[113790] in North American Network Operators' Group
Re: Important New Requirement for IPv4 Requests [re "impacting
daemon@ATHENA.MIT.EDU (Owen DeLong)
Tue Apr 21 18:28:11 2009
From: Owen DeLong <owen@delong.com>
To: Shane Ronan <sronan@fattoc.com>
In-Reply-To: <328B8B3B-9DD0-440A-99E4-B37193074CC9@fattoc.com>
Date: Tue, 21 Apr 2009 15:19:30 -0700
Cc: John Curran <jcurran@istaff.org>, nanog@nanog.org,
Roger Marquis <marquis@roble.com>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
--Apple-Mail-19-52166031
Content-Type: text/plain;
charset=US-ASCII;
format=flowed;
delsp=yes
Content-Transfer-Encoding: 7bit
On Apr 21, 2009, at 2:42 PM, Shane Ronan wrote:
> I'm not sure if anyone agrees with me, but these responses seem like
> a big cop out to me.
>
> A) If ARIN is so concerned about the potential depletion of v4
> resources, they should be taking a more proactive roll in proposing
> potential solutions and start conversation rather then saying that
> the users should come up with a proposal which they then get a big
> vote one.
>
Well... ARIN is structured with a bottom-up community driven policy
process. That has
served us well for many years, and, I think that changing it would be
a mistake. However,
in this case, that means that the following people are specifically
excluded from proposing
policy:
The BoT (other than via the emergency process)
ARIN Staff
Policy proposals must come from the community. Either at large, or,
from the ARIN AC
which is an elected subgroup of the community tasked with developing
good policy for
ARIN. The AC itself depends largely on community input for what kind
of policy the
community wants us to develop, and, at the end of the day, community
consensus is
required in order for a proposal to become policy.
> B) Again, while it might be the IETF's "job", shouldn't the group
> trusted with the management of the IP space at least have a public
> opinion about these solutions are designed. Ensuring that they are
> designed is such a way to guarantee maximum adoption of v6 and thus
> reducing the potential for depletion of v4 space.
>
The IETF specifically does not accept organizational input and
requires instead that
individuals participate. This is one of the great strengths, and, also
one of the great
weaknesses of the IETF. However, it means that even if ARIN could
develop a public
opinion (which would have to come from the ARIN community by some
process which
we don't really have as yet), this opinion wouldn't mean much in the
IETF's eyes.
> C) Are ARIN's books open for public inspection? If so, it might be
> interesting for the group to see where all our money is going, since
> it's obviously not going to outreach and solution planning. Perhaps
> it is being spent in a reasonable manner, and the fees are where
> they need to be to sustain the organizations reasonable operations,
> but perhaps not.
>
I will leave this to the BoT to answer, but, I know that the treasurer
presents a report
at every members meeting which provides at least some high level
details. I believe
that as a non-profit corporation, a great deal of openness is required
for accountability
to ARIN members.
> Mr Curran, given the response you've seen from the group, and in
> particular the argument that most CEO's or Officers of firms will
> simply sign off on what they IT staff tells them (as they have
> little to no understanding of the situation), can you explain what
> exactly you are hoping to achieve by heaping on yet an additional
> requirement to the already over burdensome process of receiving an
> IPv4 allocation?
>
I can't say what Mr. Curran expects, but, here's how I see it:
1. If an officer of the organization signs off, then, that means that
both the
organization and the officer personally can be held accountable for any
fraud that is later uncovered. If the officer is an idiot, perhaps
he'll just
sign, but, most officers I have experience with don't do that. They
usually
engage in some level of verification before signing such a statement.
2. Organizations which are submitting fraudulent requests may be less
willing to do that when someone has to make a signed attestation under
penalty of perjury. Especially when that person has fiduciary
liability to
the organization as an officer.
3. There are lots of things people will do if they don't think there
are potential
consequences. A signed attestation by a corporate officer dramatically
reduces the apparent lack of consequences to a fraudulent application.
Sure, there will always be criminals and criminals may not be bothered
by this signed attestation process. However, having it does give the
ARIN
legal team a better shot at them as well.
I am not a lawyer and these are just my own opinions.
