Here is what lac ich does: <https://www.lacnic.net/5733/2/lacnic/how-to-validate-your-abuse-contact-to-unblock-access-to-milacnic>

It's more than keeping an elaborate list of numbers, and neither they or the world has ended.


So, this could be an easy start   

Then Morecambe added, e.g no action against specific abuse types.  (I very much favour a well defined list, even if it will miss edge casses).


I think if the argument is, ripe should never do more than run a db, fighting abuse will have to happen elsewhere.

I see ripe as a community that endures it stays nice. 

So start with some simple things:

Verify folks reply.
Expand to action in specific casses.

If we agree on this we can start to work out the mechanics.

Best
Serge


On 1 August 2026 15:45:38 UTC, Gert Doering <gert@space.net> wrote:
Hi,

On Sat, Aug 01, 2026 at 01:45:15AM +0300, Sergey Myasoedov via Security-wg wrote:
On 7/31/2026, at 16:41, Nick Hilliard <nick@foobar.org> wrote:

The issue we have in the RIPE security wg, and before that, abuse-wg and anti-spam-wg, is that the solutions being proposed involves changing the nature of the RIPE NCC from a registry into an quasi-judicial and enforcement body. Essentially the arguments are of the form which could waspily be described as "politicians' logic":

Technically, we crossed this line when we introduced not just the company names, but also their registration numbers into the RIPE Database. NWI-21.

This very much sounds like a thing a registry would do, like, register
numbers and document who has them, in an unambiguous way? So which line
exactly was crossed by publishing more unambiguous holder info, for
legal entities?

Gert Doering
-- NetMaster
--
Dr. Serge Droz
Director, Forum of Incident Response and Security Teams
https://first.org