and a historical threat model is not a current operating receipt.

What can safely be published

A credential map does not need entropy figures, database schemas, internal hostnames, recovery evidence, personal data or exploit paths. It can publish control metadata:

Stage Safe public field
Eligibility Responsible institution, rule set, as-of time and exception count
Registration Source system, authentication class and successful handoff count
Credential issuance Issuer, purpose, independence claim and version
Delivery Sender class, channel, delivery window and aggregate failures
Activation Opening condition, expiry and clock authority
Recovery Approver class, verification rule, resend count and supersession result
Ballot access Inputs required and privacy-safe failure classes
Anonymization Declared identity-to-ballot separation point and attestation scope
Verification Receipt or bulletin-board function and voter instructions
Closure Key ceremony, observer, exceptions and final reconciliation

The resulting record should be versioned by meeting. If the sender arrangement changes, the old map remains available and the new map explains the changed dependency. If only the user-facing wording changes while the backend control remains identical, the record can say that. Either answer is more useful than forcing members to infer architecture from email labels.

An association vote has a bounded but real mandate

Heng Lu’s distinction between stakeholder participation and principal authority is useful here. A RIPE NCC General Meeting is not a referendum of every network operator or Internet user in the service region. It is a corporate act by an eligible member electorate. The Articles give that electorate real powers within the association, and they give the Executive Board responsibility for the technical procedure of electronic voting.

That bounded authority is a reason for stronger evidence, not a reason to dismiss the vote. Formal voting improves on atmospheric claims of community consensus because it identifies a body, a rule and an outcome. The credential chain is the running code behind that corporate act. If labels replace the chain, ritual begins to substitute for execution.

The standard should be proportionate. No one needs an Internet-wide constitutional theory to send two voting emails. Members do need to know what proof crosses each control boundary, who can repair it, what repair supersedes and how the secret ballot remains secret. The common layer can remain thin: eligibility, access, recovery, auditability, anonymity and a reliable record.

RIPE NCC has already published many of the ingredients. Its next step is not a new security slogan. It is a map of the control it already asks members to trust.

Sources