Owen
--Apple-Mail-19-52166031
Content-Disposition: attachment;
filename=smime.p7s
Content-Type: application/pkcs7-signature;
name=smime.p7s
Content-Transfer-Encoding: base64
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIERDCCBEAw
ggOpoAMCAQICARQwDQYJKoZIhvcNAQEFBQAwgaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTER
MA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoTEURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxE
ZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJ
KoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tMB4XDTA2MTIxNjE2MzcxN1oXDTE2MTIxMzE2MzcxN1ow
fTELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzEP
MA0GA1UECxMGUGVyc29uMRQwEgYDVQQDEwtPd2VuIERlTG9uZzEeMBwGCSqGSIb3DQEJARYPb3dl
bkBkZWxvbmcuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7H7JBEUaAy56E6qY
0JoHKfI+6QT7hYjnc1JezeZOA5XxK7QERkx8rdcND47xeNXjw06ZMjfhrcGkxM+1PEatBxC1Aax1
V95fKtw0DkNMKRgH138E6mZhwuWsvcA1bhxJQQc++SumEX5Uyr5dX4jYy2WgmaLKc8TD/N5G+/zb
Rc1sLrznovNvv7daKfDFlufRkPnLpeG0gx/HIFa4csMNYH2rdLt2xUBAt4TSy3fjEbp0HFVRJI4G
QRHbMmb6tBMnT9vpUZrwMHydqHHTiGr2A8PgdQeQLNEknKynVFTjJIXhBUSINhCl2HtQA+TKv+gu
EF9HrIybZSDlhGym0JUgKwIDAQABo4IBIDCCARwwCQYDVR0TBAIwADAdBgNVHQ4EFgQUzaaV8BC8
UhxaWk6IQTpqK9mLnSgwgdMGA1UdIwSByzCByIAU15gTZIxt8E1K2l0KkjrRFpdc5eyhgaykgakw
gaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTERMA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoT
EURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxEZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5
MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJKoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tggEA
MBoGA1UdEQQTMBGBD293ZW5AZGVsb25nLmNvbTANBgkqhkiG9w0BAQUFAAOBgQCWRsD48eQfaNKH
K2lohMTD9voszp/GuoWTyi6RckNxW0b0V0gv7ZGH1BUmgq2Jt7SjIis7vTY3FCZUDcR9e7fpBXJL
/euk2pPEBSHbCWAYO+uFeZ17UHz0WtInBB7Yo2EHUrkf4jeJDL7rHOG5YOVQzoV1+vdFkmQvPCPX
zPyYyzGCA7cwggOzAgEBMIGsMIGmMQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExETAPBgNVBAcT
CFNhbiBKb3NlMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzElMCMGA1UECxMcRGVMb25nIENl
cnRpZmljYXRlIEF1dGhvcml0eTEWMBQGA1UEAxMNY2EuZGVsb25nLmNvbTEcMBoGCSqGSIb3DQEJ
ARYNY2FAZGVsb25nLmNvbQIBFDAJBgUrDgMCGgUAoIIB3zAYBgkqhkiG9w0BCQMxCwYJKoZIhvcN
AQcBMBwGCSqGSIb3DQEJBTEPFw0wOTA0MjEyMjE5MzFaMCMGCSqGSIb3DQEJBDEWBBTUXjHP649a
h+y15E7WHFnqMiamATCBvQYJKwYBBAGCNxAEMYGvMIGsMIGmMQswCQYDVQQGEwJVUzELMAkGA1UE
CBMCQ0ExETAPBgNVBAcTCFNhbiBKb3NlMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzElMCMG
A1UECxMcRGVMb25nIENlcnRpZmljYXRlIEF1dGhvcml0eTEWMBQGA1UEAxMNY2EuZGVsb25nLmNv
bTEcMBoGCSqGSIb3DQEJARYNY2FAZGVsb25nLmNvbQIBFDCBvwYLKoZIhvcNAQkQAgsxga+ggaww
gaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTERMA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoT
EURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxEZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5
MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJKoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tAgEU
MA0GCSqGSIb3DQEBAQUABIIBAJK35nsMT90/BLwH4V/FbfZDuQLjn01gPNqMC9RP2AgbW8AJt5/k
TMPu9WUpzdCuFzFW2ZtlJeGbfrOgny2poBIP3hwxEQAJq0pF1Mp/uBqdjsLWcStd2jq4wVxtbkkS
MWgDGVuo9gYyHHpV12OQ6kiFqmfMR6W9mKGHw4VWu75Lk9fx0+bSX/8X++KfpF7PGM9azuqqqxKW
DJ6CYQICXVSu/gcIpaps4q03+cYhHZ/a2q+jaW0m+yTZJDoFT28r9c2ayL09ijb8a15MDc6ZDBA0
EweloBXzOr9m5t+f0mVhaM6a+zU3EDTDdK7fH7kXpP6koeQyV/DcG9qiArB0IM8AAAAAAAA=
--Apple-Mail-19-52166031--